Igaware Version 13.0.4-btrfs released #Igaware #linuxsbs

New in Version 13.0.4-btrfs [ Apr 13 2016]
==========================================

* New Features and Improvements *

  • Added a Time Zone feature. The system Time Zone can now be set to reflect the customer’s geographical location.
  • Updated the Linux Kernel to support the new BTRFS file system.
  • Installed supporting software for the BTRFS file system.
  • Installed a new LZO compression library, for new file system compressing operations.
  • Updated several Linux utility programs.
  • Removed the MultiViews option from the Web Server configuration. This speeds up web server requests.

* Fixes *

  • Network aliases script fixed for use with new glibc libraries.
  • ifup-aliases script fixed for new glibc libraries.
  • Fixed a bug in the network down script for PPP connections with IPSec VPN. The PPP connection didn’t always come back up.
  • Fixed a bug with SSL VPN and multiple LAN networks. The network routes were not pushed to the client device.

New in Version 13.0.3-glibc [ Mar 21 2016]
==========================================

* New Features and Improvements *

  • Updated the Anti-Virus engine to catch zero hour viruses.
  • A major update of the GLIBC libraries has been released to fix several security vulnerabilities that have been identified, namely; CVE 2015-7547 ( Buffer overflow) and CVE-2015-0235 ( GHOST vulnerability)

* Fixes *

  • After the recent security updates, Outlook users would sometimes be refused connection to the Zarafa server. This has been fixed.
  • PPTP VPN. A bug with a recent BASH update prevented some users from accessing devices on the server’s LAN.

Posted in System Updates | Tagged , | Leave a comment

Igaware Version 12.1.8-ADS released #Igaware #linuxsbs

New in Version 12.1.8-ADS [ Feb 21 2016]
========================================

* New Features and Improvements *

  • Updated the Web proxy software to the latest version. This provides performance gains and improvements in URL filtering of HTTPS sites.
  • Updated the pattern matching software.
  • Added a new email filering engine to detect and block the newest zero-hour Email Spam attacks.

* Fixes *

  • Fixed a possible bypass of Web URL filtering when using the Safari browser.

New in Version 12.1.7-ADS [ Feb 16 2016]
========================================

* New Features and Improvements *

  • Updated the Anti-Virus scanner to check for zero-day macros in documents.
  • Added a Network Traffic Analyser. This listens on any network interface and displays a table of current bandwidth usage by pairs of hosts, showing any network hogs. The analyser can be run concurrently on more than one Interface, to show a view of traffic on the LAN and the WAN interface at the same time.
  • Added more choices to the options for the File server Shadow Copy feature.
  • Updated the network traffic monitor with the latest software version.
  • Updated the caching, recursive DNS server software to the latest version.
  • Added an option to the General Email configuration to enable/disable TLS encryption on incoming SMTP connections. Previously, only the client ( outgoing) TLS encryption was affected.
  • Increased the performance of the Web Proxy server. Asynchronous disk access is now used, reducing contention.
  • Several improvements to the Web Configuration Interface.
  • Modified Horde IMAP groupware configuration to send emails to the SMTP network port.

* Fixes *

  • During first-time provisioning of the Active Directory Server, the DNS server is now changed to the internal BIND DNS server. Previously, the AD Server would not provision properly.
  • Created a new, default, self-signed RSA certificate for the Web Server.
  • Many other bugs squashed.

New in Version 12.1.6-ADS [ Jan 29 2016]
========================================

* New Features and Improvements *

  • Security – Installed RSA certificates for the IMAP and POP email servers.
  • Security – Updated the SASL authentication libraries to the latest version.
  • IPSec – Added a connection monitor for IPSec connections. If a ping to a remote IP address fails, then, the IPSec SA is restarted for that connection.
  • IPSec – New program and kernel module installed.
  • IPSec – Allow insecure DH group 1 and single DES for some Vigor routers and others.
  • Web proxy – Updated the server software and re-configured it to speed-up traffic flow.
  • Mail Server – Allow the Igaware mail server to transmit data to SMTP relay servers in 7 bit mode.

* Fixes *

  • Local Master Browser tick box for standalone file server server – the setting wasn’t saved.
  • Networking – Interface script fixed. This now calls ipsec restart correctly. Previously ipsec down was not called and blocked the shutdown of the ppp device.
  • Email server – Force file ownership permissions for the SMFS recipient verification server.
  • Email Server – Relaying of unlnown local users to an SMTP server was not working correctly when the server was specified with a domain name.
  • Fixed several bugs in the Web configuration interface.

