Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 03-30-2009, 02:05 AM
Active Member
 
Posts: 43
Default How to track a mail

Hi,

For security reasons we want to track certain mails that are sent to users.

We want to track if the mail is forwarded to somewhere else etc.

But becuase we use TLS all the mail logs are encrypted, so I wonder is there a way to do this, identify a specific message movement ?

Best regards,
Reply With Quote
  #2 (permalink)  
Old 03-30-2009, 02:09 AM
Moderator
 
Posts: 7,928
Default

There a numerous ways of doing this though it is dependant on which version of ZCS you are running so please update your profile with the following output so we can help you
Code:
su - zimbra
zmcontrol -v
__________________
Reply With Quote
  #3 (permalink)  
Old 03-30-2009, 02:14 AM
Active Member
 
Posts: 43
Default

Quote:
Originally Posted by uxbod View Post
There a numerous ways of doing this though it is dependant on which version of ZCS you are running so please update your profile with the following output so we can help you
Code:
su - zimbra
zmcontrol -v
It's.
Release 5.0.6_GA_2313.SLES10_64_20080522105817 SLES10_64 FOSS edition

I must be able to apply the method to past logs. So any configuration should also be valid for past logs.

Best Regards,
Reply With Quote
  #4 (permalink)  
Old 03-30-2009, 02:23 AM
Moderator
 
Posts: 7,928
Default

If you are wanting to monitor for a particular email or content then I do not think this is possible unless you do something like [SOLVED] Law Enforcement (aka intercept)? or implement mail archiving.
__________________
Reply With Quote
  #5 (permalink)  
Old 03-30-2009, 02:27 AM
Active Member
 
Posts: 43
Default

Quote:
Originally Posted by uxbod View Post
If you are wanting to monitor for a particular email or content then I do not think this is possible unless you do something like [SOLVED] Law Enforcement (aka intercept)? or implement mail archiving.
No I just want to track and identify a particular mai in logs.

I am not interested in the content of the mail, just the route it has traced. For instance I receive a mail and thi is logged, when I forward it this is also logged. So there must be a logical connection between these 2 mails in logfiles.

If the mail subject headers were not TLS encrypted, this could be done from the subject text.

But it is TLS encrypted.
Reply With Quote
  #6 (permalink)  
Old 03-30-2009, 02:32 AM
Moderator
 
Posts: 7,928
Default

Quote:
Originally Posted by ghanedan View Post
I am not interested in the content of the mail, just the route it has traced. For instance I receive a mail and thi is logged, when I forward it this is also logged. So there must be a logical connection between these 2 mails in logfiles.
Nope, once you forward the email it because its own unique email. Mail archiving is the way to handle this IMHO.
__________________
Reply With Quote
  #7 (permalink)  
Old 03-30-2009, 03:31 AM
Active Member
 
Posts: 43
Default

Any other ideas ?
Reply With Quote
  #8 (permalink)  
Old 03-30-2009, 03:38 AM
Moderator
 
Posts: 7,928
Default

Quote:
But becuase we use TLS all the mail logs are encrypted
Why are they anyway ? TLS just means that the transport mechanism between MTA1 and MTA2 is encrypted; not the actual message content itself.
__________________
Reply With Quote
  #9 (permalink)  
Old 03-30-2009, 04:43 AM
Active Member
 
Posts: 43
Default

Quote:
Originally Posted by uxbod View Post
Why are they anyway ? TLS just means that the transport mechanism between MTA1 and MTA2 is encrypted; not the actual message content itself.
Sure. I see a cryptic message-id in log files, for example:
Message-ID: <C16F17028464408664D554257EA4D1227@somebody>

And think that message id part is encrypted from message header. Ok this might not be the case.

But there must be a way to track the mail with this Message-ID
Reply With Quote
  #10 (permalink)  
Old 03-30-2009, 04:48 AM
Moderator
 
Posts: 7,928
Default

CLI zmmsgtrace - Zimbra :: Wiki
__________________
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.