IceWarp FAQs | Comparably
IceWarp Mail Server is a highly integrated messaging platform. read more
EMPLOYEE
PARTICIPANTS
3
TOTAL
RATINGS
39

IceWarp FAQs

IceWarp's Frequently Asked Questions page is a central hub where its customers can always go to with their most common questions. These are the 650 most popular questions IceWarp receives.

Frequently Asked Questions About IceWarp

  • This guide is designed to help you enable display alerts in Microsoft Outlook to trigger further issues with Outlook Sync.

    The following windows environment variable can be setfor enabling detailed Outlook error messageswhen loading VSTO add-ins.

    The 'VSTO_SUPPRESSDISPLAYALERTS' windows environment variable can be setfor enabling detailed Outlook error messageswhen loading VSTO add-ins.

    Steps to set the VSTO_SUPPRESSDISPLAYALERTS variable

    1. Close Microsoft Outlook

    2.HolddowntheWindows Keyand pressRon your keyboard.The run dialogue box will open.

    3. Typein thesysdm.cpl and press 'OK'.

    4. Select 'Environment variables...' on the Advanced tab.

    5. Select 'New...' and enter 'VSTO_SUPPRESSDISPLAYALERTS' with a value of zero '0'.

    6. Click 'OK' and restart Microsoft Outlook

    7. Go to Options > Add-ins > Manage COM Add-ins > Go... in Outlook and enable the OutlookSync Add-in. You should now get the full error of why the add-in is not loading:

    View Article
  • Dear users

    We apologise for any inconvenience caused by the issue with Outlook Sync 12.2.1, running on Windows 7 and Outlook 2010. We are currently working on a fix.

    In the meanwhile, please use the following workaround to fix the issue:

    1. you should back up the registry2. you should download the installer manually and install3.1 if Sync is installed per user apply "Workaround_sync_un_del.reg"3.2 if Sync is installed per machine apply "Workaround_sync_un_del_all.reg"4. Run Sync installation and install it to the SAME location as it was (to avoid duplicity - remember - there's no uninstall section after reg file applying).5. you shouldn't create a new profile during installation if you want to use current (from an older version).

    Or:

    Uninstall Current Outlook Sync

    Download and install the new one.

    View Article
  • This document aims to shed some light on the new feature of Outlook Sync, which supports SSO and how to configure Outlook sync and Outlook itself. Unfortunately, Outlook does not support GSSAPI protocol natively; therefore, some changes were made to Outlook sync, and thus some settings need to be reconfigured (especially after implementing SSO after previously using Outlook sync in a regular manner) - and that's what this document is aimed at - explaining all the different settings. When using SSO from the very beginning, it's recommended to start the installation with the parameter "-sso" from the command line and that sets up the profile for SSO without an issue.

    This document assumes that you have already created relevant keytabs for SSO on your domain controller for all related services (SMTP and IMAP protocols in this case), SSO and GSSAPI protocol is enabled on Icewarp server. If you haven't, please follow this document: Configuring SSO for Icewarp server

    The scope of this document is focused purely on SSO setup rather than explaining all the settings of Outlook sync. For all such information, please see this document: Outlook sync guide

    In order for Outlook Sync to work without an Exchange server it does one important thing - it creates a local proxy which imitates POP3 of Exchange which sends response to Outlook stating, that there are no new emails - this is key for Outlook to work without Exchange server (also, that is the reason why, when using Outlook sync, the profile created uses PST rather than OST - it's, in fact, a POP3 account, and it is the correct setting, IMAP account is not supported with Outlook sync - you can still add more IMAP accounts to Outlook via Outlook's account settings, but only one POP3 account is allowed with Outlook sync and its profile manager). We expanded the existing proxy in such manner that other mail protocols can be proxied via Outlook sync as well and thus enabling the Single Sign-on.

    Note that there are two layers of settings that need to be configured - first is how Outlook sync connects to Icewarp server and the second is how Outlook connects to Outlook sync (as stated previously, Outlook sync behaves like a proxy in SSO mode).

    Let's have a look at the main window of Outlook Sync.

    Fig. 1

    Let's skip the Login part for now and let's focus on the Connection section. This section states how Outlook sync connects to Icewarp server, so this is where you set up the information about what is the hostname of Icewarp (internal or external DNS A record) and what ports should be used for the connection to SMTP and IMAP (this is usually based on the settings of the company's firewall, so not all protocol's ports might be available). The best practice is to set up SSL or TLS encryption rather than unsecured connection - unless Outlook is used only from local area network without any access from the internet - but using encrypted connection is generally a good idea to avoid sending passwords over the network in plain text.

    The next step is to check if the proxy is running. This can be found on the second tab of Outlook sync settings - Advanced. The only thing we are interested in this tab is the "Local Server" section. For Outlook sync to function in SSO mode, it is necessary to have the proxy running, therefore if it's disabled, enabled it by pressing "Start".

    Fig. 2

    Note that the ports can be adjusted to random port numbers (maximum of 5 digits are supported in these fields - please note that maximum port number possible is limited to 65535). Outlook sync should be able to detect any available ports for the proxy communication so it shouldn't be necessary to tamper with the pre-generated ports. In case you want to change them, stop the proxy, change ports and then start it again. Try to avoid using ports that are by default used by other services - 25, 465, 587, 143, 993, 80, 443 etc. Higher port numbers (5 digits) are generally a good idea to avoid binding the proxy to a port that a web browser might want to use.

    Once this is set up, we can move to the next step, which is settings up Outlook's account - (e.g. how Outlook connects to Outlook sync).

    Open Start > Control Panel > Mail > Show profiles and choose the corresponding profile used with Outlook sync. Open the Properties > Email Accounts and Choose Change. You should arrive at the window "Change Account" as shown in the screenshot below:

    Fig. 3

    As you can see, the settings of localhost - 127.0.0.1 are in place for IMAP and SMTP protocols. This is correct (and also a requirement) to be able to use SSO configuration.

    It is important to remember that currently, we are adjusting settings of how Outlook communicates, not Outlook sync. For SSO to work, Outlook MUST communicate on both protocols with localhost (e.g. Outlook sync - that's why we are setting up 127.0.0.1 for both - we will need to adjust the ports as well, but we'll get to that later).

    Note that Incoming mail server address MUST always be set to 127.0.0.1 whether we want to use SSO or not. In case we are not using SSO, the Incoming mail server remains at 127.0.0.1, but the Outgoing mail server (SMTP) can be set up directly to Icewarp address, but if that is the case, the "Local Server" (as shown in figure no.2) has to be stopped.

    The Logon Information should be kept, as shown in the screenshot. The User Name has to be "Connector" and the password can be anything, except empty string, but there shouldn't be any need to change the User Name or Password.

    Next click on "More Settings.." and switch to "Outgoing server" tab. Put the bullet point to the option "Log on using" and supply login information of your account and tick "Remember password".

    Fig. 4

    Next, select the "Advanced" tab.

    Fig. 5

    In order for SSO to work, the corresponding ports from the "Local Server" from figure 2 need to be supplied for POP3 and SMTP, and in both cases any encryption needs to be disabled - do not mistake this with Outlook sync's encrypted connection towards Icewarp - we are now configuring ports for localhost, and by encrypting the communication between Outlook and Outlook Sync the communication would not get through. Save the setting by pressing OK.

    Now untick the box to automatically test account settings and press "Next" to save all the settings (the reason is that the settings, while invalid for now, would not be kept due to the test not going through).

    Press OK or Close on all the Windows opened, return to Outlook Sync and switch the "Authentication type" to "Single Sign-on".

    Fig. 6

    Once you supply your domain credentials, the SSO should be working fine.

    View Article
  • Bellow you will find known configuration issues with webmeetings:

    Missing Java on the server (restart all the services after the install) Local interface host missing a proper IP address (VoIP / General / Local interface host) SIP number should be [email protected] (VoIP / Services / WebMeetings) Browser should use HTTPS (for that you need a proper SSL certificate) Enable camera/microphone Use compatible WebRTC browser (Google Chrome recommended) Blocked ports VoIP: 5060 (UDP + TCP), 5061 (TCP), 10000-10256 (UDP) Check API value c_system_services_sip_mediaproxyenabled that should be = true Check API value c_system_services_sip_rtpproxy that should be = true Linux only cd /opt/icewarp/scripts && ./customssl.sh --install cd /opt/icewarp/ && ./icewarpd.sh --restart Limitations Guest accounts cannot share screens or become moderators Troubleshooting

    https://www.icewarp.com/support/troubleshoot_webrtc/ https://www.icewarp.com/support/troubleshoot_screensharing/

    View Article
  • In the case when you are not able to print Email content from IE 11.0.43 and you are seeing Error 404 Not Found.

    Replaceby attached file content in /icewarp/html/webmail/client/inc/

    (for Windows \icewarp\html\webmail\cient\inc\)

    Restart IceWarp services

    These Guide can be used for any 12 IceWarp server version.

    !!! Mentioned issue isfixed in version12.0.1.3 !!!

    View Article
  • General Requirements

    Make sure that all web server extensions are set toFastCGIinIceWarp Administration Console - Web - Default - Scripting.

    Upgrading MSSQL Setup

    1. It is necessary to configure both instances ofMicrosoft Data Access(64-bit and 32-bit odbcad32.exe) with the sameSystem DSN.

    2. Navigate toWindows/SysWOW64runodbcad32.exeand check your currentSystem DSNsettings.

    3. Navigate toWindows/System32runodbcad32.exeand set upexactly the same System DSNas the one above.

    4. Run the upgrade process to64-bit IceWarp Messaging Server.

    5.UseIceWarp Administrator Consoleto test connection to all the databases (Accounts,Groupware,Antispam).

    6. Log intoWebClientto see if everything works correctly. CheckContacts(Groupware) andBlacklist & Whitelist(Antispam) functionality.

    Upgrading MySQL Setup

    1. Copy 64-bitlibmysql.dllto Windows/System32folder. Link to the 64-bitlibmysql.dll(MySQL 5.5) is bellow.

    2. Make sure thereIS NOT32-bitlibmysql.dllinWindows/System32.

    3. Make sure thereIS32-bitlibmysql.dllinWindows/SysWOW64.Link to the 32-bitlibmysql.dll(MySQL 5.5) is bellow.

    4. Run the upgrade process to64-bit IceWarp Messaging Server.

    5. UseIceWarp Administrator Consoleto test connection to all the databases (Accounts, Groupware, Antispam).

    6. If you useMySQLalso forWebClientcache and you are not able to log intoIceWarp WebClientcopy the 32-bitlibmysql.dllalso to folderIceWarp/PHP.

    NOTE: If you experience some problems withLDAPmodule, please follow this thread:

    http://forum.icewarp.com/forum/showthread.php?1834-10.4.5-x64-issues&p=5356#post5356

    View Article
  • The SMS Service incorporated into IceWarp Server is a gateway to mobile networks allowing IceWarp Server to:

    send and receive SMS messages

    use SyncML SMS PUSH technology to synchronize server data to mobile devices instantly

    be a bridge between email and SMS using IceWarp Server's SMS: protocol

    extend CRM and other custom applications by text messaging capabilities

    View Article
  • For those who prefer no background image on their login screen, there is a simple workaround that you can apply.

    Insert the attached file (blank image in the right format) into two locations :

    - .../icewarp/config/_webmail/images/background/background--default.jpg- .../icewarp/html/admin/client/skins/default/login/images/background--default.jpg

    Now the WebClient and the WebAdmin will start with a white (blank) background.

    View Article
  • This guide is designed to help you configure your SMS Server using Clickatell provider.

    Step1:

    Login to Clickatell Developers Central using your existing credentials at https://central.clickatell.com/

    http://api.clickatell.com/http/sendmsg?user=XXXX&password=YYYY&api_id=ZZZZ&&from=NNNN&mo=1&to=%number%%condition;isascii;value=&text=%%condition;isunicode;value=&text=%%condition;isbinary;value=&data=%%data;isascii%%data;hex;isunicode;unicode;value=&unicode=1%%data;hex;isbinary;value=&udh=%%udh;len;hex;isbinary%&concat=%parts%

    Step 2:

    Create a new HTTP API with Add HTTP API button

    Step 3:

    Create a name for you API, set username and password

    Step 4:

    Apply for a long number to manage Two-Way SMS (optional)

    Step 5:

    Edit setting of Two-Way SMS (optional)

    Step 6:

    Select your created API and user Reply Path and Target Address examples on the picture

    Step 7:

    Move to IceWarp remote console now for the SMS server configuration

    Navigate to SMS / General and press Add to create a new configuration. Choose a name for ID, select type HTTP Request, template Clickatell HTTP Gateway and copy this link over to Device window:

    http://api.clickatell.com/http/sendmsg?user=XXXX&password=YYYY&api_id=ZZZZ&to=%number%%condition;isascii;value=&text=%%condition;isunicode;value=&text=%%condition;isbinary;value=&data=%%data;isascii%%data;hex;isunicode;unicode;value=&unicode=1%%data;hex;isbinary;value=&udh=%%udh;len;hex;isbinary%&concat=%parts%

    NOTE: Replace XXXX, YYYY and ZZZZ with your own values (XXXX stands for username, YYYY for password and ZZZZ for API_ID)

    For Two-Way messaging use following link:

    NOTE: Replace XXXX, YYYY,ZZZZand NNNN with your own values (XXXX stands for username, YYYY for password, ZZZZ for API_ID and NNNN for long number)

    Finally, set the PIN/Password.

    Step 8:

    Navigate to SMS / Users and press Add to select users/domains that willbe able to send SMS on behalf of IceWarp. Fill in the password and select Gateway from the list.

    Step 9:

    Navigate to SMS / Incoming messages and check the option Deliver according to #email# in received messages (match the values on the picture below)

    For Two-Way messaging, make a copy of install_dir/html/sms/receive_clickatell_usa.html and name this copy as receive_clickatell.html

    Open the new copy receive_clickatell.html and edit the following rows

    &id (use the name of your Gateway, in our case Clickatell)

    &pass (use your created PIN/Password)

    Save changes

    Your configuration is now complete.

    View Article
  • Posted by - NA -, Last modified by Valentin on 20 June 2014 10:25 AM

    Basic SMTP transaction

    The below SMTP log file represents the communication that happens between the client connection (such as outlook, or web mail) and the Server (Icewarp Mail Server). Each line of the log will show the sending statement from the client and then the response from the server.

    On the left hand side of the log file, you will see the IP of the client that initiates the communication.

    Next to that you will see the transaction ID. (In the example below this is [1308] )

    From the information in this log, you can see the origin, the sender, the recipient, whether the e-mail was accepted to be delivered (routed to the recipient server), and the message ID.

    After the server has accepted the e-mail from the client, it will then attempt to send the e-mail to the recipient server. The following log will show that communication.

    The basic format is the same as the original log, but Icewarp now acts as the client connecting to the recipient server. A new transaction ID is generated, and the IP on the left is now the IP of the Server (the IP on the left is always the IP of the machine that generates the initial connection.

    As you can see, the initial portion of the communication for session [173C] is a DNS lookup for the recipient domain. Once the DNS resolves, it will then connect to the recipient server and initiate a communication with it.

    As in all log files, the communication begins with the connected statement. Then, the recipient domain identifies its self in its initial response to the connection.

    The sending domain then identifies its self with a EHLO statement.

    It then announces to the recipient domain, who the e-mail is from, as well as the size of the e-mail. (always in KBs).

    It is at this point that the recipient server verifies the sender (whether by rDNS, or simply if there is an MX record attached to the domain). Once that is done, the sending server will announce who the e-mail is for, and the recipient domain will check to make sure that user actually exists. If it does, it will tell the sending server to send the e-mail.

    Once the data is sent, the recipient e-mail acknowledges the transaction, and then closes the communication.

    View Article
  • The TeamChat feature will work only when GroupWare service uses MySQL, MS SQL, or Oracle database. TeamChat will not work correctly with SQLite.

    Requirements:

    1. GroupWare using MySQL & MySQL libraries, see attachment mySQL_libs.ZIP

    2. Create a Group, enable TeamChat and add members to the Group

    ATTENTION: the following is counter-intuitive

    Download and add the 32-bitlibmysql.dll intoC:\Windows\SysWOW64

    Download and add the 64-bitlibmysql.dll intoC:\Windows\Sys32

    Open Remote Console > API >gw.connectionstring

    Name: c_gw_connectionstringValue:groupware;iwMySQLadmin;iwMySQLadminPassword;/var/lib/mysql/mysql.sock;3;2

    Open Remote Console > SQL Manager > Databases

    Name: groupwareUser: iwMySQLAdminPassword: iwMySQLAdminPasswordServer IP: <ip address where MySQL is installed>

    Notice the first 3 parameters in the API Console & SQL Manager -name, user, password- have matching values.

    Test Connection:

    Things to check if the connection test fails:

    1. Verify the mysq.dll library locations:

    32-bit >>> C:\Windows\SysWOW64

    64-bit >>> C:\Windows\Sys32

    2. Your firewall needs to allow connectivity from IceWarp server on port 3306.

    3. Permission on MySQL server - that the user, the case above, iwMySQLAdmin, has permissions to access the database from the IceWarp server.

    View Article
  • IceWarp Server Windows Installation Guide

    View Article
  • There are two options how to achieve this - binding it to CSR request or do it manually via .pem format.

    I. Binding it to CSR request

    A. Go to System > Certificates > Server Certificates > add/create.

    B. Select "Request Authority Certificate."

    C. Fill in the information then go to the next screen.

    1. Under the CSR tab, export the CSR and save it.

    2. Under the Export tab, export the Private Key and save it.

    3. Click Cancel to close the screen.

    4. Send the CSR to the vendor and obtain the signed cert.

    Certification Authority sends you signed certificate chains.

    1. Double-clickto CSR request on System > Certificates > Server Certificates tab

    2. Bind the signed certificate and CA certificate which you receive from Sing Authority - if it is a certificate for the primary domain set it as "Default certificate."

    3. Restart All Service modules and check the Error log for any records

    II. Manually via .pem format

    1. Go to System > Certificates > Server Certificates > Select "CRS" you've created

    2. Under the Export tab, export the *private key and save it.

    *NOTE: IceWarp encrypts the private key, copying it directly from the filesystem will result in a failed import.

    3. Use notepad to copy the Private Key, signed cert, and any intermediate certs to a single cert.pem file. See the example at the end of this article.

    4. Go to System > Certificates > Server Certificates > add/create

    5. Select "Add Existing Certificate"

    6. Import the cert.pem file from the single cert.pem you created in step 3

    5. Back on the Server Certificates screen, select the newly imported cert and set it as the default

    6. Restart the services.

    7. Check the IceWarp error log for SSL errors.

    Example of the single cert.pem

    View Article
  • Dear customer,

    It has been several weeks since Microsoft made its Creators Update for Microsoft Windows 10 available. As we have informed recently there was an issue of IceWarp Outlook Sync running on Windows 10 after "Creators" update. More details about the issue are described here

    Our investigation revealed that the problem happens when Outlook itself tries to access PST (Outlook data file) to collect telemetry statistics (data is being sent from a Windows to Microsoft's telemetry servers and Outlook uses them when synchronizing), hence it interferes with Outlook Sync plugin that needs to access the PST too. Therefore we had to change the way how Outlook Sync accesses PST on Windows 10.

    To prevent the freezing of Outlookwe already have a hotfix available(see download link below). Outlook Sync automatically recognizes whether it runs on Windows 10 Creators and if this is the case it uses the modified way of accessing PST, otherwise it uses the standard synchronization mechanism.Who is affected?

    Customers using Outlook Sync (any version) who installed the latest Windows 10 Creators update.

    What is the issue?

    After installing the Creators Update, Outlook may under some circumstances crash or stop working, because the update interferes with the Outlook Sync plugin and breaks the ability to synchronize data with IceWarp.

    How to fix it?

    Install the hotfix of IceWarp Outlook Sync available here For mass installation via GPO, you may need to use MSI installer available here

    Please feel free to contact us if you have any questions.

    View Article
  • Posted by on 01 August 2012 03:05 PM

    Icewarp self test fails, how it works

    Icewarp offers a Server diagnostics option, located in System/Services.

    It will check for several important factors, as shown below, in an example test, where everything is succesfull.

    Testing DNS Server '70.84.161.10;70.84.160.10;ns.lucanet.com.br'...DNS query test successful.Testing Primary Domain 'lucanet.com.br' for MX Record...Primary Domain Test Successful.Testing Internet Connectivity...Internet Connectivity Test Successful.Testing Internet Services...Internet Services Test Successful.Testing SMTP Message Transfer...SMTP Message Transfer Test Successful.

    Server Diagnostics Successful.

    Note that:

    - Your DNS servers, specified in System/Internet connection are tested. Specify several DNS servers separated by semi-colons (;). Be sure to specify DNS servers that let your system/IP do recursive queries, so it can find out the MX of destination servers, where it has to send mail out to.

    - It will check if your primary domain has a valid MX record, so it can receive emails from remote systems. The primary domain is the one that appears first, at the top, in the Icewarp console, in Domains & Accounts management. To make a specific domain the primary one, right click on it and choose to Make Primary. Note that the email administrator account defined in the primary domain receives important messages, such as system errors and information about licenses whose upgrades are expiring.

    - Internet connectivity and services are tested

    - It does an SMTP message transfer test, by sending mail using your server's IP to the administrator email account defined in the primary domain.

    View Article
  • Posted by Gary Garber, Last modified by Michael Filip on 22 July 2014 05:58 AM

    Product Evalution Basics

    To try before you buy, we offer 30 day, full-featured, evalution version of IceWarp Server included with the download. This article deals with its features, limitations and answers relatedquestions.

    FEATURES

    Evalution license has all the features available for 200 users and 30 days. Domains are unlimited, as with all our licenses. All advanced options are enabled. To test migrate more than 200 users, you can ask your sales representative to increase the number of users on your evaluation license.

    When you decide to keep the software, you will only need to enter a valid license.

    No reinstallation is required, all settings and data remain in place.

    LIMITATIONS

    The evaluation will only work on a server where there was no copy of Icewarp installed in the past.

    If you access the Administration Console, you will be presented with an alert saying how many days are left of the trial.

    After 30 days, you won't be able to change any settings or create new users. You might simply forgot that the software is not licensed as it is running neatly and requires no daily maintenance. To minimize impact to your users, there's an additional 30 day period until the services are stopped.

    After 60 days from installation, services are stopped and it would only help to reinstall with a valid license to get back on track.

    FAQ

    What happens after the free period is over?

    After 30 days the mail server (POP3/IMAP/SMTP) will still work, WebClientwill cease to function showing Unregistered at the login screen, and no further configuration changes will be possible to save in the Administration console.After further 30 days (60 days from installation) the software will cease to function and services won't start.

    When should I obtain the full license if I want to keep the software beyond the 30 days?

    When the 30 day period is over, Administration Console is locked down and there's no simple way to enter the license. You should therefore obtain the license within these 30 days, on the 30th day at the latest to be able to easily activate the software.

    How to enter the license when the Administration Console is not accessible?

    Run the installer and provide a valid Order ID under Activate License... button.

    Is it possible to extend the trial license?

    E-mail us at [email protected] or contact your local vendor. Specify the reason why you need to trial another 30 days and include the Order ID(TRLyyyymmdd) from Help > Licenses.

    How to try out a module if I have a live license?

    There are always a few days to try any module after you have renewed your license (on the recent Order ID).Secondly, each user can access any of the services for a period of 7 days, even services which you are not licensed for or those with an expired trial. Double-click the module in Help - Licenses to see which users have already used up their 7-day trial.You can request to prolong yourevaluation licenses [email protected]. Include your current Order ID or attach license information exported as XML.NOTEYou should have some Renewal period left on your existing licenses as you need to be running the latest version to properly evaluate current functionality.

    Where do I find what number of accounts I need to acquire the correct license?

    For a basic overview see Help - License dialogue, Used Seats column. See also Status - Volume - Global - Number of Users. A number of accounts within a domain can be found under the Management node. Select the domain and switch to the Info tab.Please note that the total number of accounts for mail server includes non-user types of accounts as well (Mailing Lists, List Servers, Remote Accounts etc.) The license doesn't need to cover these special accounts, but thereshould be a spare for future growth.

    You can find license and pricing options in the on-line purchase system on our website.

    Updated 15.07.2014, by Michael

    View Article
  • Dear users, please find below the essential guide for MySQL setup.MySQL DBsPlease download the MySQL community server here: http://dev.mysql.com/downloads/mysql/ You will want the 32bit installer it contains both the 32 and 64bit versions.You will also need to download the C connectors here: https://downloads.mysql.com/archives/c-c/ You will need both the 32bit and 64bit zips. There is a version of libymsql.dll in each archive.

    The 32bit dll will need to be placed in the /windows/syswow64 folder.

    The 64bit dll will need to be placed in the /Windows/System32 folder.From the Admin console please go to File>API console and filter on mysqldefaultcharset and set the value to utf8mb4.The following queries can be used to create the databases in the MySQL console.create database icewarp_accounts DEFAULT CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_cicreate database icewarp_antispam DEFAULT CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_cicreate database icewarp_groupware DEFAULT CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_cicreate database icewarp_dircache DEFAULT CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_cicreate database icewarp_activesync DEFAULT CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_cicreate database icewarp_webcache DEFAULT CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci

    View Article
  • Release Date: December 4, 2014End of Support: TBAFor documentation on MOS 4.4 releases, see the MOS 4.4 Product Guides.For detailed upgrade information for this release, see the Upgrade Instructions.

    Major New Features in MOS 4.4:

    For more information on these or any other features, see the Release Notes on the page for the specific release.

    Support for 8-series hardware platform

    WebMail/WebCal Corporate Edition - completely new user interface, with new features including:

    Tagging

    Real-Time Mail

    XML API Version 3

    Faster internal database server

    MOS 4.4.6 download information:

    For MOS 4.2.x and earlier: ftp://ftp.mirapoint.com/pub/updates/R4_4_6_GA.mpu5(size:813430148, md5sum: f16d5fbff48c06f6cb8688b56386dbfa)For MOS 4.3.x and later: ftp://ftp.mirapoint.com/pub/updates/P4_4_6_GA.mpu5(size: 661204588, md5sum: 443494dde40fe73bbc420dd767454085)

    Recommended Patches, Late-Breaking Issues

    Problem Description

    Fix Information

    !!

    Addresses glibc 'GHOST' security issues (CVE-2015-0235).

    Install D4_glibc_security to fix this potential problem.

    !!

    Addresses NTP security issues (CVE-2014-9293, CVE-2014-9294, CVE-2014-9295).

    Install D4_ntp_security to fix this problem.

    !!

    TLSv1.1 and TLSv1.2 are available.

    Install E4_4_6_TLSv12_5 to fix this problem.

    R

    Database server Service Pack 1.

    Install D4_4_6_DB_SP_1 to obtain important database bug fixes.

    R

    Corrects blackhole duration settings.

    Install D4_blackhole_timeout to fix this problem.

    O

    New language localizations unavailable.

    Install Traditional Chinese Mainland China. French. Spanish. German. Traditional Chinese Taiwan.

    O

    The ip addresses, subnet masks, domain names, or subdomain names whose messages need to be rejected.

    Install D4_4_6_smtp_restrict_sender_4 to add this feature.

    Note: Mirapoint's policy is to always integrate patches created to address known problems into the next patch release.

    !!

    Strongly recommended

    R

    Recommended

    O

    Optional

    I

    Contact support for information

    Fixed Issues: 4.4.6

    Administration

    Increased speed for deleting a user and the user's associated mailbox hierarchy. (MIRA-54988)

    Calendar

    Suppress the log entry "Failed contacting CAP server" when attempting to subscribe to a user calendar that does not exist on a Mirapoint server, for example on Microsoft Exchange. (MIRA-53114)

    Recurrent events now display correctly from shared calendars. (MIRA-53234)

    Users from different domains hosted on the same Mirapoint host are now able to invite each other to meetings as external attendees, keeping the domains truly separate. (MIRA-53247)

    Events involving a resource are now correctly updated when a change is made in a shared calendar. (MIRA-53287)

    Hardware Support

    HBA firmware on SAN-based systems will be updated upon install. (MIRA-55016)

    Newer RG170 units are now able to successfully upgrade to MOS 4.4 with this version, previously upgrades would fail due to some hardware compatibility issues. (MIRA-55018)

    IMAP

    When an IMAP client is performing a folder operation (rename, move, delete), all other IMAP folder operations on that folder are dishonored. This means IMAP folder operations create an exclusive lock on that folder until the operation is complete. (MIRA-53101)

    MTA

    The exception rules for 'senderisvalidrecipient' are now correctly honored what the systemwide setting is off. (MIRA-52612)

    Monitoring

    SNMP MIBS updated. (MIRA-53278)

    Operating System

    The 'lazy delete' function of MOS now works more reliably, enabling more efficient operation of the appliance. 'Lazy delete' causes messages to be deleted when sufficient resources are available on the system, this is invisible to end users. (MIRA-53079)

    Fixed a database deadlock condition for users with quotas set. (MIRA-53258)

    A number of database stability and efficiency improvements have been implemented in this release. (MIRA-55052)

    Removed CGI scripts that are not required for appliance operation, thus removing potential security issues. (MIRA-55084)

    A new command is introduced 'conf [enable|disable|enabled] securelcd'. With 'securelcd' enabled no information will display on the front LCD panel other than when a fault occurs. (MIRA-53162)

    Includes fixes for the bash 'Shellshock' bug. (MIRA-55076)

    Administrators may disable SSLv3 to avoid the SSL POODLE vulnerability. (MIRA-55087)

    POP

    Corrected an issue where a mailbox by the same name would be locked in all domains when the user logged in, thus not allowing concurrent access for these users.. (MIRA-55007)

    Webmail

    Webmail correctly displays messages, rather than "Body: Open", for messages where character set aliases were specified rather than a direct character set definition. (MIRA-44573)

    Users are now able to delete messages from shared folders owned by other users that have a username that contains a period ('.') character in part of their username. eg. user.name (MIRA-53281)

    Stability enhancements to the webmail service. (MIRA-54995)

    Webmail will now correctly display messages with mixed simplified and traditional Chinese character sets. (MIRA-55015)

    Fixed a problem where attaching files to an email would fail occasionally. (MIRA-55039)

    Directory searches from within webmail now work reliably. (MIRA-55047)

    Address book fields are now in the correct order on CSV export. (MIRA-55082)

    Patches Included

    D4_3_5_sslv3_option, (MIRA-55088)

    D4_3_7_DB_SP_2 (MIRA-55033)

    D4_3_7_LALA (MIRA-55035)

    D4_3_7_SP_1 (MIRA-53248)

    D4_3_7_calendar_domains_recurrent_events (MIRA-54986)

    D4_3_7_calendar_domains_recurrent_events_2 (MIRA-54986)

    D4_3_7_imap_folder_4 (MIRA-53112)

    D4_4_3_imap_folder_4 (MIRA-53112)

    D4_4_4_SNMP_hardware (MIRA-54953)

    D4_4_4_calendar_domains_recurrent_events (MIRA-54986)

    D4_4_4_pop_userlock (MIRA-55008)

    D4_4_4_sslrelay (MIRA-55086)

    D4_4_4_webmail_mixed_chinese (MIRA-55042)

    D4_4_5_SNMP_hardware (MIRA-55010)

    D4_4_5_addressbook_export_3 (MIRA-55100)

    D4_4_5_mailbox_lock_3 (MIRA-55050)

    D4_4_5_sslv3_option, (MIRA-55088)

    D4_4_5_webmail_directory (MIRA-55067)

    D4_4_sslv3_option (MIRA-55088)

    D4_bash_security_2 (MIRA-55077)

    E4_secure_lcd (MIRA-54974)

    F4_HBA_1 (MIRA-55053)

    View Article
  • Posted: March 3, 2011End of Support: December 31, 2015

    Major New Features

    For more information on these or any other features, see the Release Notes on the page for the specific release.

    WebMail/WebCal Corporate Edition - completely new user interface, with new features including:

    Tagging

    Real-Time Mail

    XML API Version 3

    MOS 4.3.7 download information

    For MOS 4.1.9 and later 4.1: ftp://ftp.mirapoint.com/pub/updates/R4_3_7a_GA.mpu5(size: 724973252, md5sum: 9eba9516e63fcc6f82bafa2d8c01c511)For MOS 4.2.1 to 4.3.6: ftp://ftp.mirapoint.com/pub/updates/P4_3_7_GA.mpu5(size: 565294948, md5sum: 5d14c67af32b51022abf8636211e7d37)

    Recommended Patches, Late-Breaking Issues

    Problem Description

    Fix Information

    !!

    Addresses glibc 'GHOST' security issues (CVE-2015-0235).

    Install D4_glibc_security to fix this potential problem.

    !!

    Addresses NTP security issues (CVE-2014-9293, CVE-2014-9294, CVE-2014-9295).

    Install D4_ntp_security to fix this problem.

    !!

    Addresses bash 'shellshock' bug.

    Install D4_bash_security_2 to fix this problem.

    !!

    Addresses a number of SSL security issues, including the recently published POODLE vulnerability.

    Install D4_4_sslv3_option to fix this problem.

    !!

    Allows successful selective restore from image backup.

    Install D4_3_7_restore_5 to fix this problem.

    !!

    Corrects an issue where deleting an IMAP selected folders caused a folder corruption.

    Install D4_3_7_imap_folder_4 to fix this problem.

    !!

    Corrects an internal db problem on Junkmail Manager installations.

    Install D4_3_7_jmm to fix this problem.

    !!

    Internal database connections were sometimes not released, this patch corrects the issue.

    Install D4_3_7_connection_leak to fix this problem.

    !!

    TLSv1.1 and TLSv1.2 are available.

    Install E4_4_TLSv12_3 to fix this problem.

    R

    Corrects a problem where filtering could be slow.

    Install D4_3_6_filter_speed to fix this problem.

    R

    Updates Corporate Edition Webmail to support the latest versions of the Chrome browser.

    Install D4_3_7_webmail_compose_2 to fix this problem.

    R

    Updates Corporate Edition Webmail to support the latest versions of the Chrome browser for Chinese locales.

    Install D4_3_7_webmail_compose_zs_CN_2 to fix this problem.

    R

    Corrects a problem where the POP mailbox for a user would be locked unintentionally.

    Install D4_4_4_pop_userlock to fix this problem.

    R

    Corrects blackhole duration settings (MIRA-55000).

    Install D4_blackhole_timeout to fix this problem.

    O

    Disclaimers with position set to 'top' now preserves the original email contents.

    Install D4_3_7_filter_disclaimer to fix this problem.

    O

    With this patch autoreply messages honour the 'Auto-Submitted:' header of incoming messages.

    Install D4_3_autoreply to fix this problem.

    O

    Database server Service Pack 5.

    Install D4_3_7_DB_SP_5 to fix this problem.

    I

    HTML messages would not wrap in the compose window correctly under all circumstances.

    Install D4_3_6_webmail_wrap_2 to fix this problem.

    Note: Mirapoint's policy is to always integrate patches created to address known problems into the next patch release.

    !!

