Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 12-30-2008, 12:57 PM
Junior Member
 
Posts: 9
Default Implementation plans

My company currently uses Zimbra for its email. Our mail server is configured as a standalone Zimbra server. We also maintain a separate LDAP server. We have decided to consolidate all of our LDAP resources into a single server, and that the canonical source should be the mail server and not our other LDAP server.

The mail server resides in our DMZ. It makes me very uncomfortable to have our master password database stored in the DMZ, so I would prefer that the master LDAP server reside in the LAN, and the mail server be configured as a replica LDAP server. I realize that this does not provide a great deal more security - a password stolen from a replica server is just as valid as one stolen from the master - but it is a significant enough security gain that I am eager to implement it.

My plan is then to configure a machine to serve as an LDAP replica, with our mail server as the LDAP master, and eventually promote that machine to master status per the instructions in the wiki. There is one small snag to this plan - the mail server resides in the DMZ and must continue to reside in the DMZ for the time being so that our employees can access their email from outside of our network. I'm planning on doing this by configuring the LDAP master to push updates to the mail server by means of <pre>syncrepl</pre> (as described in the OpenLDAP administrator's guide).

My question, then: has anyone done this (and documented their progress somewhere I can see it?) Alternatively, can anyone recommend a better way to do this? I don't believe moving the mail server into the LAN is an option - our employees must be able to access their email, contacts, and calendar outside of our network.

Last edited by KitPeters; 12-30-2008 at 12:57 PM.. Reason: corrected URL syntax
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.