New in Version 12.1.5-ADS [ Jan 11 2016]
========================================

* New Features and Improvements *

  • Security – Plain text passwords (LOGIN/PLAIN auth mech) are disabled for eMail server SMTP authentication.
  • Web Interface – Added an option to allow LOGIN/PLAIN clear-text passwords for SMTP authentication.
  • Security – Added X-FRAME-OPTIONS to Web server response headers.
  • Security – Prevent possiblity of XSS ( cross-site scripting) in Web
    configuration interface.

— New in Version 12.1.2-ADS [ Dec 22 2015]
========================================

  • Anti-Spam – added some rules to get rid of current invoice spam.
  • Securtiy – Added CRAM authentication for IMAP – cram-md5.pwd
  • Security – Installed RSA certs for IMAP server. This allows secure TLS connections.
  • Security – Added an option to block email that contains Microsoft OLE documents with Macros to the Anti-Virus page – off by default.
  • Security – Secured incoming IMAP and POP3 connections with CRAM encryption during login and TLS for the connection.
  • Security – Secured incoming IMAP and POP3 connections with TLS encryption.
  • Many other small improvements.

* Fixes *

  • Backup – When mounting a cifs share as a backup destination, the username is tried both with and without the workgroup name. Newer kernel require the WORKGROUP/user format.
  • Routing – Fixed some routing tables that had multiple rule entries – table-iproute now deletes a rule before adding it again.
  • Backup – Exclude the $RECYCLE.BIN folder when backuping up ISCSI sources.
  • Networking – Allow DH group 1 for IPSEC VPN.
  • DHCP Server – Set the zone domain properly from the correct LAN domain, if we are using the BIND DNS Server.
  • Web Interface – Don’t cache the image of the Email Traffic graph, so that the new one displays correctly.

Posted in System Updates | Tagged , | Leave a comment

Igaware Version 12.0.1 released #Igaware #linuxsbs

* New Features and Improvements *

  • Active Directory Server support – A major re-write of the Samba software and User/ Group code to provide full Active Directory Server support. The Igaware box can now act as a Microsoft Active Directory server. Users are administered using Microsoft’s RSAT tools from a Windows workstation.
  • Zarafa server – The Zarafa server can now integrate fully to an Active Directory server. This is true if the Igaware box is acting as an ADS DC or as an ADS Member.
  • Active Directory Server – Added NTP time syncronisation to AD DC (signd ) for Windows client machines.
  • Installed new g++ run-time libraries.
  • Squid web cache/proxy – Installed Squid 3.2.
  • Apache web server – Installed latest version of apache web server.
  • Apache web server – Changed high protocol option to block TLSv1 & SSLv3
  • Samba server – Updated Samba to version 4.1.20.
  • Hylafax – changed modem ttyline to ttyUSB0 for usb modem type.
  • Web Interface – Allow a user to have a blank surname in config interface
  • Zarafa Search Indexer – When the Zarafa Search Indexer is disabled the /var/lib/zarafa/index/ directory is cleared.
  • Samba4 – Added the GNUTLS libraries.
  • Web Interface – The Web page title is now hidden, until logged in.
  • Security – Installed the latest version of OpenSSL. This allows high security protocols with apache – tlsv1.1
  • OpenVPN – Added health check for openVPN SSL server.
  • Web Interface – Windows Services menu option finally removed. Replaced with Active Directory.
  • Many other improvements.

    * Fixes *

  • DNS BIND server – Fixed the named configs for nultiple LAN’s with same domain name. Also fixed out of band domain zone files.
  • Sendmail  – FIXED the sendmail configuration when a WAN interface is down and has no IP address.
  • Backup – FIXED the zarafa backup to remove the zarafa-dump.new destination directory ( if it already exists)
  • System Status – Fixed a problem with Web Visits statistics – printing errors
  • Network Routing – Fixed a long running problem with iproute tables. The commit changes table ( in ifup-post) wasn’t run when the IP address of an interface was changed. This meant that the interface disapeared from the WAN ip route tables.
  • Web Interface – Added “cache: false” to ajax calls to stop Internet Explorer caching ajax calls.
  • ISCSI Server – Change ISCSI file pre-allocation – if fallocate fails then try dd.
  • File Server – When creating new share – replace space with underscore for $share
  • Mail Delivery – Fixed a problem setting file ownership for the vacation program ( . instead of 🙂
  • DBS BIND Server – Fixed a problem when bind_on = false and emtpy named.master zone files were written.
  • Networking – Fixed a long standing bug with networking multi-homed WAN setups. If the ppp link went down it would delete the default route.
  • Networking – Fixed the failover_mw health script. Wasn’t checking failover_mw daemon.
  • Squashed a variety of other bugs.

Posted in Linux Small Business Server, System Updates | Tagged , , | Leave a comment

Igaware Version 11.0.2 released #Igaware #linuxsbs

New in Version 11.0.2 [Wed Sep 23 2015] =========================================
* New Features and Improvements *

  • Added hard-coded DNS SRV records to BIND named zone file.
  • Updated System Health for named daemon ( in dnrd)
  • Updated mysqluner.pl – MailScanner
  • Added a list of ip route tables ( eth1, etc) to Status , network routes page.
  • Changed ref to Zarafa Outlook client download.
  • Modified my.cnf file creation – now merges local file
  • Modified Zarafa server.cfg file creation – now merges local file
  • Changing the nameservers now reloads and clears cache for dnsmasq
  • mysql and my.cnf now uses innodb plugin
  • Changed min attachment size to 0 in Mailscanner*.template
  • Added IgawareKAM to rsync schedule to xfer KAM.cf

* Fixes *

  • Changed hosts file – replace host spaces with –
  • Added drop user ”@’localhost’; to mysql_create.sql
  • FIXED openvpn.Could not ping local LAN or 10.8.0.1. learn-address script needed #!/bin/sh
  • FIXED dirvish when the share name has spaces ( put quotes in)
  • Fixed long running problem. When interface goes ( or is brought) down ( e.g ifdown), then, any routes in tables ( ip route list table eth1) are removed ( by kernel, cause the interface has gone) and NOT replaced. Changed ifup-post to call /var/igaware/network-scripts/table-iproute all up, instead of just for DEVICE
  • Fixed LAN config – problems with fields were not reported as window closed.
  • Fixed the add new filename content page for email filtering
  • Fixed global_access in rsyncit.sh – do it all the time
  • Fixed perconda backup when 7days set.
  • Fixed report export
  • Fixed OLD http report page

Posted in System Updates | Tagged , | Leave a comment

Returned mail: see transcript for details – Outgoing SMTP Problems and Resolution

It’s increasingly common for emails sent to Hotmail, Yahoo and AOL to be returned (‘Returned mail: see transcript for details’) as Internet Service Providers introduce increasingly simplistic measures to combat spam, e.g. simply blocking one RBL list or IP range.

Unless your outgoing email server is deemed 100% trust worthy you can’t guarantee the delivery of genuine emails.

Even if you set-up your outgoing email server with all the correct credentials (PTR, SPF DXIM etc.) there can still be problems as some ISPs will simply not accept emails from servers with IP numbers within a customer range of another ISP; at the time of writing if you are a BT Customer then ISP 1&1 will not accept any email!

To avoid delivery problems there are two recommended solutions:

  1. Use the SMTP server of your ISP.
  2. Use a third party SMTP Server provider e.g. http://www.arrowmail.co.uk/services.aspx#h1

Maintaining the trustworthiness of a sending server is an on-going job. It involves keeping up with the latest “good behaviour” standards, being fully RFC-compliant, staying off blacklists and requesting ISPs to trust your server. Unless you want to do this maintenance then use one of the suggestions above.

Posted in Email, Linux Small Business Server | Leave a comment

Igaware Version 11.0.1-1 released #Igaware #linuxsbs

New in Version 11.0.1-1 [Tue Aug 11 2015]
=========================================

* New Features and Improvements *

  • The Zarafa database is now backed up using Perconda xtrabackup. It’s much faster to backup and restore and uses less resourses.
  • Installed new PHP libraries
  • Installed new Perl libraries
  • Installed new Python libraries
  • Installed new Zlib compression libraries.
  • Updated the OpenSSL security libraries.
  • Modified the Zarafa Users page to allow the free-form entry of the default email name.
  • Added several new network commands.
  • Created a script to block all access to Facebook IP’s. This is not enabled by default.
  • Updated the file command to identify more signatures.
  • Installed fail2ban to block remote access from script kiddies.
  • Increased max_input_vars in php.ini
  • sysctl – vm.vfs_cache_pressure to 3000
  • Zarafa – re-linked the server with tmalloc ( gperftools) to increase memory
    performance.
  • Added a “folder list” tab for the Zarafa user information dialog popup.
  • Separated the mail server daemons for LAN and WAN. This gives increased control over mail delivery.
  • Added the system uptime & kernel version to checkin page.