    Strongly recommended

    R

    Recommended

    O

    Optional

    I

    Contact support for information

    Fixed Issues: 4.3.7

    Administration

    When "admin get security" does not list 'cleartext' as an option and the administrator connects to the administration GUI using HTTPS an 'internal error' is no longer reported and a successful connection is formed. (52110)

    Reduced logging so that only relevant information is stored, this saves disk space under the STORE.SYSSTORE area. (57157)

    Clustering

    On clustered systems, licenses will not be removed automatically when deleting the cluster. Previously, licenses were automatically removed from former standby head units even if it is running production services when the administrator deleted the cluster; this resulted in services failing. (57079)

    Documentation

    Some edits were made to the online help files to clarify search term usage. (54951)

    Filtering

    Correct the problem where a redirect filter would also deliver a copy of the message to the original recipient, thus behaving like a wiretap filter. Now redirect filters only deliver the message to the redirect address. (57023)

    MOS now correctly translates utf-8 characters in disclaimers when converting to an alternative character set. (57099)

    Hardware Support

    On 7 series hardware, an occasional alert would appear "CPU module 1 is missing or failed", the underlying issue for falsely reporting this condition has been corrected. (56533)

    Querying the storage layer via either the web interface or CLI commands is now faster. (56792)

    MTA

    If a non-local domain has a good MX record, A records will not be used in routing decisions. (56248)

    MOS will ignore any IPv6 records for MX hosts. Previously MX hosts containing IPv6 addresses exclusively would cause mail to bounce. (57143)

    Monitoring

    The SEL log is now cleared when it approaches being full. The SEL log is still monitored for events that administrators should be made aware of. (56583)

    Monitoring of external services now honours a setting of '0' for NTP services. ie. SYSTEM.NTP*RESP 0 (56951)

    Operating System

    The SSL service no longer consumes excessive resources during high connection rate periods. (56610)

    Static network routing rules will survive changes to bonded NIC's. (57046)

    Increased the number of resources available to service database transactions. (57206)

    Security

    After importing a configuration file (with 'conf import'), the system will now update the mtaverify settings afterwards correctly. (54521)

    Webmail

    In Corporate Edition Webmail personal folders are now displayed even if the IMAP subscription is not set on a personal folder. (50713)

    Mirapoint Webmail now has 98% character coverage for the ISO-2022-JP-2 character encoding. Full coverage will be available in a future MOS release. (56837)

    Integrated contents of patch E4_3_5_webmail_iso2022jp into core MOS code. (57108)

    Corporate Edition v2 no longer allows attackers to capture a users session ID by inserting remote images or a 'href' tag (that users click on) into a HTML formatted message if the administrator of the Mirapoint appliance does not use the setting "http set cookies strict" (57191)

    Patches included:

    D4_3_6_filter (57132)

    D4_3_5_smtp_ipv6_ignore_1 (57155)

    D4_3_5_sslrelay and D4_4_2_sslrelay (57174)

    D4_3_5_webmail (57185)

    D4_3_5_webmail_1 (57217)

    D4_3_5_nic_failover (57222)

    D4_sel_log_clear and full fix included. (56761)

    Fixed in Previous Releases

    4.3.6-GA: http://ftp.mirapoint.com/pub/docs/articles/mos43/relNotes-4_3_6-00894.pdf

    Known Issues: 4.3.7

    Administration

    The "Return-Path" header is not treated consistently during message filtering, sometimes it is removed and other times it is not. (48010)

    The "MON Clear" command doesn't clear the alerts returned by "mon status". (57087)

    Cannot import exceptions to single users. (57034)

    Selective restores from image based backups, including local disk backups, will fail on 4.3.6. (57204)

    MOS does not honour the setting of '0' against the "mon setthresh system.service*resp" command. The system should not monitor the service, however MOS continues to monitor and produce alerts in the case of failure. (57064)

    If the total number of JMM users exceeds the regular "user limit" license, you are unable to add regular users to a system - this is not the intended design. (36043)

    Branding

    "ERROR file too large" while publishing the brand containing chinese locale. (56933)

    Calendar

    All day event cannot be changed to event less than All day. (57088)

    The "Repeat until" date is changed after saving the event. This can lead to a repeated event's last instance not appearing in a user's calendar if they are in a different timezone. (56799)

    "No conflict" alert is shown when creating an all day event, although there exist a regular event on the same day. (56954)

    In calendar when Time Mode = 24 hrs and Day spans from 0 to 24 hrs, new event created at 0:00-1:00 appears twice in "Horizontal Week View". Once on previous day after 23:00 hr cell and another at correct place at 0:00 cell. (56813)

    Event update by person with whom the calendar is shared with write access doesn't work as expected. (56814)

    Repeated event can't be viewed by person with whom the calendar is shared if the user is given read/write permission. (56816)

    Unable to open/download attachment from any event instance belonging to repeating events in CE. (56981)

    Calender CE uses local machine time to decide age of an event. (56990)

    When owner deletes the event from calendar, the notification is not sent to attendees and also event from attendees's calendar is not deleted. (56851)

    Hardware Support

    "stat get system.voltage" command does not work. (56891)

    MTA

    When recipient domain is not resolvable, the mail is delivered to user on local machine. (57040)

    If a user with auto reply enabled receives an e-mail which has the "Reply-to" header split over more than one line then the user can receive a non-delivery report relating to the auto reply. (57051)

    Users are unable to set both a forward and an auto reply at the same time. (11909)

    Webmail

    In certain circumstances the display name is not displayed correctly when a reply is sent from WebMail to Mac OSX. (57084)

    Error after double-clicking checkbox in sharing controls. Once user double clicks any of the check box under Options" -> "SharingControls", subsequent single/double click on those check boxes will result in checkbox getting converted to text box. (56809)

    Signature is displayed incorrectly above compose window in IE8. (57003)

    If the user is logged into a portal page, logging out redirects to the respective login page of webmail edition and not to the portal page login. (56944)

    Users are not displayed in the Sharing Control section of the UI when they have been enabled with read or write permissions. This occurs with IE9 only. (56379)

    Deleted contact appears in "Edit Group" dialog box. "Invalid contact index" displays when you click "Ok". This issue no longer appears after logout/ login. (56793)

    The WebMail address book can crash if patch E4_3_CE42_US_3 is installed and named brands are present for delegated domains. (57042)

    When 'ldapautoreply' is enabled, users with a dot in their username (eg. fred.bloggs) are unable to set an auto reply message correctly. (55304)

    LDAP address book queries will not display the common name attrbiute (cn) in Corporate Edition Webmail. (56370)

    View Article
  • Posted: March 3, 2011End of Support: December 31, 2015For detailed information on this release, see the Release Notes.For a list of known reported issues at the time of this release, see Known Issues.For complete documentation on the MOS 4.3.6 release, see the MOS 4.3 Product Guides.

    Download Information

    For MOS 4.1.9 and later 4.1: ftp://ftp.mirapoint.com/pub/updates/R4_3_6_GA.mpu5(721829620, MD5: ac41e7839df493eee490febddcb3730f)For MOS 4.2.1 and later 4.2, or 4.3.0 through 4.3.5: ftp://ftp.mirapoint.com/pub/updates/P4_3_6_GA.mpu5(562087308, MD5: 1650dfd9ac614f1de0d89735257ddc9f)

    Recommended Patches, Late-Breaking Issues

    Problem Description

    Fix Information

    !!

    Addresses glibc 'GHOST' security issues (CVE-2015-0235).

    Install D4_glibc_security to fix this potential problem.

    !!

    Addresses NTP security issues (CVE-2014-9293, CVE-2014-9294, CVE-2014-9295).

    Install D4_ntp_security to fix this problem.

    !!

    Addresses bash 'shellshock' bug.

    Install D4_bash_security_2 to fix this problem.

    !!

    Addresses a number of SSL security issues, including the recently published POODLE vulnerability.

    Install D4_4_sslv3_option to fix this problem.

    !!

    Removes an XSS vulnerabilty in Corporate Edition webmail

    Install D4_4_2_webmail to fix this problem.

    !!

    Allows successful selective restore from image backup.

    Install D4_3_7_restore_5 to fix this problem.

    !!

    Fixes high SSL connection level count

    Install D4_4_2_sslrelay to fix this problem.

    !!

    TLSv1.1 and TLSv1.2 are available with ECDHE ciphers.

    Install E4_4_TLSv12_5 to fix this problem.

    R

    Corrects a problem where filtering could be slow.

    Install D4_3_6_filter_speed to fix this problem.

    R

    Add previous Japanese CE WebMail locale

    Install E4_3_CE42_JP_2 to fix this problem.

    R

    Add previous English CE WebMail locale

    Install E4_3_CE42_US_2 to fix this problem.

    R

    Resolves diagnostic file generation problem

    Install D4_diagdata_1 to fix this problem.

    R

    Redirect filtering now works as per specification

    Install D4_3_6_filter to fix this problem.

    R

    Updates Corporate Edition Webmail to support the latest versions of the Chrome browser.

    Install D4_3_7_webmail_compose_2 to fix this problem.

    R

    Updates Corporate Edition Webmail to support the latest versions of the Chrome browser for Chinese locales.

    Install D4_3_7_webmail_compose_zs_CN_2 to fix this problem.

    R

    Corrects blackhole duration settings (MIRA-55000).

    Install D4_blackhole_timeout to fix this problem.

    O

    Unable to set ldap based autoreply if a '.' in a user name

    Install D4_3_6_ldapautoreply_2 to fix this problem.

    O

    With this patch autoreply messages honour the 'Auto-Submitted:' header of incoming messages.

    Install D4_3_autoreply to fix this problem.

    I

    HTML messages would not wrap in the compose window correctly under all circumstances.

    Install D4_3_6_webmail_wrap_2 to fix this problem.

    Note: Mirapoint's policy is to always integrate patches created to address known problems into the next patch release.

    !!

    Strongly recommended

    R

    Recommended

    O

    Optional

    I

    Contact support for information

    View Article
  • Posted: March 3, 2011End of Support: December 31, 2015For detailed information on this release, see the Release Notes.For a list of known reported issues at the time of this release, see Known Issues.For complete documentation on the MOS 4.3.5 release, see the MOS 4.3 Product Guides.

    Download Information

    For MOS 4.1.9 and later 4.1: ftp://ftp.mirapoint.com/pub/updates/R4_3_5_GA.mpu5(667847948, 6bd50847b6e9f54b3815e14701c60db9)For MOS 4.2.1 and later 4.2, or 4.3.0 through 4.3.4: ftp://ftp.mirapoint.com/pub/updates/P4_3_5_GA.mpu5(500292068, 3f2743501a10b547b8a94a1d8b9cd831)

    Recommended Patches, Late-Breaking Issues

    Problem Description

    Fix Information

    !!

    Addresses glibc 'GHOST' security issues (CVE-2015-0235).

    Install D4_glibc_security to fix this potential problem.

    !!

    Addresses NTP security issues (CVE-2014-9293, CVE-2014-9294, CVE-2014-9295).

    Install D4_ntp_security to fix this problem.

    !!

    Addresses bash 'shellshock' bug.

    Install D4_bash_security_2 to fix this problem.

    !!

    Addresses a number of SSL security issues, including the recently published POODLE vulnerability.

    Install D4_3_5_sslv3_option to fix this problem.

    !!

    Removes an XSS vulnerabilty in Corporate Edition webmail

    Install D4_3_5_webmail_2 to fix this problem.

    !!

    Fixes high SSL connection level count

    Install D4_3_5_sslrelay to fix this problem.

    !!

    NIC bonding settings maintained between reboots

    Install D4_3_5_nic_failover to fix this problem.

    !!

    TLSv1.1 and TLSv1.2 are available.

    Install E4_3_5_TLSv12_3 to fix this problem.

    R

    Ensures static routes are maintained after network change

    Install D4_3_5_route_cfg_change to fix this problem.

    R

    Add previous Japanese CE WebMail locale

    Install E4_3_CE42_JP_2 to fix this problem.

    R

    Add previous English CE WebMail locale

    Install E4_3_CE42_US_2 to fix this problem.

    R

    Resolves diagnostic file generation problem

    Install D4_diagdata_1 to fix this problem.

    R

    Redirect filtering now works as per specification

    Install D4_3_6_filter to fix this problem.

    R

    Updates Corporate Edition Webmail to support the latest versions of the Chrome browser.

    Install D4_3_7_webmail_compose_2 to fix this problem.

    R

    Updates Corporate Edition Webmail to support the latest versions of the Chrome browser for Chinese locales.

    Install D4_3_7_webmail_compose_zs_CN_2 to fix this problem.

    R

    Corrects blackhole duration settings (MIRA-55000).

    Install D4_blackhole_timeout to fix this problem.

    R

    Network monitoring causes unexpected failover in a clustered environment (MIRA-55383).

    Install D4_3_5_failover_2 to fix this problem.

    O

    With this patch autoreply messages honour the 'Auto-Submitted:' header of incoming messages.

    Install D4_3_autoreply to fix this problem.

    Note: Mirapoint's policy is to always integrate patches created to address known problems into the next patch release.

    !!

    Strongly recommended

    R

    Recommended

    O

    Optional

    I

    Contact support for information

    View Article
  • Release Date: June 20, 2013End of Support: TBAFor complete documentation on the MOS 4.4.3 release, see the MOS 4.4 Product Guides.For detailed upgrade information for this release, see the Upgrade Instructions.

    Major New Features in MOS 4.4:

    For more information on these or any other features, see the Release Notes on the page for the specific release.

    Support for 8-series hardware platform

    WebMail/WebCal Corporate Edition - completely new user interface, with new features including:

    Tagging

    Real-Time Mail

    XML API Version 3

    Faster internal database server

    MOS 4.4.3a-GA fixes several critical issues, including difficulties with upgrade, and mail delivery when LDAP is misconfigured.

    Download Information:

    For MOS 4.2.x and earlier: ftp://ftp.mirapoint.com/pub/updates/R4_4_3a_GA.mpu5(size: 786567204, md5sum: 826db97bd2d0f69b63add45070f81301)For MOS 4.3.x and later: ftp://ftp.mirapoint.com/pub/updates/P4_4_3a_GA.mpu5(size: 626821204, md5sum: c51a9fea5fe471f6aacba54b735f2f40)

    Recommended Patches, Late-Breaking Issues:

    Problem Description

    Fix Information

    !!

    Addresses glibc 'GHOST' security issues (CVE-2015-0235).

    Install D4_glibc_security to fix this potential problem.

    !!

    Addresses NTP security issues (CVE-2014-9293, CVE-2014-9294, CVE-2014-9295).

    Install D4_ntp_security to fix this problem.

    !!

    Addresses bash 'shellshock' bug.

    Install D4_bash_security_2 to fix this problem.

    !!

    Addresses a number of SSL security issues, including the recently published POODLE vulnerability.

    Install D4_4_sslv3_option to fix this problem.

    !!

    Fix to prevent excessive database connection build-up

    Install D4_4_2_connection_leak to fix this problem.

    !!

    Allows successful selective restore from image backup.

    Install D4_4_3_restore_5 to fix this problem.

    !!

    Corrects a number of database corruption issues when accessing user folders.

    Install D4_4_3_DB_SP to fix this problem.

    !!

    TLSv1.1 and TLSv1.2 are available.

    Install E4_4_TLSv12_3 to fix this problem.

    !!

    Corrects an internal db problem on Junkmail Manager installations.

    Install D4_4_3_jmm to fix this problem.

    R

    Updates Corporate Edition Webmail to support the latest versions of the Chrome browser.

    Install D4_4_3_webmail_compose_2 to fix this problem.

    R

    Updates Corporate Edition Webmail to support the latest versions of the Chrome browser for Chinese locales.

    Install D4_4_3_webmail_compose_zs_CN_2 to fix this problem.

    R

    Corrects a problem where the POP mailbox for a user would be locked unintentionally.

    Install D4_4_4_pop_userlock to fix this problem.

    R

    Corrects blackhole duration settings (MIRA-55000).

    Install D4_blackhole_timeout to fix this problem.

    Note: Mirapoint's policy is to always integrate patches created to address known problems into the next patch release.

    !!

    Strongly recommended

    R

    Recommended

    O

    Optional

    I

    Contact support for information

    Fixed Issues: 4.4.3

    Administration

    When "admin get security" does not list 'cleartext' as an option and the administrator connects to the administration GUI using HTTPS an 'internal error' is no longer reported and a successful connection is formed. (52110)

    Reduced logging so that only relevant information is stored, this saves disk space under the STORE.SYSSTORE area. (57157)

    Branding

    Branding uploads are now successful under MOS v4.4.x (57192)

    Clustering

    On clustered systems, licenses will not be removed automatically when deleting the cluster. Previously, licenses were automatically removed from former standby head units even if it is running production services when the administrator deleted the cluster; this resulted in services failing. (57079)

    Documentation

    Some edits were made to the online help files to clarify search term usage. (54951)

    Filtering

    Correct the problem where a redirect filter would also deliver a copy of the message to the original recipient, thus behaving like a wiretap filter. Now redirect filters only deliver the message to the redirect address. (57023)

    MOS now correctly translates utf-8 characters in disclaimers when converting to an alternative character set. (57099)

    Hardware Support

    On 7 and 8 series hardware, an occasional alert would appear "CPU module 1 is missing or failed", the underlying issue for falsely reporting this condition has been corrected. (56533)

    Querying the storage layer via either the web interface or CLI commands is now faster. (56792)

    The command "model get chassis" now reports different values for the M8000 and M8800 models. (57038)

    MOS now correctly reports RAID controller information (cache state and battery charge levels) from 8-series systems. (57138)

    MTA

    If a non-local domain has a good MX record, A records will not be used in routing decisions. (56248)

    MOS will ignore any IPv6 records for MX hosts. Previously MX hosts containing IPv6 addresses exclusively would cause mail to bounce. (57143)

    Monitoring

    The SEL log is now cleared when it approaches being full. The SEL log is still monitored for events that administrators should be made aware of. (56583)

    The Remote Access Controller (RAC) firmware is updated in this release to enable CPU temperature monitoring on 8-series hardware. On the first boot of this MOS version we expect an additional delay of approximately 7 minutes while the firmware is updated. Subsequent boots will return to the normal execution time. (56780)

    RG180 hardware no longer logs a 'power supply failure' on the next boot after the power supply is disconnected from the system. (56900)

    Monitoring of external services now honours a setting of '0' for NTP services. ie. SYSTEM.NTP*RESP 0 (56951)

    MOS now monitors the health of both power supplies on the S800 and RG280 models. (57078)

    Operating System

    The SSL service no longer consumes excessive resources during high connection rate periods. (56610)

    Static network routing rules will survive changes to bonded NIC's. (57046)

    Increased the number of resources available to service database transactions. (57206)

    During a boot, if internal databases require automated recovery actions, these actions are allowed to fully complete and service is restored. Previously these actions would abort resulting in the appliance failing to resume operations and requiring intervention by Support engineers. (57228)

    Security

    After importing a configuration file (with 'conf import'), the system will now update the mtaverify settings afterwards correctly. (54521)

    Webmail

    In Corporate Edition Webmail personal folders are now displayed even if the IMAP subscription is not set on a personal folder. (50713)

    Mirapoint Webmail now has 98% character coverage for the ISO-2022-JP-2 character encoding. Full coverage will be available in a future MOS release. (56837)

    Integrated contents of patch E4_3_5_webmail_iso2022jp into core MOS code. (57108)

    Corporate Edition v2 no longer allows attackers to capture a users session ID by inserting remote images or a 'href' tag (that users click on) into a HTML formatted message if the administrator of the Mirapoint appliance does not use the setting "http set cookies strict" (57191)

    Patches included:

    D4_3_6_filter (57132)

    D4_4_2_raidadmmon (57150)

    D4_3_5_smtp_ipv6_ignore_1 (57155)

    D4_3_5_sslrelay and D4_4_2_sslrelay (57174)

    D4_4_2_webmail (57175)

    D4_3_5_webmail (57185)

    D4_4_2_branding (57200)

    D4_3_5_webmail_1 (57217)

    D4_3_5_nic_failover (57222)

    D4_sel_log_clear and full fix included. (56761)

    D4_migrate_series8 (57152)

    D4_admingui (57254)

    Fixed in Previous Releases

    4.4.2-FCS: http://ftp.mirapoint.com/pub/docs/articles/mos44/relNotes-4_4_2_FCS.pdf

    Known Issues: 4.4.3

    Administration

    The "Return-Path" header is not treated consistently during message filtering, sometimes it is removed and other times it is not. (48010)

    The "MON Clear" command doesn't clear the alerts returned by "MON Status". (57087)

    Cannot import exceptions to single users. (57034)

    Selective restores from image based backups, including local disk backups, will fail on 4.3.6 and 4.4.x. (57204)

    MOS does not honour the setting of '0' against the "mon setthresh system.service*resp" command. The system should not monitor the service, however MOS continues to monitor and produce alerts in the case of failure. (57064)

    If the total number of JMM users exceeds the regular "user limit" license, you are unable to add regular users to a system - this is not the intended design. (36043)

    Branding

    "ERROR file too large" while publishing the brand containing chinese locale. (56933)

    Calendar

    All day event cannot be changed to event less than All day. (57088)

    The "Repeat until" date is changed after saving the event. This can lead to a repeated event's last instance not appearing in a user's calendar if they are in a different timezone. (56799)

    "No conflict" alert is shown when creating an all day event, although there exist a regular event on the same day. (56954)

    In calendar when Time Mode = 24 hrs and Day spans from 0 to 24 hrs, new event created at 0:00-1:00 appears twice in "Horizontal Week View". Once on previous day after 23:00 hr cell and another at correct place at 0:00 cell. (56813)

    Event update by person with whom the calendar is shared with write access doesn't work as expected. (56814)

    Repeated event can't be viewed by person with whom the calendar is shared if the user is given read/write permission. (56816)

    Unable to open/download attachment from any event instance belonging to repeating events in CE. (56981)

    Calender CE uses local machine time to decide age of an event. (56990)

    When owner deletes the event from calendar, the notification is not sent to attendees and also event from attendees's calendar is not deleted. (56851)

    Hardware Support

    "stat get system.voltage" command does not work. (56891)

    MTA

    When recipient domain is not resolvable, the mail is delivered to user on local machine. (57040)

    If a user with auto reply enabled receives an e-mail which has the "Reply-to" header split over more than one line then the user can receive a non-delivery report relating to the auto reply. (57051)

    Users are unable to set both a forward and an auto reply at the same time. (11909)

    Webmail

    In certain circumstances the display name is not displayed correctly when a reply is sent from WebMail to Mac OSX. (57084)

    Error after double-clicking checkbox in sharing controls. Once user double clicks any of the check box under Options" -> "SharingControls", subsequent single/double click on those check boxes will result in checkbox getting converted to text box. (56809)

    Signature is displayed incorrectly above compose window in IE8. (57003)

    If the user is logged into a portal page, logging out redirects to the respective login page of webmail edition and not to the portal page login. (56944)

    Users are not displayed in the Sharing Control section of the UI when they have been enabled with read or write permissions. This occurs with IE9 only. (56379)

    Deleted contact appears in "Edit Group" dialog box. "Invalid contact index" displays when you click "Ok". This issue no longer appears after logout/ login. (56793)

    The WebMail address book can crash if patch E4_3_CE42_US_3 is installed and named brands are present for delegated domains. (57042)

    When 'ldapautoreply' is enabled, users with a dot in their username (eg. fred.bloggs) are unable to set an auto reply message correctly. (55304)

    LDAP address book queries will not display the common name attrbiute (cn) in Corporate Edition Webmail. (56370)

    View Article
  • Posted: March 3, 2011End of Support: December 31, 2015For detailed information on this release, see the Release Notes.For a list of known reported issues at the time of this release, see Known Issues.For complete documentation on the MOS 4.3.4 release, see the MOS 4.3 Product Guides.

    Download Information

    For MOS 4.1.9 and later 4.1: ftp://ftp.mirapoint.com/pub/updates/R4_3_4_GA.mpu5(873199772, 1cc8c320384bf8599dd39cb872ad68f4)For MOS 4.2.1 and later 4.2, or 4.3.0 through 4.3.2: ftp://ftp.mirapoint.com/pub/updates/P4_3_4_GA.mpu5(705670724, 414e57fb72dd51b25f6f754907ec5039)

    Recommended Patches, Late-Breaking Issues

    Problem Description

    Fix Information

    !!

    Addresses glibc 'GHOST' security issues (CVE-2015-0235).

    Install D4_glibc_security to fix this potential problem.

    !!

    Addresses NTP security issues (CVE-2014-9293, CVE-2014-9294, CVE-2014-9295).

    Install D4_ntp_security to fix this problem.

    !!

    Addresses bash 'shellshock' bug.

    Install D4_bash_security_2 to fix this problem.

    !!

    Addresses a number of SSL security issues, including the recently published POODLE vulnerability.

    Install D4_3_5_sslv3_option to fix this problem.

    !!

    TLSv1.1 and TLSv1.2 are available.

    Install E4_3_5_TLSv12_3 to fix this problem.

    R

    Multiple bad logins previously caused an interruption of service due to a LDAP failover

    Install D4_3_4_ldapfailover to fix this problem.

    R

    Updates Corporate Edition Webmail to support the latest versions of the Chrome browser.

    Install D4_3_7_webmail_compose_2 to fix this problem.

    R

    Updates Corporate Edition Webmail to support the latest versions of the Chrome browser for Chinese locales.

    Install D4_3_7_webmail_compose_zs_CN_2 to fix this problem.

    R

    Corrects blackhole duration settings (MIRA-55000).

    Install D4_blackhole_timeout to fix this problem.

    O

    With this patch autoreply messages honour the 'Auto-Submitted:' header of incoming messages.

    Install D4_3_autoreply to fix this problem.

    Note: Mirapoint's policy is to always integrate patches created to address known problems into the next patch release.

    !!

    Strongly recommended

    R

    Recommended

    O

    Optional

    I

    Contact support for information

    View Article
  • Posted: March 3, 2011End of Support: December 31, 2015For detailed information on this release, see the Release Notes.For a list of known reported issues at the time of this release, see Known Issues.For complete documentation on the MOS 4.3.3 release, see the MOS 4.3 Product Guides.MOS 4.3.3a-GA provides a new P-patch which fixes an issue where appliances previously updated with R-patches could fail to restart after upgrading to MOS 4.3.3 using its P-patch.If you are upgrading an appliance that was previously upgraded using an R-patch, use the R-patch to upgrade to MOS 4.3.3.The P4_3_3_GA installer links to the newest installer. Customers who have cached copies of this update should use the newer install path (with a "a" before the "GA") instead of the older path.

    Download Information

    For MOS 4.1.9 and later 4.1: ftp://ftp.mirapoint.com/pub/updates/R4_3_3_GA.mpu5(864848428, 20aa73fb929e6f1307f90001629affbe)For MOS 4.2.1 and later 4.2, or 4.3.0 through 4.3.2: ftp://ftp.mirapoint.com/pub/updates/P4_3_3a_GA.mpu5(694927620, 54f01e63cfb22d0fe5dc751b93ca47ba)

    Recommended Patches, Late-Breaking Issues

    Problem Description

    Fix Information

    !!

    Addresses glibc 'GHOST' security issues (CVE-2015-0235).

    Install D4_glibc_security to fix this potential problem.

    !!

    Addresses NTP security issues (CVE-2014-9293, CVE-2014-9294, CVE-2014-9295).

    Install D4_ntp_security to fix this problem.

    !!

    Addresses a number of SSL security issues.

    Install D4_4_ssl_security_2 to fix this problem.

    !!

    Addresses a number of SSL security issues.

    Install D4_3_3_ssl_security to fix this problem.

    !!

    The nicknames field for users' contacts disappear after upgrade to MOS 4.3.3 and accessing WebMail contacts a second time.

    Install D4_3_3_addrbook to fix this problem.

    !!

    TLSv1.1 and TLSv1.2 are available.

    Install E4_3_3_TLSv12_3 to fix this problem.

    R

    Corrects blackhole duration settings (MIRA-55000).

    Install D4_blackhole_timeout to fix this problem.

    O

    MOS 4.3 provides only WebMail/WebCal Corporate Edition version 2, but not version 1 which was available on MOS 4.2 and earlier releases.

    Install E4_3_CE42_US_2 to provide Corporate Edition version 1 (English) on a MOS 4.3 appliance.

    O

    MOS 4.3 provides only WebMail/WebCal Corporate Edition version 2, but not version 1 which was available on MOS 4.2 and earlier releases.

    Install E4_3_CE42_JP_2 to provide Corporate Edition version 1 (Japanese) on a MOS 4.3 appliance.

    O

    With this patch autoreply messages honour the 'Auto-Submitted:' header of incoming messages.

    Install D4_3_autoreply to fix this problem.

    Note: Mirapoint's policy is to always integrate patches created to address known problems into the next patch release.

    !!

    Strongly recommended

    R

    Recommended

    O

    Optional

    I

    Contact support for information

    View Article
  • Posted: March 3, 2011End of Support: December 31, 2014For detailed information on this release, see the Release Notes.For a list of known reported issues at the time of this release, see Known Issues.For complete documentation on the MOS 4.3.2 release, see the MOS 4.3 Product Guides.

    Download Information

    For MOS 4.1.9 and later 4.1: ftp://ftp.mirapoint.com/pub/updates/R4_3_2_FCS.mpu5(860908036, c0b34926f1bec3e6fdf21c85468f3b4a)For MOS 4.2.1 and later 4.2, or 4.3.0 through 4.3.1: ftp://ftp.mirapoint.com/pub/updates/P4_3_2_FCS.mpu5(690965228, 090239ffbee9fd2435d919588b433d09)

    Recommended Patches, Late-Breaking Issues

    Problem Description

    Fix Information

    !!

    Addresses NTP security issues (CVE-2014-9293, CVE-2014-9294, CVE-2014-9295).

    Install D4_ntp_security to fix this problem.

    !!

    Addresses a number of SSL security issues.

    Install D4_4_ssl_security_2 to fix this problem.

    !!

    Addresses a number of SSL security issues.

    Install D4_3_3_ssl_security to fix this problem.

    !!

    TLSv1.1 and TLSv1.2 are available.

    Install E4_3_3_TLSv12_3 to fix this problem.

    R

    Resolves diagnostic file generation problem

    Install D4_diagdata_1 to fix this problem.

    R

    Corrects blackhole duration settings (MIRA-55000).

    Install D4_blackhole_timeout to fix this problem.

    O

    Allows the use of 2048-bit SSL keys

    Install E4_sslkey_2048 to fix this problem.

    O

    With this patch autoreply messages honour the 'Auto-Submitted:' header of incoming messages.

    Install D4_3_autoreply to fix this problem.

    Note: Mirapoint's policy is to always integrate patches created to address known problems into the next patch release.

    !!

    Strongly recommended

    R

    Recommended

    O

    Optional

    I

    Contact support for information

    View Article
  • Posted: March 3, 2011End of Support: December 31, 2014For detailed information on this release, see the Release Notes.For a list of known reported issues at the time of this release, see Known Issues.For complete documentation on the MOS 4.3.1 release, see the MOS 4.3 Product Guides.MOS 4.3.1a-FCS fixes several critical issues, including difficulties with upgrade, and mail delivery when LDAP is misconfigured.The R4_3_1_FCS and P4_3_1_FCS installers link to the newest installers. Customers who have cached copies of this update should use the newer install path (with a "a" before the "FCS") instead of the older path.

    Download Information

    For MOS 4.1.9 and later 4.1: ftp://ftp.mirapoint.com/pub/updates/R4_3_1_FCS.mpu5(610118188, 4e728381d84a7a591d5afc4a01931537)For MOS 4.2.1 and later 4.2, or 4.3.0: ftp://ftp.mirapoint.com/pub/updates/P4_3_1_FCS.mpu5(408546764, dda3c32c2db6af464385ffd40595ac63)

    Recommended Patches, Late-Breaking Issues

    Problem Description

    Fix Information

    !!

    Addresses NTP security issues (CVE-2014-9293, CVE-2014-9294, CVE-2014-9295).

    Install D4_ntp_security to fix this problem.

    !!

    Addresses a number of SSL security issues.

    Install D4_4_ssl_security_2 to fix this problem.

    !!

    Addresses a number of SSL security issues.

    Install D4_3_1_ssl_security to fix this problem.

    R

    Resolves diagnostic file generation problem

    Install D4_diagdata_1 to fix this problem.

    R

    Corrects blackhole duration settings (MIRA-55000).

    Install D4_blackhole_timeout to fix this problem.

    O

    Allows the use of 2048-bit SSL keys

    Install E4_sslkey_2048 to fix this problem.

    O

    With this patch autoreply messages honour the 'Auto-Submitted:' header of incoming messages.

    Install D4_3_autoreply to fix this problem.

    Note: Mirapoint's policy is to always integrate patches created to address known problems into the next patch release.

    !!

    Strongly recommended

    R

    Recommended

    O

    Optional

    I

    Contact support for information

    View Article
  • Release Date: June 30, 2014End of Support: TBA

    Major New Features in MOS 4.4:

    For more information on these or any other features, see the Release Notes on the page for the specific release.

    Support for 8-series hardware platform

    WebMail/WebCal Corporate Edition - completely new user interface, with new features including:

    Tagging

    Real-Time Mail

    XML API Version 3

    Faster internal database server

    For detailed information on this release, see the Release Notes.For a list of known reported issues at the time of this release, see Known Issues.For complete documentation on the MOS 4.4.2 release, see the MOS 4.4 Product Guides.MOS 4.4.2b-FCS fixes several critical issues, including difficulties with upgrade, and mail delivery when LDAP is misconfigured.

    Download Information:

    For MOS 4.2.x and later: ftp://ftp.mirapoint.com/pub/updates/R4_4_2b_FCS.mpu5(725104516, 4912f0cb9a83ff7d701e6fac9285329a)

    Recommended Patches, Late-Breaking Issues:

    Problem Description

    Fix Information

    !!

    Addresses glibc 'GHOST' security issues (CVE-2015-0235).

    Install D4_glibc_security to fix this potential problem.

    !!

    Addresses NTP security issues (CVE-2014-9293, CVE-2014-9294, CVE-2014-9295).

    Install D4_ntp_security to fix this problem.

    !!

    Addresses bash 'shellshock' bug.

    Install D4_bash_security_2 to fix this problem.

    !!

    Addresses a number of SSL security issues, including the recently published POODLE vulnerability.

    Install D4_4_sslv3_option to fix this problem.

    !!

    Fix to prevent excessive database connection build-up

    Install D4_4_2_connection_leak to fix this problem.

    !!

    Removes an XSS vulnerabilty in Corporate Edition webmail

    Install D4_4_2_webmail to fix this problem.

    !!

    Allows successful selective restore from image backup.

    Install D4_4_3_restore_5 to fix this problem.

    !!

    Fixes high SSL connection level count

    Install D4_4_2_sslrelay to fix this problem.

    !!

    Allows branding uploads to succeed

    Install D4_4_2_branding to fix this problem.

    !!

    TLSv1.1 and TLSv1.2 are available.

    Install E4_4_TLSv12_3 to fix this problem.

    R

    Allows checking RAID battery status on 8-series hardware

    Install D4_4_2_raidadmmon to fix this problem.

    R

    Updates Corporate Edition Webmail to support the latest versions of the Chrome browser.

    Install D4_4_3_webmail_compose_2 to fix this problem.

    R

    Updates Corporate Edition Webmail to support the latest versions of the Chrome browser for Chinese locales.

    Install D4_4_3_webmail_compose_zs_CN_2 to fix this problem.

    R

    Corrects blackhole duration settings (MIRA-55000).

    Install D4_blackhole_timeout to fix this problem.

    Note: Mirapoint's policy is to always integrate patches created to address known problems into the next patch release.

    !!

    Strongly recommended

    R

    Recommended

    O

    Optional

    I

    Contact support for information

    View Article
  • Release Date: June 30, 2014End of Support: TBAFor documentation on MOS 4.4 releases, see the MOS 4.4 Product Guides.For detailed upgrade information for this release, see the Upgrade Instructions.

    Major New Features in MOS 4.4:

    For more information on these or any other features, see the Release Notes on the page for the specific release.

    Support for 8-series hardware platform

    WebMail/WebCal Corporate Edition - completely new user interface, with new features including:

    Tagging

    Real-Time Mail

    XML API Version 3

    Faster internal database server

    MOS 4.4.5a download information:

    For MOS 4.2.x and earlier: ftp://ftp.mirapoint.com/pub/updates/R4_4_5a_GA.mpu5(size: 798058332, md5sum: f8808b7fc1eba9dd3433245ebd51a5a7)For MOS 4.3.x and later: ftp://ftp.mirapoint.com/pub/updates/P4_4_5a_GA.mpu5(size: 638443252, md5sum: 189cc3adf5d6b0dfd443e317bbd1c768)

    Recommended Patches, Late-Breaking Issues

    Problem Description

    Fix Information

    !!

    Addresses glibc 'GHOST' security issues (CVE-2015-0235).

    Install D4_glibc_security to fix this potential problem.

    !!

    Addresses NTP security issues (CVE-2014-9293, CVE-2014-9294, CVE-2014-9295).

    Install D4_ntp_security to fix this problem.

    !!

    Addresses bash 'shellshock' bug.

    Install D4_bash_security_2 to fix this problem.

    !!

    Addresses a number of SSL security issues, including the recently published POODLE vulnerability.

    Install D4_4_5_sslv3_option to fix this problem.

    !!

    Fixes a database deadlock issue that may affect service.

    Install D4_4_5_mailbox_lock_4 to fix this problem.

    !!

    TLSv1.1 and TLSv1.2 are available.

    Install E4_4_4_TLSv12_3 to fix this problem.

    R

    Corrects blackhole duration settings (MIRA-55000).

    Install D4_blackhole_timeout to fix this problem.

    Note: Mirapoint's policy is to always integrate patches created to address known problems into the next patch release.

    !!

    Strongly recommended

    R

    Recommended

    O

    Optional

    I

    Contact support for information

    Fixed Issues: 4.4.5

    Addressbook

    In webmail, when selecting multiple addresses from multiple address book searches, the selected addresses are maintained across searches. Previously, only the last selection was remembered. (MIRA-52350)

    Administration

    The 'restore to factory settings' function is no longer supported and has been removed from the product. A re-install is now necessary to fully reset the product. (MIRA-52970)

    The command 'Mtaverify Set AllowedEntryLifetime' now accepts longer periods of time than represented by a single digit. For example, previously a value of 36d would be rejected but 9d would be accepted, now 36d is accepted. (MIRA-50661)

    Importing UCE exceptions for a single user, via the CLI, now works correctly. (MIRA-52776)

    MOS now honours the header 'Auto-Submitted:' and will not generate an auto reply message to emails that contain that header. (MIRA-53108)

    A configuration restore, that contains 'trustedhost' groups, now successfully completes. (MIRA-53139)

    Fully deprecated Kerberos IV from MOS. (MIRA-53173)

    Fixed a problem with the Kerberos V client that would cause it to fail to authenticate clients. (MIRA-53175)

    Restoring a configuration file with multiple 'mtaverify' servers now succeeds. (MIRA-53044)

    After performing a selective restore on a users 'Trash' folder, all restored mails are now correctly visible to the user. (MIRA-53131)

    Email headers are now logged correctly, in full. Previously, some headers were missing the first few characters. (MIRA-46253)

    Logs now correctly report the size of an auto reply generated email. (MIRA-51237)

    Including log events ADMIN.* by default as a log route, this restores the default log configuration of previous MOS versions. (MIRA-53070)

    Calendar

    Corrected an issue that could rarely cause some calendar instability. (MIRA-53210)

    Clustering

    A warning is now generated if a replica server is running out of disk space. (MIRA-54822)

    Filtering

    Invalid recipient addresses could cause filtering to fail and messages remain in the mail queue, this behaviour has now been corrected by performing address verification before filtering. (MIRA-53237)

    Hardware Support

    On systems that have had their RAID controller changed to LSI controllers, MOS will now properly report failed drives. (MIRA-52171)

    IMAP

    IMAP in 'ldapproxy' mode now supports the authentication mechanism 'plain'. (MIRA-22785)

    When an IMAP client is performing a folder operation (rename, move, delete), all other IMAP folder operations on that folder are dishonoured. This means IMAP folder operations create an exclusive lock on that folder until the operation is complete. (MIRA-53101)

    The IMAP log format is now correct when 'derivedomainip' is configured. (MIRA-53224)

    Corrected an IMAP proxy instability issue. (MIRA-53253)

    MTA

    Before this release, an invalid auto reply message for a user may cause mail to that user to be queued. Now, invalid auto reply messages are ignored and not processed, mail will be delivered to the users INBOX normally. (MIRA-40328)

    If no RBL servers are defined, but RBL checking is turned on, now RBL checking is ignored. Previously, connecting SMTP clients would receive 'connection refused'. (MIRA-44878)

    The SMTP server will continue to accept connections when the 'misbehaving mailer list' reaches it's 1024 limit. Previously, the SMTP server would refuse connections when the limit was reached. (MIRA-52123)

    The setting 'smtp set identhost' now takes immediate effect. (MIRA-52257)

    Users are able to set both a forward and an auto reply at the same time, and both will apply. (MIRA-11618)

    SPF now correctly handles the case where an IP has no corresponding PTR record in DNS. (MIRA-52449)

    Monitoring

    Increased the limit for CPU temperature warnings for 8-series equipment, as these limits were set too low and generated false alerts. (MIRA-53110)

    The command 'stat get system.totalinboxes' now correctly reports. (MIRA-53182)

    Published updated SNMP MIB files for 7 and 8 series equipment. (MIRA-53181)

    Operating System

    Renaming a shared mailbox folder in webmail now works correctly. (MIRA-52628)

    After upgrading to MOS v4.4.4, some users would see hung IMAP connections or errors reported when the INBOX was selected. The underlying cause was found and corrected in this version. (MIRA-53142)

    Previously, concurrent IMAP connections to the same folder would cause timeouts. Now concurrent connections use a more fine-grained locking mechanism so that more concurrent operations may be supported. (MIRA-53197)

    Performing rapid quota "get" and "set" operations no longer results in database connectivity issues. (MIRA-53254)

    m8800 systems may be successfully upgraded to this release using either R or P patches. (MIRA-53187)

    Corrected a problem upgrading to 4.4 releases, from an older release, onto systems that have more than one disk shelf, eg. M8800. (MIRA-53188)

    When upgrading 8x00-series equipment that has multiple network interfaces or network failover configured, the network configuration is maintained after upgrade with an R patch. (MIRA-53189)

    SAN connected systems now correctly report the state of all paths, consistently, across monitoring tools. (MIRA-52187)

    When connecting a new head unit to an existing SAN LUN, for example upgrading from an s6000 to s8000 head unit, the command 'model get chassis' now reports correctly as the new head unit. (MIRA-53176)

    Security

    Enhancements made to Sophos AS 'outbound' mode so that anti-spam scanning is more accurate. This is automatically available to any Sophos AS customers via automatic anti-spam updates, so upgrade to this version is not explicitly required to gain access to this enhancement. (MIRA-53204)

    MOS now correctly removes the 'X-Junkmail:' header from a message if the domain is whitelisted. (MIRA-53280)

    Webmail

    Corporate Edition (v2) webmail will now prompt for confirmation if the 'Subject' field is blank. (MIRA-48602)

    The default cursor position is now the 'To:' field when composing a new message in webmail. (MIRA-51798)

    Long lines in an email (greater than 1000 characters) with utf-7 or utf-8 encoding, no longer have an exclamation mark inserted into them. (MIRA-41918)

    Corporate Edition (v2) now allows users to specify a HTML signature. (MIRA-53010)

    Webmail users will no longer, occasionally, encounter an 'Internal Error' messaging when performing a spell check. (MIRA-53032)

    Webmail Standard Edition now correctly displays Japanese characters in the 'Subject' field. (MIRA-53185)

    Occasional webmail instability issues have been addressed. (MIRA-53190)

    Webmail now correctly expands groups that are specified as recipients in a compose window. (MIRA-53194)

    Corporate Edition webmail now returns correct results when performing an address book search using a term that contains double-byte characters. (MIRA-53214)

    Webmail now correctly displays events for resources that are used in recurrent events. (MIRA-53226)

    Corrected a problem where links contained in emails sent by Junkmail Manager to users, would result in errors when clicked. (MIRA-53241)

    After sorting a folder message list, in Standard Edition webmail, when a message is selected, the correct message is displayed to the user. (MIRA-53245)

    Copyright notices updated. (MIRA-54950)

    Patches Included

    D4_3_5_addressbook_history

    D4_3_7_JMM_deletion

    D4_3_7_SP_1

    D4_3_7_dptadmmon_diskfails

    D4_3_7_imap_folder2

    D4_3_7_imap_proxy_auth_plain

    D4_3_7_stat_totalinboxes

    D4_3_7_webmail_core_2

    D4_3_autoreply

    D4_3_uce_exceptions

    D4_4_3_calendar_repeat_event

    D4_4_3_imap_folder2

    D4_4_3_proxy_dnscache

    D4_4_3_webmail_encode_2

    D4_4_4_calendar_repeat_event

    D4_4_4_healthm_cpu

    D4_4_4_imap_loop_and_cache

    D4_4_4_mmfid_core_address

    D4_4_4_proxy_dnscache

    D4_4_4_webmail_se_subject

    D4_4_4_webmail_sort

    D4_4_autoreply

    D4_4_ssl_security_2

    Known Issues:

    Addressbook

    Deleted contact appears in "Edit Group" dialog box. "Invalid contact index" displays when you click "Ok". This issue no longer appears after logout/ login. (MIRA-52543)

    Administration

    If the total number of JMM users exceeds the regular "user limit" license, you are unable to add regular users to a system - this is not the intended design. (MIRA-33781)

    The "Return-Path" header is not treated consistently during message filtering, sometimes it is removed and other times it is not. (MIRA-44277)

    Branding

    "ERROR file too large" message is received when publishing a brand file which contains the Chinese locale brand files. (MIRA-52679)

    Calendar

    The "Repeat until" date is changed after saving the event. This can lead to a repeated event's last instance not appearing in a user's calendar if they are in a different timezone. (MIRA-52549)

    In calendar when Time Mode = 24 hrs and Day spans from 0 to 24 hrs, new event created at 0:00-1:00 appears twice in "Horizontal Week View". Once on previous day after 23:00 hr cell and another at correct place at 0:00 cell. (MIRA-52563)

    Repeated event can't be viewed by person with whom the calendar is shared if the user is given read/write permission. (MIRA-52566)

    When owner deletes the event from calendar, the notification is not sent to attendees and also event from attendees's calendar is not deleted. (MIRA-52600)

    "No conflict" alert is shown when creating an all day event, although there exist a regular event on the same day. (MIRA-52700)

    Unable to open/download attachment from any event instance belonging to repeating events in CE. (MIRA-52725)

    Calender CE uses local machine time to decide age of an event. (MIRA-52734)

    All day event cannot be changed to event less than All day. (MIRA-52828)

    Hardware Support

    "stat get system.voltage" command does not work. (MIRA-52637)

    MTA

    If a user with auto reply enabled receives an e-mail which has the "Reply-to" header split over more than one line then the user can receive a non-delivery report relating to the auto reply. (MIRA-52793)

    Webmail

    Users are not displayed in the Sharing Control section of the UI when they have been enabled with read or write permissions. This occurs with IE9 only. (MIRA-52168)

    Error after double-clicking checkbox in sharing controls. Once user double clicks any of the check box under Options" -> "SharingControls", subsequent single/double click on those check boxes will result in checkbox getting converted to text box. (MIRA-52559)

    If the user is logged into a portal page, logging out redirects to the respective login page of webmail edition and not to the portal page login. (MIRA-52690)

    View Article
  • Release Date: October 30, 2013End of Support: TBA

    For documentation on MOS 4.4 releases, see the MOS 4.4 Product Guides.For detailed upgrade information for this release, see the Upgrade Instructions.

    Major New Features in MOS 4.4:

    For more information on these or any other features, see the Release Notes on the page for the specific release.

    Support for 8-series hardware platform

    WebMail/WebCal Corporate Edition - completely new user interface, with new features including:

    Tagging

    Real-Time Mail

    XML API Version 3

    Faster internal database server

    MOS 4.4.4-GA fixes several webmail issues and important updates to the internal database servers. Additionally, this release increases the speed of filtering and increases the number of LUN grows from 4 to 8.

    MOS 4.4.4 Download Information:

    For MOS 4.2.x and earlier: ftp://ftp.mirapoint.com/pub/updates/R4_4_4c_GA.mpu5(size: 797961388, md5sum: 0769cf089e9a65f6d56d90e6a0631e21)For MOS 4.3.x and later: ftp://ftp.mirapoint.com/pub/updates/P4_4_4a_GA.mpu5(size: 638398252, md5sum, md5sum: 2ca415701e9d943e2861244881978062)

    Recommended Patches, Late-Breaking Issues:

    Problem Description

    Fix Information

    !!

    Addresses glibc 'GHOST' security issues (CVE-2015-0235).

    Install D4_glibc_security to fix this potential problem.

    !!

    Addresses NTP security issues (CVE-2014-9293, CVE-2014-9294, CVE-2014-9295).

    Install D4_ntp_security to fix this problem.

    !!

    Addresses bash 'shellshock' bug.

    Install D4_bash_security_2 to fix this problem.

    !!

    Addresses a number of SSL security issues, including the recently published POODLE vulnerability.

    Install D4_4_4_sslrelay to fix this problem.

    !!

    Corrects an internal database issue where a a lock is unable to be obtained for some users. This patch is required on all message stores and Razorgate systems running JMM.

    Install D4_4_4_imap_loop_and_cache to fix this problem.

    !!

    TLSv1.1 and TLSv1.2 are available.

    Install E4_4_4_TLSv12_3 to fix this problem.

    R

    Corrects a problem where the POP mailbox for a user would be locked unintentionally.

    Install D4_4_4_pop_userlock to fix this problem.

    R

    Corrects blackhole duration settings (MIRA-55000).

    Install D4_blackhole_timeout to fix this problem.

    Note: Mirapoint's policy is to always integrate patches created to address known problems into the next patch release.

    !!

    Strongly recommended

    R

    Recommended

    O

    Optional

    I

    Contact support for information

    Fixed Issues: 4.4.4

    Administration

    Renaming a parent folder now propagates to all child folder names. Previously, in some cases, this change would not propagate. (56507)

    MOS was not honouring the setting of '0' against the "mon setthresh system.(service)*resp" command. The system should no longer monitor the service when set to '0'. (57064)

    Message expiration will now correctly honour the insert date for all messages in a mailbox. (57202)

    Selective restores from image based backups, including local disk backups, will now restore correctly. (57204)

    Calendar

    When an event is updated using the XML interface, the owner is no longer moved to an 'external attendee'. (57247)

    Documentation

    Removed from the system alert online help the "mon setthresh" parameters which can not be set. (56407)

    Various updates to end user online help pages in Webmail. (56582)

    Various errors and corrections made to online help and administration manuals. (57154)

    Filtering

    Using either ':envelopeto' or ':tocc' filter condition with the 'matches' test now correctly activates when using a non-local user part in an email address. Previously the test would not match if, for example, a users alias was specified in the condition. (45609)

    MOS now processes X-Junkmail headers according to the following rules: If antispam is enabled, rename any existing X-Junkmail header to X-pre-Mira-Junkmail. If a message is from a trustedhost, keep the X-Junkmail header. Do not change the X-Junkmail header if antispam is not enabled. (56938)

    An identified small memory leak has been corrected. (57201)

    Restored filtering speed. Recent MOS versions have experienced slower filtering than older releases. (57265)

    Disclaimers with position set to 'top' now preserves the original email contents. Previously some lines may have been overwritten in some instances. (57363)

    IMAP

    When a folder is locked by an external IMAP client, folder deletes are not honoured. (57376)

    MTA

    Junk Mail Manager now honours NOTIFY= flags included in SMTP commands. Previously NOTIFY= flags were silently dropped. (55871)

    Operating System

    Administrators may now set the number of bits used when creating SSL keys. The default value is now 2048, the maximum value for the number of bits may be set to 8192. This is achieved using the new commands 'ssl sethostkeybits' and 'ssl gethostkeybits' - please see the administrators guide for more details. (49513)

    While adding very large lists of users quickly (100,000+), the internal database no longer creates an internal deadlock. (56516)

    All known SSL vulnerabilities have been removed. This version of MOS received an 'A' rating for SSL security. (56689)

    Added support for new, more secure, SSL ciphers. (56874)

    MOS now supports up to 8 'grow' operations on SAN LUN's. Previously only 4 were supported. (57164)

    Database connection leak fixed. (57218)

    Various enhancements made to internal database servers creating more a reliable MOS service. (57270)

    Speed improvements made in querying SAN LUN's. (57274)

    Updates to the Israeli timezone files. (57367)

    Security

    Introduced a dedicated outbound mode for Premium Antispam. Commands introduced are: uce set/get premiummode (outbound|default) - see administrators guide for more details. (57291)

    Webmail

    When 'ldapautoreply' is enabled, users with a dot in their username (eg. fred.bloggs) are now able to set an auto reply message correctly. (55304)

    LDAP address book queries would not display the common name attrbiute (cn) in Corporate Edition Webmail. (56370)

    In Webmail Corporate Edition, word wrapping appears correctly in all browsers after performing a spell check. (56389)

    Webmail Corporate Edition now handles HTML attachments correctly. (56911)

    When multiple Corporate Edition Webmail windows are open, hitting reply will quote the correct email in the compose window. (57158)

    Corporate Edition now correctly handles base64 encoded line feed characters. (57186)

    Corporate Edition now allows correct editing of draft messages after deleting another draft from the Drafts folder. Previously the draft would appear un-editable. (57193)

    Copyright notices updated. (57258)

    Corrected a problem found in Standard Edition Webmail where next/last links would be incorrectly disabled under certain conditions. (57296)

    Corporate Edition Webmail now correctly line wraps when the user has a signature defined. (57301)

    Corporate Edition now correctly handles and honours font settings in all browsers. (57303)

    Address book entries containing a comma are now correctly handled when a message is composed to, or an invitation sent out to that contact. (57349)

    Some language translation issues were corrected. (57359)

    Corporate Edition now correctly supports the latest versions of the Chrome web browser. (57364)

    Patches included:

    D4_3_6_ldapautoreply_2 (57255)

    D4_4_3_restore_5, D4_3_7_restore_5 (57263)

    D4_4_2_connection_leak (57267)

    D4_3_7_filter_speed (57282)

    D4_3_6_webmail_wrap_2 (57295)

    D4_3_7_webmail_html_display, D4_3_7_webmail_ce_display (57360)

    D4_3_6_timezone (57368)

    D4_3_7_filter_disclaimer (57372)

    D4_4_3_jmm, D4_3_7_jmm (57379)

    D4_4_3_imap_folder, D4_3_7_imap_folder (57389)

    D4_4_ssl_security (50492)

    Known Issues: 4.4.4

    Administration

    The "Return-Path" header is not treated consistently during message filtering, sometimes it is removed and other times it is not. (48010)

    The "MON Clear" command does not clear the alerts returned by the "MON Status" command. (57087)

    Cannot import UCE exceptions for a single specified user. (57034)

    If the total number of JMM users exceeds the regular "user limit" license, you are unable to add regular users to a system - this is not the intended design. (36043)

    Branding

    "ERROR file too large" message is received when publishing a brand file which contains the Chinese locale brand files. (56933)

    Calendar

    All day event cannot be changed to event less than All day. (57088)

    The "Repeat until" date is changed after saving the event. This can lead to a repeated event's last instance not appearing in a user's calendar if they are in a different timezone. (56799)

    "No conflict" alert is shown when creating an all day event, although there exist a regular event on the same day. (56954)

    In calendar when Time Mode = 24 hrs and Day spans from 0 to 24 hrs, new event created at 0:00-1:00 appears twice in "Horizontal Week View". Once on previous day after 23:00 hr cell and another at correct place at 0:00 cell. (56813)

    Event update by person with whom the calendar is shared with write access doesn't work as expected. (56814)

    Repeated event can't be viewed by person with whom the calendar is shared if the user is given read/write permission. (56816)

    Unable to open/download attachment from any event instance belonging to repeating events in CE. (56981)

    Calender CE uses local machine time to decide age of an event. (56990)

    When owner deletes the event from calendar, the notification is not sent to attendees and also event from attendees's calendar is not deleted. (56851)

    Hardware Support

    "stat get system.voltage" command does not work. (56891)

    MTA

    When recipient domain is not resolvable, the mail is delivered to user on local machine. (57040)

    If a user with auto reply enabled receives an e-mail which has the "Reply-to" header split over more than one line then the user can receive a non-delivery report relating to the auto reply. (57051)

    Users are unable to set both a forward and an auto reply at the same time. (11909)

    Webmail

    In certain circumstances the display name is not displayed correctly when a reply is sent from WebMail to Mac OSX. (57084)

    Error after double-clicking checkbox in sharing controls. Once user double clicks any of the check box under Options" -> "SharingControls", subsequent single/double click on those check boxes will result in checkbox getting converted to text box. (56809)

    Signature is displayed incorrectly above compose window in IE8. (57003)

    If the user is logged into a portal page, logging out redirects to the respective login page of webmail edition and not to the portal page login. (56944)

    Users are not displayed in the Sharing Control section of the UI when they have been enabled with read or write permissions. This occurs with IE9 only. (56379)

    Deleted contact appears in "Edit Group" dialog box. "Invalid contact index" displays when you click "Ok". This issue no longer appears after logout/ login. (56793)

    View Article
  • ConnectR 5.1 Release Notes

    ConnectR 5.1 (build 5.1.0) is the latest release of the Openwave Messaging add-in to Microsoft Outlook that synchronizes:

    Calendar events, to-do/task items, and address book contacts between your Message Server and Outlook

    Data, both ways -- Outlook to Message Server, and vice versa

    Immediately when you enter or edit a calendar event, task/to-do item, or contactNote: ConnectR is a data synchronization tool only, and cannot be used to migrate users from a Microsoft Exchange server to a Mirapoint Message Server.

    ConnectR 5.1 requires a Message Server appliance running either of the following:

    Messaging Operating System (MOS) 4.1.6 or higher.

    Messaging Operating System (MOS) 3.10.6 or higher.

    Important:

    If upgrading from a pre-5.x version of ConnectR, each person in your end-user population should run a clean sync after upgrading to the new ConnectR client. See Synchronizing Your Calendar From Scratch for instructions that you can pass on to your end-users.

    Ensuring that you have the latest Windows updates.

    ConnectR must be uninstalled when Microsoft Outlook has been installed. When you want to uninstall Microsoft Outlook from your computer, you must uninstall ConnectR first.

    If ConnectR was disabled by Outlook2013 and cause a crash, please change the setting of Add-ins in Outlook. Go to Outlook File menu -> Info -> Manage Add-ins, select Mirapoint ConnectR, and then select Always enable this add-in.

    ConnectR does not support OST file as the outlook data file in Outlook 2013. Before Configuring ConnectR, if you used OST file as the outlook data file to save calendar, contact and task, please change the OST file to PST file first. The details are in the user guide.

    Enhancement in the 5.1 Release

    Support Outlook 2013

    Fixes In the 5.1 Release

    Cannot add shared user. (57498)

    ConnectR was disabled after open Outlook2013. (57502)

    Need to add "Outlook 2013" to "InstallShield Wizard". (57506)

    If the outlook is un-installed firstly, the ConnectR will not be removed.(57508)

    ConnectR cannot display well in OL 2013. (57544)

    Known Issues In This Release

    If your environment includes a proxy server, you cannot synchronize your calendars if the XML versions installed on the proxy and your appliance are different from each other. The most common scenario is when the XML version on the proxy is a lower version than the version on your appliance. (The XML version running on an appliance determined by the MOS release installed.)Workaround: Make sure the XML version on both appliances are the same. (44680)

    Redirected meeting invitations (invitations that are originally sent to a grantor but redirected to a delegate) are identical to those that appear in the delegate's Inbox. (43424)

    If a delegate invites his/her grantor to a meeting via Outlook, the event will not get scheduled in the grantor's calendar if the delegateacting on behalf of the grantorreads the invitation. Once the grantor opens the invitation, the event will appear in his/her calendar. Keep in mind that the grantor will see meeting invitations as long as he/she does not opt to have them sent only to the delegate. (43233)

    Your appliance and the WebCal client support dates between midnight January 1, 1970 and December 31, 2035 only. However, Microsoft Outlook does not have this restriction. If you try to synchronize events whose dates are out of this range, the appliance will ignore them and you will encounter an error notifying you that the event time is not supported by the appliance. Also, please be aware that importing a calendar file that includes an event with an out-of-range date is likely to cause problems with your WebCal calendar.Workaround: Do not enter calendar events whose dates are not within the range of midnight January 1, 1970 and December 31, 2035. (41468)

    If you install ConnectR on a computer running the Microsoft Windows Vista or Windows 7 operating system, you might encounter the following dialog boxes. The information below instructs you on what to do if these particular dialog boxes display:

    You might encounter a dialog box informing you that an unidentified program wants to access your computer:Windows 7 dialog box: information regarding this problem Vista dialog box:To ensure the successful installation of ConnectR, click Yes or the Allow option as appropriate.

    You might encounter a dialog box informing you that this program might not have installed correctly:To ensure the successful installation of ConnectR, click the This program installed correctly option.

    When you try to uninstall ConnectR on computer running Microsoft Windows Vista or Windows 7, you might encounter a dialog box informing you that an unidentified program wants to access your computer. (The dialog box is similar to the ones detailed in the previous known issue.) Click Yes or the Allow option as appropriate to continue with the uninstallation.

    There is a known problem regarding the installation of ConnectR and certain Microsoft Outlook-compatible plugins and PDAs (personal digital assistants). Important: Before installing ConnectR, you must review the and follow the instructions provided.

    In Outlook, you can visually drag a private event in a delegator's calendar to a different time slot or drag an event border to modify the time; however, the changes will not be saved. Only the grantor can modify or delete his/her private events. To visually restore the private event to its original state, refresh the Outlook display (which you can do by clicking the Mail tab and then clicking the Calendar tab again).Click No if the following dialg box displays:

    NOTE: In Outlook 2013, by default, it now turns off any add-in that adversely affects performance, resiliency, or reliability of Outlook. Outlook 2013 simply calculates that ConnectR slows down the Outlook start-up procedure and disables it. In this case, go to Outlook File menu -> Info -> Manage Add-ins, select Mirapoint ConnectR, and then select Always enable this add-in.

    Because of a known problem with Microsoft Outlook, you will be able to visually move an event within a grantor's calendar despite the grantor denying you write access. The problem manifests itself in the following scenario:

    Grantor has previously given you write permission to his/her calendar.

    Within WebCal, grantor changes your access permissions so that you can no longer add or modify events.

    Within the grantor calendar, you drag an event to a new time.Although it appears as if you modified a read-only event, your modification is not actually saved to the appliance. Once a sync occurs, the event returns to its original date and time.

    If you create profiles before the installation of ConnectR, after the installation of ConnectR, the existent profile that set as POP3 may be affected.

    Workaround:

    Select File in Microsoft Outlook.

    Select Info.

    Select Email and select Account Setting.

    If the file location is empty, select Change Folder.

    Selct New Outlook Data File and select the right file manually. We recommed that you configure the profile after ConnectR is installed or configure the profile with IMAP.

    Known Issues with Microsoft Outlook

    The following are known problems with Microsoft Outlook, independent of the ConnectR add-in:

    If you share a calendar owned by another user, both you and the owner will receive reminders set up for that calendar. (55244)

    When importing a calendar file that was exported from WebMail, Microsoft Outlook 2007 does not import repeating events correctly. Repeating events with no end date are converted to a non-repeating event. Also, if you have a repeating event with a specified end date, only the first instance appears in your Outlook calendar.(48223)

    A meeting updated from private to non-private is not reflected in an attendee's Outlook calendar even after reading the update email. This is a problem specific to Outlook 2007. (43332)

    You must restart Outlook so that the proper attendee status is reflected for an event where you have accepted selected occurrences of a recurring meeting. Specifically, the problem occurs in the following scenario: 1) In Outlook, a user schedules a recurring meeting and invites an attendee; 2) Both the meeting organizer and attendee synchronize; 3) In Outlook, the attendee accepts a single occurrence of the meeting and then synchronizes; 4) In WebCal, attendee accepts another single occurrence of the meeting and then synchronizes. In Outlook, the status for the event accepted via WebCal is "Please respond." If the attendee restarts Outlook, the correct status (accepted) is displayed.(38490)

    Synchronizing Your Calendar From Scratch

    After installing the ConnectR 5.1.x add-in, complete the following steps to synchronize your calendar from scratch:

    Login to WebMail/WebCal (Corporate Edition or Standard Edition).

    Ensure that your calendar data is correct. If necessary, resolve any conflicts or problems so that WebMail/WebCal is up to date.

    Log out of WebMail/WebCal.

    Start Microsoft Outlook.

    Click the Add-Ins tab.

    In the Add-Ins toolbar, click Clean Synchronize using ConnectR.

    In the dialog box, select theServer to Outlookradio button

    With this option, ConnectR will replace your calendar data in Outlook with the calendar data from WebMail/WebCal.

    Click Start.

    In the warning dialog box, click Yes to proceed with the clean sync.

    In the Synchronization complete dialog box, click OK.

    Note: Only calendar data is affected by a clean sync; contact and task information are not.

    View Article
  • AOS5.2.9 Release Notes: A Seamless Improvement to Exporting, Search & Redaction

    Mirapoint is committed to constantly updating and improving upon its email archiving solutions to ensure customers get the best and most relevant information possible. The following is our attempt to let you, our faithful customers, know about any and all changes weve made to our products. The latest set of release notes involves a software update to AOS5.2.9. Click here for a full list of enhancements and bug fixes.

    Changes to users.

    Exporting Emails

    There are a number of enhancements related to exporting emails. Before this release, when you exported emails you received a zip file that expanded into an HTML file describing the emails and the emails in their own files. Now that header file can be the entirety of the export; basically a list of email descriptions including who sent it, the recipients, subject, and date of the email. Not only can you get this in HTML format, but as a Microsoft Excel readable file (.csv).

    For any exported list of email, you have always had the ability to share that list with other users on the archive. With the new release, you will be able to permit users defined through LDAP (eg. Active Directory) access to your exported emails.And finally, when an export is done, the type will be included in the security audit log entry.

    Click here

    Searching

    A simple, yet profound change has been made to the Text search term. Now, when you include words or phrases in there, it will not only search the subject and body of the email, but also any indexable attachments.

    When you search on multiple terms, all the search terms appearing in the email will be highlighted, making it easier to find relevant portions of the email.Also, some of the help text for the search screen has been clarified.

    Redaction

    Redaction, added in release 5.2.8, has been improved. No longer is redaction limited to the owner of the Tag, now, any user with Tag Administration can use redaction on any email viewed through any Tag display. The redaction string will also handle situations where there may be various numbers of spaces between the words, differences in capitalization, formatting (bold, italic, etc.), and ignore punctuation. EG. redacting Chicken Little will also redact chicken. Little, chicken little, and CHICKEN LITTLE.

    Changes for Administrators

    System administration has been improved with this release. Some changes are cosmetic, like removing unnecessary warning messages from the backup details, no longer listing deleted fetchers in the nightly notification, clearer messages in the upgrade job details, and the status page being optimized to load faster. Some are substantive. Hereare the highlights.

    Migration

    You now have the ability to import emails in EML (raw) format. The migration screen allows you to point to a directory, and EML files and zipped containers holding EML files will be imported, processed, indexed, and stored like any other email.

    Migrating PST files into the system now has a drop-down menu that allows the system to use the information in the PST file to assign the owner. Previously, the assumption was that each PST file contains emails from one specific user. If this is not correct, then the Address Discovery drop down can be set to None to allow the system to extract the owner from the email. See the help text on the Migration page for more discussion on the three options of the Address Discovery parameter.We have made changes to improve migration performance for all types of migration.

    Retention

    The retention policy now allows setting retention rules based on the Tags associated with the email. For example, you can tag all the emails from the CEO and set them to never be deleted, while the rest of the emails are cleaned out based on other criteria in the retention policy.

    Deleting Email

    Administrators now have the ability to delete specific emails. The Data Retention policy is the normal way to remove emails from the archive. However, there have been instances where an administrator has been legally required to remove an email. This gives you the ability to delete it. See the Email Deletion Configuration screen under the Maintenance tab for more information on this feature. This feature is only available to customers who have a support contract.

    Miscellaneous Changes

    Rebooting, shutting down, or starting the system will be recorded in the audit log.The Message Intelligences Social Analytics screen can display emails directly (rather than give you the email information to go into the Search screen).We hope the improvements explained above will help make your experience using Mirapoint'semail archiving solutions that much easier and seamless.

    for a full list of enhancements and bug fixes.

    View Article
  • Release Date: August 19, 2015End of Support: TBAFor documentation on MOS 4.4 releases, see the MOS 4.4 Product Guides.For detailed upgrade information for this release, see the Upgrade Instructions.

    Major New Features in MOS 4.4:

    For more information on these or any other features, see the Release Notes on the page for the specific release.

    Support for 8-series hardware platform

    WebMail/WebCal Corporate Edition - completely new user interface, with new features including:

    Tagging

    Real-Time Mail

    XML API Version 3

    Faster internal database server

    MOS 4.4.7 download information:

    For MOS 4.3.x and earlier: ftp://ftp.mirapoint.com/pub/updates/R4_4_7_GA.mpu5(size:823508676, md5sum: c40c5a23ca132151a5ffa22b94c59c80)For MOS 4.4.x and later: ftp://ftp.mirapoint.com/pub/updates/P4_4_7_GA.mpu5(size:663929308, md5sum: dafada9981acebcdf026529d8c821b9b)

    Recommended Patches, Late-Breaking Issues

    Problem Description

    Fix Information

    !!

    TLSv1.1 and TLSv1.2 are available.

    Install E4_4_6_TLSv12_5 to add this security enhancement.NOTE: Install this patch to have SSH access to the server.

    O

    New language localizations avaialble.

    Install Traditional Chinese Mainland China. French. Spanish. German. Traditional Chinese Taiwan.

    Note: Mirapoint's policy is to always integrate patches created to address known problems into the next patch release.

    !!!

    Critical

    !!

    Strongly recommended

    R

    Recommended

    O

    Optional

    I

    Contact support for information

    Fixed Issues: 4.4.7

    AddressBook

    The address book CGI will no longer crash when invalid data is found, and rather display "Data exception" in the associated field when accessed via webmail. (MIRA-55274)

    Administration

    A full NDMP restore is now more reliable. (MIRA-55128)

    A new command implemented 'User Set AutoCalendarAccept' that causes some users to always accept events. This is designed to be primarily activated on resource accounts so when other users attempt to schedule the resource conflicts may be seen. (MIRA-53265)

    Corrected an issue when renaming large mailbox names would report a system i/o error. (MIRA-55117)

    Multiple IMAP sessions manipulating the same message set could, occasionally, result in inconsistent database content. (MIRA-55278)

    Corrected an issue when listing mailboxes that use multi-byte character sets. (MIRA-55108)

    Calendar

    A repeating event can now be viewed correctly by a delegate with read permission. (MIRA-52566)

    Creating an all day event will now report a conflict if a timed event exists on the same day. (MIRA-52700)

    An all day event can now be changed to event less than 'all day'. (MIRA-52828)

    When an event is updated using the XML interface, the owner is no longer moved to an 'external attendee'. (MIRA-52982)

    When an invitation email is read via IMAP or POP the event will now appear in the users calendar. (MIRA-53049)

    Updating an attachment on a recurring event now replaces the existing attachment. (MIRA-53282)

    MOS now respects the domain setting for 'Default Email Reminder' when set to 'disabled', this setting now applies to all users in the domain. (MIRA-55093)

    After importing contacts that were exported using webmail the phone number fields are now correctly mapped to the correct fields. (MIRA-55104)

    Some calendar stability enhancements. (MIRA-55113)

    When scheduling a repeating event, future conflicts will be reported that occur within 28 days of the first date. (MIRA-55147)

    Inter-server calendar communications are now more stable. (MIRA-55258)

    The XML server now correctly handles clients that close their connection prematurely. (MIRA-55260)

    Webmail and webcal could previously become unstable with a large number of XML clients in an IDLE state. (MIRA-55266)

    Further webmail and webcal stability enhancements. (MIRA-55290)

    A memory leak was fixed in the calendar server. (MIRA-55291)

    Memory usage optimised for multi-threaded calendar and webmail applications. (MIRA-55296)

    Clustering

    Remote Site Replication (RSR) is more reliable for a large number of file changes. (MIRA-55161)

    Documentation

    Copyright notices updated. (MIRA-55309)

    The online help for 'ntp get status' has been updated with a full description of all fields. (MIRA-55236)

    Filtering

    The MTA now correctly handles, by bouncing with a 552 code, messages who's header exceeds one million bytes. (MIRA-55103)

    Escape characters in regular expressions are now correctly recognised in the Japanese locale. (MIRA-55169)

    Hardware Support

    iDRAC firmware updated to v1.66.65 for 8-series systems. (MIRA-54972)

    IMAP

    The limit for the number of messages in a folder has been increased from to 50,000 to 150,000 in delegated domains. (MIRA-42102)

    Logging in as 'administrator' when the IMAP server is in 'ldapproxy' mode no longer causes the session to hang or terminate. (MIRA-55156)

    MTA

    DKIM now correctly verifies Google's DKIM signatures. (MIRA-55191)

    The autoreply function now correctly handles "Reply-To:" headers split over more than one line. (MIRA-52793)

    SPF return values modified to align with the online help. Similarly, the online help has been updated to be accurate. (MIRA-55178)

    Operating System

    Additional database stability issues. (MIRA-55116)

    When creating a folder path, eg. user.username.folderA.folderB.folderC, all intermediate folders will also be created. (MIRA-55143)

    Fixed a database deadlock condition that would occur during a server migration when IMAP was being used to transfer mail contents. (MIRA-55172)

    Timezone files updated (2014-11-17). (MIRA-55244)

    NTP client and libraries updated to address potential security vulnerabilities (CVE-2014-9293, CVE-2014-9294, CVE-2014-9295) (MIRA-55193)

    Cautionary update to avoid GHOST exploit, there is no known exploit possible on the appliance (CVE-2015-0235). (MIRA-55242)

    TLSv1.1 and TLSv1.2 now supported. (MIRA-55089)

    MD-5 ciphers removed from SSL/TLS protocols. (MIRA-55155)

    Security

    Signature Edition (Rapid) AS and AV engine was updated in base version. This is normally handled by online updates, but some customers do not enable automatic updates and were therefore missing the latest engine updates. (MIRA-42604)

    Introduced a new branding variable for JMM pages, called $(logreaduser_user), that references the mailbox part of an email address. (MIRA-55216)

    Webmail

    Corporate Edition Webmail now correctly displays Microsoft 'windmail.dat' bodies, also known as 'ms-tnef' bodies. (MIRA-51627)

    When 'http root' is set to Enterprise v2 and a secondary locale (eg. Hebrew, Spanish) is set to the default locale, the correct login page is now displayed. (MIRA-55256)

    Emails that have a HTML body part now properly render in Webmail Corporate Edition v2. (MIRA-52175)

    The HTTP proxy now better manages file descriptor resources. (MIRA-53231)

    Phone numbers created in Outlook and sync'ed to the server via ConnectR now appear correctly in Webmail. (MIRA-54997)

    Sending a message, via a web service (webmail or XML), with more than a million bytes in the header are now correctly handled. (MIRA-55160)

    Patches Included

    D4_2_glibc_security (MIRA-55248)

    D4_3_7_DB_SP_3 (MIRA-55241)

    D4_3_7_autocalendar_2 (MIRA-55262)

    D4_3_7_calendar_autoaccept (MIRA-53165)

    D4_3_7_eui_root (MIRA-55269)

    D4_4_3_DB (MIRA-55157)

    D4_4_3_DB_4 (MIRA-55283)

    D4_4_3_NDMP_forcefsck (MIRA-55207)

    D4_4_4_DML_SP_2 (MIRA-55219)

    D4_4_4_STS_SP3 (MIRA-55267)

    D4_4_4_STS_SP4 (MIRA-55284)

    D4_4_4_STS_SP5 (MIRA-55298)

    D4_4_4_calendar_conflict (MIRA-55240)

    D4_4_4_webcal_hang_diag (MIRA-55308)

    D4_4_5_jmm_summary (MIRA-55257)

    D4_4_5_mail_header_limit (MIRA-55168)

    D4_4_6_DB_SP_1 (MIRA-55249)

    D4_glibc_security (MIRA-55248)

    F4_8series_iDRAC_1_66_65 (MIRA-55245)

    View Article
  • Release Date: November 23, 2016End of Support: TBAFor documentation on MOS 4.4 releases, see the MOS 4.4 Product Guides.For detailed upgrade information for this release, see the Upgrade Instructions.

    Major New Features in MOS 4.4:

    For more information on these or any other features, see the Release Notes on the page for the specific release.

    Support for 8-series hardware platform

    WebMail/WebCal Corporate Edition - completely new user interface, with new features including:

    Tagging

    Real-Time Mail

    XML API Version 3

    Faster internal database server

    MOS 4.4.8download information:

    For MOS 4.3.x and earlier: ftp://ftp.mirapoint.com/pub/updates/R4_4_8_GA.mpu5(size:823508676, md5sum: 896849def177be79f3d91c078d1d0ea2)For MOS 4.4.x and later: ftp://ftp.mirapoint.com/pub/updates/P4_4_8_GA.mpu5(size:663929308, md5sum: c71fd85660ce0a7a9df272c83b5f4e67)

    Recommended Patches, Late-Breaking Issues

    Problem Description

    Fix Information

    O

    New language localizations avaialble.

    Install Traditional Chinese Mainland China. French. Spanish. German. Traditional Chinese Taiwan.

    Note: Mirapoint's policy is to always integrate patches created to address known problems into the next patch release.

    !!!

    Critical

    !!

    Strongly recommended

    R

    Recommended

    O

    Optional

    I

    Contact support for information

    Fixed Issues: 4.4.8

    Addressbook

    Exporting contacts as a CSV file using the Firefox browser in a non-English locale would fail. (MIRA-55346)

    Administration

    Accidentally entering a space character on the end of a domain in 'ldap gui' mode when administering a domain could result in all ldap entries for that domain being removed. (MIRA-55314)

    Rebuilding a mailbox with more than 150,000 messages would fail with an 'out of memory' error. Mailbox rebuilds could only be conducted by the Support team. (MIRA-55115)

    Restoring a delegated domain user via a selective restore may restore the user to the incorrect domain. (MIRA-55272)

    Deleting a user could fail after selectively restoring an entire domain. (MIRA-55315)

    SSH service updated to take advantage of updated TLS versions and ciphers. (MIRA-55313)

    Calendar

    In some cases, a user could not see all events of a user on a different host even though they had been granted permission. (MIRA-55359)

    Clustering

    The N+1 failover subsystem, could occasionally, inaccurately determine a network failure and cause a failover that is not required. (MIRA-55383)

    RSR could fail if there were an extremely large number of changes between delta syncs. (MIRA-55363)

    Documentation

    Copyright notices updated. (MIRA-55453)

    Filtering

    Unexpected mail address formats (e.g. "[email protected]"@example.org) would cause a memory alignment issue, resulting in a message in the log of "Domain filters passed illegal address" (MIRA-22747)

    Very long message subjects encoded using ISO-2022-JP could cause the filtering subsystem to crash. (MIRA-55405)

    IMAP

    Logging in as 'administrator' when the IMAP server is in 'ldapproxy' mode no longer causes the session to hang or terminate. (MIRA-55156)

    A large number of IMAP search parameters would cause excessive load and could crash the IMAP service. IMAP search parameters are now limited to a maximum of 200. (MIRA-55401)

    Deleting an IMAP folder with a very long name would sometimes fail. (MIRA-55425)

    MTA

    User filters now take priority over calendar auto-processing. (MIRA-55182)

    Introduced a log entry when a connection is blocked due to an RBL entry. (MIRA-55432)

    Added more detail into the RBL headers when 'rblhandling' is set to header mode. (MIRA-55433)

    The system would not respect LDAP bind requirements when resolving the 'mailgroup:members' query. (MIRA-55379)

    On some occasions, the SMTP server would not process a message when presented with the '.' to end the message submission. (MIRA-55437)

    On some occasions, the SMTP server would not process a message when presented with the '.' to end the message submission. (MIRA-55437)

    SPF checking would incorrectly report a domain that contained a TXT record, but no SPF details. (MIRA-55406)

    Operating System

    NTP synchronization could fail if a TLS patch was applied. (MIRA-55355)

    The blackhole duration would not be reset if a connection is made by the same IP address that is already on the netif blackhole list. (MIRA-55000)

    The command 'storage listsan' could fail with the error message 'unexpected command result = 11', if there were a higher number of valid paths to a LUN. (MIRA-55356)

    Webmail

    Implemented a timeout in which all HTTP request headers and bodies must be received in to avoid the slow HTTP header attack vulnerability. Header timeout: 10 seconds; Body timeout: 30 seconds. (MIRA-55387)

    Implemented a timeout in which all HTTP request headers and bodies must be received in to avoid the slow HTTP header attack vulnerability. Header timeout: 10 seconds; Body timeout: 30 seconds. (MIRA-55387)

    When composing a reply in HTML format and quoting an original message 'inline' would result in some mis-formatting. (MIRA-52974)

    Now correctly import contacts from CSV, LDIF and VCF formats. (MIRA-55285)

    Corrected some cross site scripting vulnerabilities. (MIRA-55302)

    Some messages would not display in Corporate Edition using the Firefox browser, if the message header contained unannounced Traditional Chinese characters. (MIRA-55343)

    Corporate Edition would not maintain the message selection when sorting the mailbox list on a field. (MIRA-55352)

    Webmail would not display a contact list correctly in the Firefox browser. (MIRA-55353)

    Some HTML formatted messages that contain nested tags would result in an error 'Sorry, an error occurred'. (MIRA-55414)

    When replying to a message that contains Japanese characters in the quoted body, could result in some characters being substituted with asterisks. i.e. '*' (MIRA-55415)

    Webmail would not display a contact list correctly in the Chrome browser. (MIRA-58392)</li>

    Patches Included

    D4_4_4_STS_SP6 (MIRA-55328)

    D4_4_4_STS_SP7 (MIRA-55360)

    D4_4_4_ldap_mailgroup (MIRA-55380)

    D4_4_4_mta_illegal_address (MIRA-55413)

    D4_4_6_NDMP_selective_restore (MIRA-55448)

    D4_4_7_imap_search (MIRA-55407)

    D4_4_7_ldapproxy_hang (MIRA-55372)

    E4_x_TLSv12 (MIRA-55277)

    D4_4_6_addressbook_import (SUPPORT-2717)

    View Article
  • Hello everyone,

    IceWarp Server 12.1.1 has, in some specific environments, following issues we are aware of:

    Can't find path to _webmail during installation

    Control service is crashing on HTTPS requests

    SSL certificates have bad signature

    Spam reports are having all items while only new requested

    RTL issues in WebClient

    Spellchecker is disabled by default in WebClient

    IMAP public folders not working correctly

    AntiSpam LIVE may show could not connect to ctasd service

    Exception in IPS max number of connections may not we working correctly

    WebClient login page does not respect selected language

    PHP error may appear while importing contacts

    language not found may appear during installation of OutlookSync

    Flag done may not be correctly synchronized with OutlookSync and WebClient

    IMAP subfolders may not be visible in IceWarp Desktop Client

    View Article
  • Posted by Milan Sykora on 06 December 2016 05:14 AM

    IceWArpserver 11.4 brings option with Let's Encrypt certificate

    https://www-media.icewarp.com/en/pdf/whats-new-11_4.pdf

    All the certificates discussed are used for SSL/TLS.

    The default certificate is self-signed and does not match your domain. You can create more self-signed certificates, which are current and match your hostname(s), but self-signed certificates need to be manually deployed to client devices.

    Certificates issued by recognized Certificate Authorities are trusted by client devices, but CAs charge exorbitant fees for the certificates and each hostname listed.

    Open certification authority that lets administrators create and maintain server security certificates for free. And now thanks to the Lets encrypt agent integration into WebAdmin and console, securing your IceWarp installation cannot get any easier. Certificates are automatically reissued before expiration, and need to be reissued manually only if domains are added or removed.

    Server DNS record hasto be resolvable and port 80 should be open.

    From within the Admin console go to System > Certificates screen.

    Click Add/Create button

    Select "Free Let's Encrypt certificate" and next.

    Put in the hostname(s) of your email server and click next.

    Wait for a green checkbox to appear next to the newly created certificate item.

    Let's Encrypt is a project that aims to make encryption more accessible by issuing signed certificates for free. Any client device that has added Let's Encrypt as a trusted CA will recognize these certificates as trusted. IceWarp 11.4 can retrieve certificates from Let's Encrypt for all your domains, automatically and for free.

    View Article
  • IceWarp Unified Communications

    IceWarp WebClient

    Administration Guide Version 12

    View Article
  • Posted by Gary, Last modified by Milan Sykora on 26 February 2016 07:14 AM

    Installing SSL Certificate

    related to this article: Certificate Management under IceWarp server

    The Following steps will walk an Icewarp Administrator through the proper steps to set up a unique SSL certificate from a trusted Certification Authority, which will allow the server to utilize the SSL Functions. Although these instructions will use a Free Trial certificate as an example, they will also work for implementing paid certificates as well.

    This tutorial uses the well known Certificate Authority VeriSign, but most Certificate Authorities, such as Thawte and GeoTrust, also have free trial certificates. The only difference will be the ordering process. There is a list of the most well-known Certificate Authorities the end of this article.

    A free Trial SSL Certificate from VeriSign has a 14 day validity period. This should be plenty of time to evaluate it's use on the Icewarp Server, and to familiarize yourself with the broader issues of SSL certificates.

    There are 4 steps to get a signed certificate and install it on the Icewarp Server:

    Generating a CSR (Certificate Signing Request) and Private Key

    Sending the CSR to the CA (Certificate Authority, VeriSign in this tutorial).

    Merge the signed Certificate from the CA with the Private Key (generated in step 1).

    Installing the merged certificate onto the Icewarp Server.

    1) Generating CSR (Certificate Signing Request) and Private KeyOpen the Icewarp Administration console and go to the Main Menu > System > Certificates > Server Certificates tab.

    Press "Create Server Certificate" and complete all fields in the form.

    VeriSign

    Common name will be your mail servers hostname. (in this case it will be mail.icewarpdemo.com)

    Check the box "Certificate Signature Request" - otherwise the Icewarp Server will generate a self-signed private key instead of the CSR.

    Fill in the Private Key File with the path and file name where it will be stored. (suggested naming convention would be private.pem.)

    Fill in the Public Key / CSR with the path and file name where it will be stored. (suggested naming convention would be csr.pem)

    Both files will be generated in the .pem file format.

    2) Send the CSR to a CA (Certification Authority - VeriSign in this tutorial)The CSR that was generated now gets sent to a Certificate Authority. The CA will check the request, digitally sign it with their certificate, and send it back. Because we are only requesting the Free Trial the checking procedure is simple and the signed certificate will be send back promptly. When you are buying a "real" certificate the checking procedure is more detailed, as proof of domain ownership will need to be proven. To follow this tutorial, and use the free trial certificate you can go to the VeriSign page and follow their wizard. (Or it is possible at this step to generate a paid certificate and continue on when it has been returned.)

    When requesting a certificate it will be neccessary to use a real e-mail address as the certificates will be sent to that contact information. When you are asked for your CSR you should cut and paste the content of the CSR.pem file that was generated in step 1. This file can be opened with any text-based editor (such as notepad).

    Choose a challenge phrase (password) for the certificate. This challenge phrase is used when the certificate is to be renewed, revoked, or any changes are to be made to it.

    Confirm the information provided and the signed certificate will be sent to the email address provided.

    Save this certificate to a new .pem file. (signedprivatekey.pem for this demonstration)

    3) Merging the Signed Certificate from Certificate Authority with your Private KeyThe email message sent to you from [email protected] will contain information on what to do next. The Verisign certificates will need to be installed into the servers browser.Follow this link . Copy and paste the certificate into the file TrialRoot.crt.

    For a Windows/IE browser double-click the certicate to install it. For a Firefox browser go to the Tools, Options, Advanced, Encryption, View certificates, Import. (Drop down menus in Firefox).

    Once done all certificates signed by Verisign's Trial Certificate Authority will be considered as trusted by the browser. (This step is not necessary when a non-trial certificate has been purchased)

    To merge the Private Key and signed certificate from Verisign into a destination file a third .pem file will need to be created. This demo will use mycert.pem as the filename.

    private key - private.pem

    signed key - signedkey.pem

    On command line run - "copy private.pem+signedkey.pem mycert.pem"

    Mycert.pem is now the certificate file that can be imported into Icewarp. It contains both the private key and the Certificate information from the CA.

    Note: Some CA (like Comodo) uses intermediate CA - an another certificate. In such case you need to join all these 3 certificates (Private, Signed Public and Intermediate together - "copy private.pem+signedkey.pem+intermediate.pem mycert.pem"

    4) Installing the merged certificate in Icewarp

    Once the mycert.pem file is created it needs to be imported into the Icewarp Server.

    Open the Administration GUI and go to Main Menu > System > Certificates > Server Certificates taband click the "Add"button.

    Insert the IP address that this certificate is intended for.This will be the IP address that the Icewarp users are directed to when they access this server.

    Insert the fully qualified name of the certificate file(full path to where the file is being stored. It is suggested that the certificate be stored in the \merak\config directory).

    To apply the new certificate a restart the Web/Control service is neccessary.

    To Test this new certificate open up a browser and go to https://mail.domain_name.com:32001/webmail. Be sure to use s https instead of http. The default SSL port is 32001. List of CA - Certification Authorities:

    Comodo DigiCert GeoTrust GoDaddy Network Solutions Thawte

    View Article
  • Posted by Ondrej Vanek, Last modified by Ondrej Vanek on 26 July 2016 05:27 AM

    Dual authentication is new feature for better security of your server-client connection.

    It is very usefull if you want to protect your mail server from unauthorised access to your webclient, EAS account or other client without special client pkcs12 certificate, with defined rule whenever you will require the certificate while connecting from all or only external network. According to the fact that pkcs12 certificate generated via openssl can be also password protected, super strong and generated for each user separetely, for email signing and encryption as well, your server and all informations in users accounts can be secured as well as current connection to banking sector.Following scenario is for your own self-signed certificate authority created in openssl on windows. in case if you would face a problem while the certificates creations(e.g. an error when openssl is searching for something in linux) use attached installer

    After installing the openssl library(choose copy OpenSSl DLLs to The Windows system directory) run openssl.exe from the install dir and create private key, self sign and import to your server trusted root CA authorities.

    For automatic generation of p12 certificates from csv file for each user separately use the certificator. For better security, tips and tricks generating the certificates search in google, for linux read following article. According to the fact that openssl is linux based, its much easier to create and handle CA there.

    Steps:-create root key-self sign root certificate-import root certificate into trusted root certification authorities

    -set signed root.pem as trusted CA in icewarp admin console

    -generate client certificate, sign it with root CA and convert to pkcs12 form.-create rule for IP in console>web -access tab and enable checkbox require client certificate-import pkcs12 certificate to users web browser settings/certificates/your(personal) certificatesEXAMPLES: complex certificates CA authority and managment in openssl 1.to create the root key execute:openssl> genrsa -des3 -out rootCA.key 4096 -aes-256-cbc

    (-des3 command is for password encryption of the key, you will be asked for this password each time signing a csr)

    2.next step is to self-sign this certificate:openssl> req -x509 -new -nodes -key rootCA.key -days 2048 -out rootCA.pemThis will start an interactive script which will ask you for various bits of information. Fill it out as you see fit. Once done, this will create an SSL certificate called rootCA.pem, signed by itself, valid for 2048 days, and it will act as your root certificate.To make this certificate trusted in your server, copy the rootCA.pem elsewhere and rename it to rootCA.crt, double click it and click on install certificate, in the import certificate wizzard choose the store for certificates, enable show physical store checkbox

    and choose Trusted root certificate authorities- local computer

    To define the self signed certificate as CA certificate in Icewarp go to console>certificates>CA certificates -click on add button

    choose the rootCA.pem file and confirm, now you have defined CA certificate for your icewarp server.

    (you can create and use more CA certificates together, e.g. each domain can use its own CA, so you can easily manage client certificates- at the moment the only way how to protect your server against abuse of client cert is to recreate the CA)

    3.Next step is to generate client certificate, sign it with root CA and convert to pkcs12 form. note: in case you would like to create client certificates for each user separately, for email signing and encryption, skip steps 3.-5. and instead of them follow this article

    openssl> genrsa -des3 -out client.key 2048 -aes-256-cbc4.Once the key is created, youll generate the certificate signing request.openssl> req -new -key client.key -out client.csrYoull be asked various questions (Country, State/Province, etc.). Answer them how you see fit. The important question to answer is common-name.

    Common Name (eg, YOUR name) []: your server hostname (or domain name)

    (in this concrete example, you can fill as CN whatever you want, but filling hostname would add more trust to users, who would not delete the certificate as unknown during some "moment of weakness", also domain names might be usefull for managing mutliple domain server)note: if you are planning to generate more client certificates and want to create, the CN must be unique for each certificate5.Once thats done, youll sign the CSR, which requires the CA root key.openssl> x509 -req -in client.csr -CA rootCA.pem -CAkey rootCA.key -CAcreateserial -out client.crt -days 5006.The client certificate and key must be converted to the PKCS12 format before getting imported into a client desktop's browser. To perform this conversion, complete the following procedure:openssl> pkcs12 -export -in <Directory-Path>/<Client-Certificate-Filename> -inkey <Directory-Path>/<Client-Key-Filename> -out <Directory-Path>/<Client-PKCS12-Filename> -name "<PKCS12-Name>"For example, to convert the /shared/exampleCA/client1.crt certificate with the /shared/exampleCA/client1.key key to the PKCS12 file named client1.p12, type the following command:openssl pkcs12 -export -in /shared/exampleCA/client1.crt -inkey /shared/exampleCA/client1.key -out /shared/exampleCA/client1.p12 -name "client1 pkcs12"7.Now go to icewarp console>web -double click the settings for webclient page>access and create a rule for requesting certificate from client while connecting to webclient.this rule is filtering dual auth for connection from outside of internal network you can specify the URI, e.g. /webmail or /Microsoft-Server-ActiveSync for EAS, users would have to import the pfx/p12/pkcs12 certificate nito their devices. (to be honest, I did not test it via EAS yet)

    8.On client machine insert the pkcs12 certificate into users browser -settings/certificates/your certificates import (depends on browser) or import the certificate in system via certificate import wizzard.

    Please check the link below for dowloading the open ssl.

    https://wiki.openssl.org/index.php/Binaries

    o.vanek

    View Article
  • For IceWarp version 12. is prepared external login script located in\IceWarp\html\webmail\client\_external

    which can be used as source code for external login example in customers web portals.

    <form method="post" action="LOGIN_PAGE_URL"> <input type="hidden" name="referer" value="REFERER_URL" /> <input type="hidden" name="ctz" id="ctz" value="TIMEZONE" /> <input type="hidden" name="language" value="LANGUAGE_CODE" /> <input type="hidden" name="to" id="to" value="INTERFACE" /> <input type="text" name="iw_username" value=""/> <input type="password" name="password" value=""/> <input type="hidden" name="disable_ip_check" value="1"/> <input type="hidden" name="_c" value="auth" /> <input type="hidden" name="_a[login]" value="1"/> <input type="hidden" name="type" value="external"/> <input type="hidden" name="_n[js]" value="0" id="jscontrol"/> <input type="submit" value="Login"/></form>

    View Article
  • Posted by Gary Garber, Last modified by Tomas Zubov on 14 July 2014 11:16 AM

    This guide will walk you through choosing, ordering, configuring, and installing the certificate using Icewarp. This guide mainly only provides information based on the individual using a Icewarp signed certificate.

    View Article
  • In the case when you will deploy IceWarp WebDocumentVMWare image version 5.5 in VMWare Workstation and the error pop-up window will be shown

    more info here >>>

    then here are two possibilities how to quickly fix it.

    A, unmount .iso file from the image and try to deploy .ova file again

    try to edit the CDROM reference in OVF to remotepassthrough to see if helps:

    B, slowestbut 100% function option is add machine from .vmdkfile

    1, unzip downloadedimage file to folder by 7zip application (http://www.7-zip.org/download.html)

    2, navigate to unzipped folder and use 7zip to existing .ova file and unpack it again

    3, unpacked folder will include .mf; .ova; and .vmdk files

    4, import.vmdk file to VMWare by the following instruction:

    1.Step

    Click "File," "New" and "Virtual Machine" in VMware.

    2.Step

    Click "Next" and choose "Custom" for your machine type.

    3.Step

    Choose "Legacy" if your VMDK file is from an earlier version of VMWare. Choose "New" if it is the current version. Click "Next."

    4.Step

    Choose the Operating System you are installing from the list and then select its version from the drop-down menu. If you do not know, click the radio button next to "Other." Click "Next" to continue.

    5.Step

    Enter a name for the virtual machine and then choose a folder to store it.

    6.Step

    Specify the number of processors you would like to use. This must match the number of processors on your computer. The default setting of "one" is the safest.

    7.Step

    Choose the amount of memory you would like to allocate to the operating system. Adjust the slider until it reaches the minimum requirements listed on the screen.

    8.Step

    Choose your network type and click "Next."

    9.Step

    Select "Use an existing virtual disk" from the Select a Disk window and click "Next."

    10.Step

    Browse to the .vmdk file on your hard drive and click it. Press "Open" to select it.

    11.Step

    Click "Finish."

    Little modified steps can be used for VirtualBox.

    View Article
  • Apparently the broken update KB4338818 applies only to Windows 7, Windows Server 2008 R2 and Windows Server 2012 R2.

    The issue relates to broken Windows update KB4338818 published on July 10, 2018 (https://support.microsoft.com/en-us/help/4338818/windows-7-update-kb4338818, last entry in "Known issues in this update". Microsoft talks about the IIS service, but in reality it happens to other services too)

    The next patch KB4338821 published on July 19, 2018 has the correction.(https://support.microsoft.com/en-us/help/4338821/july242018kb4338821osbuildpreviewofmonthlyrollup)

    To solve the issue, please install patch KB4338821

    For the Windows 2012 install patchKB4339916

    View Article
  • In the case when you are not able to print Email content from IE 11.0.43 and you are seeing Error 404 Not Found.

    Replaceby attached file content in /icewarp/html/webmail/client/inc/

    (for Windows \icewarp\html\webmail\cient\inc\)

    Restart IceWarp services

    These Guide can be used for any 11.4 IceWarp server version.

    View Article
  • Standard password:the9Xuye

    The WebDocuments server must be able to access the IceWarp server by hostname and DNS must be working so it can update. Edit /etc/resolv.conf to add proper DNS servers.

    If the IceWarp and WebDocuments servers are on the same internal network: edit /etc/hosts on the WebDocuments server to add an entry for the IceWarp server.

    Example: 10.10.10.10 icewarpserver.hostname.com

    Make sure WebDocuments is updated by running the following command:

    #apt-get install --only-upgrade icewarp-webdocuments

    Do the following if a static IP is needed to be set.

    edit /etc/network/interfacesRemove:iface eth0 inet dhcpAdd:auto eth0iface eth0 inet staticaddress 192.168.1.10 <- your static IP address herenetmask 255.255.255.0 <- your subnet mask heregateway 192.168.1.1 <- your default gateway here

    WebDocument services restart

    #systemctl restart nginx#/etc/init.d/supervisor restart

    How to proceed:

    #apt-get upgrade / update1. #systemctl restart nginx2. #/etc/init.d/supervisor restart3. In console please click Test Connection button again4. Check if documents works now

    IceWarp Server must be able to send out tcp packets to destination ports 8081, 80 or 443 on WebDocuments host.Check if the WEB service is NOT configured to use ssl for only the public IP, !!! communication with WebDocuments is using internal IP

    For Trial License where is displayed License issue do>

    1, Activate IceWarp Trial License from License tab2, restart IceWarp server modules3, #systemctl restart nginx4, #/etc/init.d/supervisor restart5, steps 3 and 4 has to be without fails, if yes repeat until success6, on IceWarp use Test Conneciton /it should take more time the before/7, log to the WebClient and verify

    View Article
  • Windows 7 as standard user and when opening a mailto: link in Firefox, it tries to open the link in Internet Explorer. Set the mailto: in Firefox to IceWarp Desktop Client, then the mail client opens, but the mail address from the link is not transfered, nor it opens a window for creating a new mail.

    This is not working with Desktop Client 11.4 and the newest one.

    The other thing is, when right clicking a document, there is no option in the context menu for sending this document as an email.

    Solution:

    mailto registry entry is missing, after adding the missing registry key (following this article: https://answers.microsoft.com/en-us/ie/forum/ie8-windows_other/no-mailto-protocol/21d255eb-77b2-4067-9080-8d81ad77f396) the mailto links start working in Firefox.

    These are the steps:

    1. Click Start, Run and type Regedit.exe

    2. Navigate to the following branch:

    HKEY_LOCAL_MACHINE\Software\Classes\mailto

    3. From the Edit menu, select New, and then click String Value.

    4. Type URL Protocol as the name of the new String Value

    5. Exit the Registry Editor

    View Article
  • Posted by, Last modified by on 01 August 2012 01:09 PM

    Integrating Outlook Sync With Any Existing POP3 Profile

    One of the many advantages the Sync client gives customers is the ability to bind to an existing POP3 profile. This means if you have current Outlook users in a POP3 profile and now wish to have them synchronize contacts, calendars and other Groupware data with their IceWarp account this can be done.

    When binding the Sync client to their POP3 profile it can upload all of the data that resides in their current .PST file (Mail, Contacts, etc.) to the server, making it accessible from other locations instead of just Outlook itself.

    This FAQ will walk you through the steps of "Binding" their current POP3 account to the Outlook Sync Client.

    1. You first need to install the Sync Client. It is best to always use the same version Sync client with the server version being run. To ensure both versions are the same please download the Sync client from your own server. You can do this from the WebClient login page by clicking "Utilities for Windows (Linux if using this OS)" and this will take you to the download screen seen below.

    [email protected]

    2. Once downloaded please close Outlook and being the installation. For installation instructions please refer to the "Outlook Sync User Guide" available at the URL below.

    http://www.icewarp.com/downloads/documentation/server/

    ** Please note that you do not need to create a new profile when installing the Sync client, If you run the installer with the "--noprofile" argument it will install without requesting a profile be created. Then you can bind to your existing Outlook profile.

    To do this open the CMD prompt and navigate to the location of the Outlook Sync .exe or .msi file and run the following command:

    outlook-sync.exe --noprofile (see image below)

    This will then open the installer and no profile will need to be created.

    3. Now that the Sync client is installed please open Outlook into the existing POP3 profile.

    4. Once the profile has loaded you can now bind Sync with your server account. Doing this will vary among the Outlook versions.

    For 2010 please go to "Add-In's" to see this option

    For 2007 you will see this on the Outlook taskbar

    5. Click on the option "Bind this profile with server account"

    6. The Settings window will appear and you will need to specify your account password and verify the other settings seen are correct. Once you verify the settings are correct press "OK".

    7. You will then be presented with the notification window stating "Profile Bind Done. Restart Outlook", press "OK" and close Outlook.

    8. Now open Outlook again and be sure to load the same existing profile as before.

    9. Once this loads it will search the server to see if there is currently information seen on the server that matches what is seen in the client. You will receive the "Initial Synchronization" message. There are two scenario's from here:

    A) You have matching data on the server: If the sync finds you to have data that matches on the server it will present you with a Yes or No dialog box. It is stating that if you upload the data from Outlook it could cause duplication of data. Since this is a POP3 account and not synchronizing anything other than the Inbox this means the user most likely chose to leave a copy of their mail on the server.

    To resolve this so you can upload all of the data without fear of duplication from Outlook to the server first go onto the server and find the users mailbox and either delete their current inbox mail or just move it out of the inbox in to another folder.

    As you see in the image I have mail in the mailbox which is also in Outlook. In the image below I create a folder called "Old_Inbox" and then cut and paste all the mail into this folder. Again, you can also delete this mail since it really is in the client already but to be cautious you can do it this way.

    Now that I know the data the synchronization was seeing is no longer there I will press "No", this will force all data from Outlook up to the server. This is what you want to do in order to have Outlook fully push all of it's current data to the server.

    B) The other choice is "Yes", this will delete all the data on the client and pull the data down from the server. Do not do this unless you are absolutely sure the server contains the exact same data as Outlook, so all mail, calendars, contacts, etc. If you say "Yes" then it will automatically begin deleting the data from Outlook permanently.

    10. You will now begin to see the folders from the server being downloaded and data from Outlook being uploaded. If you open the "Synchronization Progress Window" you can follow the progress of this. The initial synchronization will take the longest time of any synchronization and can range from a few seconds to minutes depending on the amount of data being pushed to the server.

    Once the synchronization is complete you would have fully synchronized your old existing POP3 profile with the IceWarp server and from that point forward all data from Outlook will be synchronized to the server and from the server to Outlook. This also allows you to add in other devices and services, like an iPhone using ActiveSync and completely keep everything fully synchronized.

    With this you could make a change in any device whether it be adding a contact, changing an event, deleting a message, etc. and have those additions or modifications show up in the other devices being synchronized. This gives you a complete solution so you always have complete access to your personal data or shared data.

    If you have any questions or problems please contact

    View Article
  • See attachment.

    View Article
  • Posted by Ian Marshall on 15 July 2014 11:31 AM

    The IceWarp administration console has a feature that many people don't know about that helps prevent accidental user deletion.

    Deleting accounts can be easy to do, for instance when making fast server changes or just accidentally hitting the delete button. Once deleted, these accounts can be difficult and time consuming to restore.

    To enable safe delete, just click Options > Use Safe Delete Confirmation. Once enabled, you will be asked to confirm before any account is deleted.

    View Article
  • In version 12.0.3 you may have noticed an abnormal number of connections to GroupWare.There is no issue really, as it is just # of sessions that are opened internally and they do NOT use any resources.

    Developers will fix that in version 12.0.4

    Basically nothing to worry about, just # of internal and external sessions were opened (previously it was the same, but not counted in console)

    View Article
  • Hello,

    This is a known issue that will be fixed in version 12.0.3 due out in the very near future.

    Since we have not issued an official release yet the following link to the webmail.zip from 12.0.3 rc8 can be used to patch on top of 12.0.2 server.

    https://server.icewarp.com/teamchatapi/webmail.zip

    Note: Before proceeding, we recommend:

    - Make a backup of your HTML folder before applying the patch in case you run into any issues.

    - We do not recommend patching older server versions.

    View Article
×
Rate your company