Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 05-13-2011, 01:32 AM
Advanced Member
 
Posts: 222
Default POP3 + SSL problem after upgrade to ZCS 7.1

Hi,
after upgrading my ZCS 7.0.2 to 7.1 users have problems connecting to server using POP3+SSL (port 995). They all get the same error:

Your server does not support encryption type you have specified.

I did not mess with (valid) SSL certificate after ZCS upgrade, and also SSL is valid and shows properly in admin console. POP3 service is running.
Plain-text POP3 via port 110 works without problems.

When testing with telnet to port 995, instead of blank reply, I get a bunch of smileys:
§♥☺☻☺

Connection to host lost.


Any idea?
Anybody else with same problems?

Last edited by Labsy; 05-13-2011 at 01:44 AM..
Reply With Quote
  #2 (permalink)  
Old 05-13-2011, 03:45 AM
Advanced Member
 
Posts: 222
Default

UPDATE:
Found almost 100 connections to POP3S port 995 from 1 single IP, like:

Code:
tcp6    0    0    zimbra.server.com:pop3s 1.2.3.4%187:51234 ESTABLISHED
tcp6    0    0    zimbra.server.com:pop3s 1.2.3.4%187:51235 ESTABLISHED
tcp6    0    0    zimbra.server.com:pop3s 1.2.3.4%187:51236 ESTABLISHED
tcp6    0    0    zimbra.server.com:pop3s 1.2.3.4%187:51237 ESTABLISHED
tcp6    0    0    zimbra.server.com:pop3s 1.2.3.4%187:51238 ESTABLISHED
tcp6    0    0    zimbra.server.com:pop3s 1.2.3.4%187:51239 ESTABLISHED
...
As I cannot change default 100 pop3 connections limit without restart, I tried to block this IP on firewall level, but since connections are ESTABLISHED, firewall cannot kill them.

So next I try to kill those sessions:

Code:
tcpkill host 1.2.3.4
But no connections were killed, stuck with

Code:
tcpkill: listening on eth0 [host 1.2.3.4]
Anyways, seems like I found problem source.
Reply With Quote
  #3 (permalink)  
Old 05-13-2011, 03:56 AM
Advanced Member
 
Posts: 222
Default

Actually...considering circumstances, this could also be Zimbra vulnerability, since an attacker can open multiple POP3 connections to server, rendering it unavailable for all other users.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.