Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
 
Go Back   Zimbra - Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra - Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 05-15-2006, 12:31 PM
Senior Member
 
Posts: 73
Default Does Zimbra support IMAP Secure Authentication?

Hi All

When I select "Use secure authentication" in my IMAP server settings in Thunderbird, I get this error "You cannot log in to myimapserver.domain.com because you have enabled secure authentication and this server does not support it. " (see attached screenshots).

My question - does Zimbra support IMAP Secure Authentication?
Is there anything I should do on the Zimbra server?
Everything seems working in Zimbra - nothing in zimbra.log.
All services running - including saslauthd (although I don't know if this is related to Secure authentication).

I am using Zimbra 3.1 on Fedora 4.
"Use SSL connection" in Thunderbird works, but "Use secure authentication" does not.
I've also enabled both "Use SSL" and "Use secure authentication" at the same time, but it still gave the same error message.

From my understanding, Thunderbird IMAP server settting "Use secure authentication" means that the client and server negotiate whether they want to use CRAM-MD5, MD5-digest or Kerberos to authenticate the user without sending the password across the network.
Now, does Zimbra support this? Can somebody advise?

Thank you very much in anticipation.

gui
Attached Images
File Type: jpg thunder02.jpg (8.2 KB, 864 views)
File Type: jpg thunder01b.jpg (15.9 KB, 869 views)

Last edited by zzzzsg : 05-16-2006 at 10:33 AM.
Reply With Quote
  #2 (permalink)  
Old 05-21-2006, 06:39 PM
Zimbra Employee
 
Posts: 4,784
Default

Try using just SSL for IMPA. Make sure in the Admin UI you have SSL enabled for IMAP.
__________________
Bugzilla - Wiki - Downloads - Offline Client
Reply With Quote
  #3 (permalink)  
Old 05-25-2006, 06:48 PM
Senior Member
 
Posts: 73
Default

Hi Kevin

I've tried that before and it worked, but that is not what we want.
We don't want the entire IMAP to be SSL.
Only want Secure Authentication.

Thanks.

gui


Quote:
Originally Posted by KevinH
Try using just SSL for IMPA. Make sure in the Admin UI you have SSL enabled for IMAP.
Reply With Quote
  #4 (permalink)  
Old 05-26-2006, 01:12 PM
Zimbra Employee
 
Posts: 4,784
Default

Ok then that would be an enhancement request. I don't think we support that today.
__________________
Bugzilla - Wiki - Downloads - Offline Client
Reply With Quote
  #5 (permalink)  
Old 11-06-2009, 07:08 AM
Intermediate Member
 
Posts: 15
Default

While on the subject zimbra does not support encrypted mails
like PGP or anyother format
Reply With Quote
  #6 (permalink)  
Old 11-06-2009, 07:23 AM
Zimbra Consultant & Moderator
 
Posts: 11,517
Default

Quote:
Originally Posted by awtohost View Post
While on the subject zimbra does not support encrypted mails
like PGP or anyother format
Search bugzilla for 'pgp'.
__________________
Regards


Bill
Reply With Quote
  #7 (permalink)  
Old 11-06-2009, 07:19 PM
Outstanding Member
 
Posts: 596
Default

In the 3 years since the original post, Zimbra has added kerberos. Configuration is complex, but big kerberos shops are used to that.

The md5 challenge/response mechanisms require the server to store a cleartext or cleartext-equivalent password, which is generally considered undesirable. Recent null-byte and rekeying news notwithstanding, SSL3/TLS is better... and best is kerberos, client certs, or one-time passwords over TLS.

As for PGP, I'd say that Zimbra is 100% in sync with PGP's security model, which is that user keyrings should never be stored on servers (neither pubring nor secring). Keys should live on your single-user workstation. You can use an IMAP client, or possibly a browser plugin like FireGPG.
Reply With Quote
Reply


Thread Tools
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

Zimbrablog.com




 

Search Engine Optimization by vBSEO 3.1.0