* Fixes *

  • System health – fixed the check for winbindd – too many files.
  • Fixed link to submit.cf
  • Reordered the r8169 ethernet driver to be first loaded above r8168 & r8101.
  • Fixed a problem with squidGuard going to emergency mode – removed spaces.
  • Fixed a problem with the backup when the Fileserver Shadow Copy feature is enabled.
  • Fixed a rare problem with the Web Activity hours report.
  • Fixed a problem with the hosts file and LAN2
  • Fixed a problem with the SQL server shutdown script.

New in Version 11.0.0-3 [Fri July 03 2015]
========================================

* New Features and Improvements *

  • Updated the Internet Speed test code.
  • Changed dpd timeout and delay for IPSec
  • Updated the Mail Server M4 configuration files. They were out of date.
  • Notices regarding detected Email Virii are now not passed on to the recipient.
  • Added security to stop brute force attack against any open SSH server.
  • Increased the Anti-Spam score for Pyzor and Razor detections.

* Fixes *

  •  Fixed a problem with the Fileserver “shadow copy” initialisation.
  • The backup was taking too long after a change to the catalogue file generation. Fixed.
  • Fixed a problem with the Zarafa server out of office notification for recent installations.

Posted in System Updates | Tagged , | Leave a comment

Igaware Version 11.0.0-3 released #Igaware #linuxsbs

New in Version 11.0.0-3 [Fri July 03 2015]
========================================

* New Features and Improvements *

  •  Updated the Internet Speed test code.
  • Changed dpd timeout and delay for IPSec.
  • Updated the Mail Server M4 confuration files. They were out of date.
  • Notices regarding detected Email Virii are now not passed on to the recipient.
  • Added security to stop brute force attack against any open SSH server.
  • Increased the Anti-Spam score for Pyzor and Razor detections.

    * Fixes *

  • Fixed a problem with the Fileserver “shadow copy” initialisation.
  • The backup was taking too long after a change to the catalogue file generation. Fixed.
  • Fixed a problem with the Zarafa server out of office notification for recent installations.

Posted in Linux Small Business Server, System Updates | Tagged , | Leave a comment

CDC Wealth Management Ltd – Igaware Linux Small Business Server Case Study – 8 Users

CDC Wealth Management provides bespoke financial solutions to high and ultra high net worth individuals throughout the UK. Established in 2006, the firm has grown to a team of six advisers, who visit and advise clients, face to face with meetings held on and off-site.

As the CDC advisers spend a considerable amount of time off-site, it is essential that they have reliable access to emails and documents while out the office, using their mobiles, tablets, and laptops. Their existing IT systems were unreliable, so they looked for advice from Mark Shaw (System Administrator) of the North East Business and Innovation Centre (BIC) in Sunderland. This was an obvious contact point for CDC as their head office is based at the BIC and as a tenant one of the benefits they can tap into is IT support from the BIC’s IT team, led by Mark.

Mark told us, “CDC was being held back by the systems they had in place. Remote access to data was unreliable, and important features such as shared calendars, and out-of-office, weren’t available.”

On Mark’s recommendation, CDC chose to migrate to an Igaware Linux Small Business Server. “The Igaware Linux Small Business Server ticked all the boxes for CDC. It offered a robust, all-in-one server solution providing remote access to files, email, shared calendars and contacts. As security and data backup are included, it offered the compliance essential for CDC as independent Demokonto für Trader and financial advisers.”

The BIC IT team undertook the migration, and now look after the server in the BIC’s own data centre on-site.

John Dixon, MD at CDC, is ‘delighted’ with the Igaware Linux Small Business Server. “The Igaware Server has given us the confidence and ability to grow our business, and better serve our clients. We know we can access emails and documents wherever we are, easily and always.”

The Igaware Linux Small Business Server is an all-in-one server solution engineered to meet the needs of SMEs:

  • Internet & Email Security
  • Remote Working/VPN
  • File Server
  • Email Collaboration Server
  • Data Backup
  • Affordable
  • Fully managed & supported

Posted in Case Study, Linux Small Business Server | Leave a comment

Igaware Version 11.0.0-2 released #Igaware #linuxsbs

This blog entry details updates in latest release plus other recent releases not mentioned on here before now.

