Friday, November 13, 2020

Secure Zimbra Server with Let’s Encrypt SSL Certificate

Step 1: Install certbot-auto tool

wget https://dl.eff.org/certbot-auto
chmod +x certbot-auto

Move the script to directory in your PATH.

sudo mv certbot-auto /usr/local/bin

Confirm it working.

sudo certbot-auto --version

Step 2: Stop Zimbra Proxy Service

We need to stop the jetty or nginx service services before we can configure it to use Let’s Encrypt SSL certificate.

$ sudo su - zimbra -c "zmproxyctl stop"
Stopping proxy...done.
$ sudo su - zimbra -c "zmmailboxdctl stop"
Stopping mailboxd...done.

Step 3: Obtain Let’s Encrypt SSL Certificate
Once the Zimbra proxy and mailboxd services are stopped we can proceed to request for Let’s Encrypt in auto mode. Make sure you pass all the hostnames used by your Mail Server.

# export EMAIL="[email protected]"
# certbot-auto certonly --standalone 
  -d mail.computingforgeeks.com 
  --preferred-challenges http 
  --agree-tos 
  -n 
  -m $EMAIL 
  --keep-until-expiring

You can find all your files under /etc/letsencrypt/live/$domain

$ ls -lh /etc/letsencrypt/live/mail.computingforgeeks.com
total 4.0K
lrwxrwxrwx. 1 root root  50 Jul  5 23:42 cert.pem -> ../../archive/mail.computingforgeeks.com/cert1.pem
lrwxrwxrwx. 1 root root  51 Jul  5 23:42 chain.pem -> ../../archive/mail.computingforgeeks.com/chain1.pem
lrwxrwxrwx. 1 root root  55 Jul  5 23:42 fullchain.pem -> ../../archive/mail.computingforgeeks.com/fullchain1.pem
lrwxrwxrwx. 1 root root  53 Jul  5 23:42 privkey.pem -> ../../archive/mail.computingforgeeks.com/privkey1.pem
-rw-r--r--. 1 root root 692 Jul  5 23:42 README

[Read more…]

Saturday, March 9, 2019

Reject Unlisted Domain ເທິງ Zimbra 8.5 ດ້ວຍ policyd

Image does not exist: https://i0.wp.com/imanudin.net/wp-content/uploads/2014/09/policyd-groups.jpg?resize=825%2C154

ມີຂັ້ນຕອນດັ່ງນີ້:

1. ເລືອກ Policies > Groups.
2. ໃນ action ເລືອກ add
3.ໃສ່ຄຳວ່າ list_domain ໃນຫ້ອງ Name ສ່ວນໃນຫ້ອງ comment ປະຫວ່າງເປົາ ແລ້ວກົດ Submit Query
4. ກັບຄືນມາລາຍການ ແລ້ວເລືອກ list_domain>Action>Change>ຫ້ອງ Disabled ເລືອກເປັນ no >Submit Query ແລ້ວກັບຄືນ
Image does not exist: https://i0.wp.com/imanudin.net/wp-content/uploads/2014/09/policyd-groups.jpg?resize=825%2C154
5. ເລືອກ list_domain>Action>Add ໃຫ້ໃສ່ຂໍ້ມູນ Name= @domain.com >Submit Query>Back to group #domain ແມ່ນໝາຍເຖິງໂດເມນຂອງທ່ານ
Image does not exist: https://i0.wp.com/imanudin.net/wp-content/uploads/2014/09/policyd-members-groups.jpg?resize=825%2C161
[Read more…]

ວິທີຕິດຕັ້ງ PolicyD ເທິງ Zimbra 8.5 ແລະ ຮຸ່ນຕໍ່ມາ

Image does not exist: http://vavai.net/wp-content/uploads/2014/02/policyd_logo-300×130.png

ມີຂັ້ນຕອນຕິດຕັ້ງດັ່ງນີ້:

1. ເປີດໃຫ້ Policyd ທຳງານ

su - zimbra
zmprov ms `zmhostname` +zimbraServiceInstalled cbpolicyd +zimbraServiceEnabled cbpolicyd
cd       
exit

