Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Installation

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 03-04-2009, 06:03 PM
New Member
 
Posts: 3
Default Zimbra + mod_proxy

Hi Guys,
First I wanted to say awesome product! