Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 02-14-2008, 08:54 AM
Senior Member
 
Posts: 67
Default GAL Access Password?

Hi guys,

Just a question about something I have not been able to find up to now. When you open the LDAP port to allow GAL lookups in Thunderbird, you do not need to type in a username and the LDAP is running on a non-secure port. Is there an easy way to change these settings on the server so that users can access the port 636 (LDAPS) and are required to enter a password to do GAL lookups?

Many thanks,
Gary
Reply With Quote
  #2 (permalink)  
Old 02-14-2008, 11:52 AM
Moderator
 
Posts: 1,027
Default

This is an identified issue. See this thread.
Restricting LDAP permissions

It's been registered as a bug, and you can add your vote or comments on bugzilla:
Bug 15378 - Obviate the need for and disallow LDAP anonymous binds

See also
Bug 16601 - Secure Access To LDAP

In other words, you're not the only one with this concern, and it will be addressed but is not fixed at this time.

In the meantime, is your concern having public access from the outside world, or also securing the GAL within your own network? If the former, firewalling the server and not permitting port 389 access except from the LAN will provide some level of security; then outside users would have to log into a VPN (or simply use the web client--ssl only--from outside) before accessing their mail. May not be ideal from your architecture but it will certainly work from a security perspective.

Cheers,

Dan
Reply With Quote
  #3 (permalink)  
Old 02-18-2008, 07:08 AM
Senior Member
 
Posts: 67
Default

Hi Dan,

Many thanks for your response. I shall vote on the bug and notify our client of the current status.

Best regards,
Gary
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.