2.ເປີດໃຊ້ Policyd WebUI ດ້ວຍຜູ້ໃຊ້ root

cd /opt/zimbra/httpd/htdocs/ && ln -s ../../cbpolicyd/share/webui

ຈາກນັ້ນໄປແກ້ໄຂໄຟລ໌ /opt/zimbra/cbpolicyd/share/webui/includes/config.php ແລ້ວເອົາເຄື່ອງໝາຍ “#” ໃສ່ທາງໜ້າ $DB_DSN ແລ້ວເພີ່ມອັນໃໝ່ໃສ່ກ່ອນ $DB_USER ດ້ວຍຂໍ້ມູນລຸ່ມນີ້.
[Read more…]

Thursday, March 7, 2019

ວິທີປ້ອງກັນການສົ່ງເມວຕ້ອງ Login ກ່ອນ ໃນ Zimbra

Image does not exist: https://i2.wp.com/imanudin.net/wp-content/uploads/2014/09/thunderbid-different-identity.jpg?resize=493%2C437

ຖ້າໃຊ້ຮຸ່ນ 8.5 ຂຶ້ນມາເຮັດຕາມຂັ້ນຕອນນີ້ໄດ້:
1. ເຂົ້າໃຊ້ຜູ້ໃຊ້ zimbra

su - zimbra
zmprov mcf zimbraMtaSmtpdSenderLoginMaps proxy:ldap:/opt/zimbra/conf/ldap-slm.cf +zimbraMtaSmtpdSenderRestrictions reject_authenticated_sender_login_mismatch

[Read more…]

Wednesday, February 27, 2019

ຕັ້ງຄ່າໃຫ້ reject authenticated sender login mismatch ໃນ zimbra

Image does not exist: https://i.ytimg.com/vi/7iYrw4VSjSM/hqdefault.jpg
ເປັນການປ້ອງກັນການສົ່ງເມວທີ່ບໍ່ໄດ້ມີການລັອກອິນກ່ອນ ຊຶ່ງມີຂັ້ນຕອນດັ່ງນີ້:
1. ກວດເບິ່ງ zimbraMtaSmtpdRejectUnlistedSender ແລະ zimbraMtaSmtpdRejectUnlistedRecipient ໄດ້ເປີດໃຊ້ໃນ zimbra mta?

zmprov gacf | egrep zimbraMtaSmtpdRejectUnlistedSender
zmprov gacf | egrep zimbraMtaSmtpdRejectUnlistedRecipient

ຖ້າຜົນຮັບອອກມາເປັນແບບນີ້ ແມ່ນຍັງບໍ່ໄດ້ເປີດໃຊ້
zimbraMtaSmtpdRejectUnlistedSender: no
zimbraMtaSmtpdRejectUnlistedRecipient: no

2. ເປີດໃຊ້ງານດ້ວຍຄຳສັ່ງ

zmprov mcf zimbraMtaSmtpdRejectUnlistedRecipient yes
zmprov mcf zimbraMtaSmtpdRejectUnlistedSender yes

[Read more…]

ວິທີການສົ່ງເມວທາງ Telnet

Image does not exist: https://cdn.ttgtmedia.com/ITKE/uploads/blogs.dir/25/files/2007/11/test-1.gif

1. ເປີດ command prompt.
ຕອນນີ້ ທ່ານສາມາດເຊື່ອມຕໍ່ ດ້ວຍ ໂປຣແກຣທ telnet ຕາມຄຳສັ່ດັ່ງນີ້:

 telnet example.com 25

2. ພີມ ehlo example.com example.com ເປັນໂດເມນຕົວຢ່າງໃນບົດຄວາມນີ້

ehlo example.com

3. ພີມ mail from: [email protected]:

mail from: [email protected]

4. ພີມ rcpt to: [email protected], [email protected] (ອີເມວປາຍທາງ):

 rcpt to: [email protected][email protected]

5. ຂຽນເນື້ອໃນອີເມວໃຫ້ພີມ data, ຕາມດ້ວຍ subject ແລະ ຂໍ່້ຄວາມສຸດດ້ວຍເຄື່ອງໝາຍ . (ຈ້ຳເມັດ)
[Read more…]

Subscribe

  • RSS Atom

ອອນລາຍ: 1 | ມື້ນີ້: 15 | ວານນີ້: 25 | ທິດນີ້: 95 | ເດືອນນີ້: 874 | ປີນີ້: 11834 | ລວມ: 78937