Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 08-29-2011, 02:35 AM
Member
 
Posts: 10
Default additonal protection with httpasswd

Hi,

is it possible to enable a password authentication (Apache config), before being redirect to the main login page ? Only for External access

regards
Reply With Quote
  #2 (permalink)  
Old 08-29-2011, 03:13 AM
Zimbra Consultant & Moderator
 
Posts: 20,315
Default

Quote:
Originally Posted by tvone View Post
is it possible to enable a password authentication (Apache config), before being redirect to the main login page ? Only for External access
Why would you want to make a user login twice to get to their email account?
__________________
Regards


Bill
Reply With Quote
  #3 (permalink)  
Old 08-29-2011, 03:34 AM
Member
 
Posts: 10
Default

Hi Bill,

thanks for your reply.

Our Zimbra Mail Server(http Login page) is reachable from WAN (via DNS or IP). I had in mind that it would be more safe to ask for a additional password before you get access to the main mail login page. Simply to filter bruteforce-attacks or things like that. For all other employees which come via internal network will get directly to the login page .

Regards
Reply With Quote
  #4 (permalink)  
Old 08-29-2011, 03:40 AM
Zimbra Consultant & Moderator
 
Posts: 20,315
Default

Quote:
Originally Posted by tvone View Post
Our Zimbra Mail Server(http Login page) is reachable from WAN (via DNS or IP). I had in mind that it would be more safe to ask for a additional password before you get access to the main mail login page. Simply to filter bruteforce-attacks or things like that. For all other employees which come via internal network will get directly to the login page .
Then why not implement a strong password policy (you can do that in the Admin UI) and/or something like fail2ban if you're concerned about brute force attacks? just adding two login pages doesn't really make you more secure unless you do something about what happens if a login fails or is apparently an 'attack'.
__________________
Regards


Bill
Reply With Quote
  #5 (permalink)  
Old 08-29-2011, 05:23 AM
Member
 
Posts: 10
Default

Hi,

fail2ban is a good tool and i think i will use it. The second point is, with an additional query you will not see the page immediately. And that means you have no oportunity to exploit security gaps in java, javascript,mysql etc. Because you will intercepted these previously. Correct me if i'm wrong
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.