New in Version 11.0.0-2 [Mon June 15 2015]
========================================

* New Features and Improvements *

  • Updated the Linux Kernel to v3.18.14
  • Updated the OpenSSL software to the latest version.
  • Updated the nmap network discovery software to the lastest version.
  • Updated “Ping scan lan” in System=> Tools to use fing instead of ping.
  • Updated the PHP software to a new version.
  • Updated the anti-virus scanner to the latest version.
  • Updated the Anti-Spam software to the latest version. Added new plugins.
  • The kernel boot grub scripts have been re-rwitten to allow EFI booting for new hardware.Removed the SSLv3 protocol for the Igaware Web server, when high security is selected.
  • Created and installed a new TLS certificate for sendmail in /etc/mail/certs.
    – Removed some old directories from the web server path – /addresbook, /addr and /icons.
  • Added a facility to the AV software to ignore problem “false positive” signatures. Note: this has only been used once.
  • Re-compiled curl to include ca-bundle certificate path.
  • Changed the memory allocator for the AV daemon to improve performance.
  • Added winbindd daemon check to the System Status Console. This will prevent the log files filling up if the daemon gets confused.
  • Added sender based address routing to the Email server. Servers=> Email=> SMTP Forward. A new option “forwarding based on” has been added.
  • Installed secure tunneling software – stunnel.
  • The default networking qdisc has been changed to fq_codel. This should help with network “buffer bloat”.
  • Updated the Iscsi kernel modules for new kernel version.
  • Updated the IPSec VPN kernel module to use the Libreswan version for the new kernel.
  • Re-compiled curl to include ca-bundle certificate path
  • Installed the sshfs software to allow mounting of remote directories.
  • Updated hardware sensors software.
  • Installed Perl modules – Net/Patricia, IO/Socket/IP, and a few more for the Anti-Spam email scanner.

* Fixes *

  •  Fixed a problem when setting the Email “vacation” notice in the Horde groupware. The bug was introduced with the new version of Sendmail.
  • Fixed a problem with the email “vacation” message database introduced with the new version of the Sendmail email server.
  • Fixed a bug with unknown local recipient forwarding that was intorduced with the new version of the Sendmail software.
  • Fixed an bug with the System Status Console daemon.
  • Fixed the Log Viewer export function. The exported file format would sometimes be corrupted.
  • Fixed a problem with a new feature for the Email trailer blacklist. Add an extra space after :, incase there isn’t any.
  • Updated the Dynamic DNS software to fix a bug.
  • Removed restriction for sslv3 SSL protocol – some old browsers don’t support TLS.

New in Version 10.3.4 [Sun Apr 19 2015]
=======================================

* New Features and Improvements *

  • Installed latest version of sendmail mail server. Provides security updates.
  • New advanced Email anti-spam features added.
  • New feature added to the File Server – Windows Shadow Copy feature ( Restore
    previous versions). This has been added to the Fileserver Share config’ page.
    You can enable the Shadow Copy feature for any File Server Share and be able to
    use the “Restore previous versions” tab in Windows.
  • Added USB 3.0 drivers to Linux kernel code.
  • Updated the Check-in page to show general network interface information in a
    popup window.
  • Zarafa Server cache is now cleared on a Sunday to limit VM usage.
  • Added network access control to PPTP VPN. You can now limit the destination
    LAN network that is accessible during a PPTP session.

* Fixes *

  • Fixed a problem when exporting logs for viewing in Log Viewer. Old logs would
    appear corrupt and would not open.
  • Corrected the firewall rule placement for “Port Input” REJECT rules.
  • Port Forward config’ page. Fixed a page renering problem.
  • Re-written HTTP communication functions. Fixes HTTP POST delay problem.

Posted in System Updates, Uncategorized | Tagged , | Leave a comment

Some Handy Desktop Shortcuts…….

Vacation message
Non Zarafa users can set vacation messages using the following desktop shortcut:
https://serverip/config/USERS/vacation.php?username=user&password=password

The username and password should be the user’s username and password and server ip that of the Igaware Linux Small Business Server.

Spam Whitelist

You can create a desktop shortcut similar to the following:

http://SERVER_IP/config/SERVERS/EMAIL/FILTER/SPAM/desktop_whitelist2.php ( obviously SERVER_IP is the local ip address)

If you go to that URL, it will explain other options that can be set.

For example, you have to specify the user name in the URL. Do that with:

http://SERVER_IP/config/SERVERS/EMAIL/FILTER/SPAM/desktop_whitelist2.php?username=user

You can, also, set the password on the URL:

http://SERVER_IP/config/SERVERS/EMAIL/FILTER/SPAM/desktop_whitelist2.php?username=user&password=password

 

Posted in Hidden Gems, Linux Small Business Server | Leave a comment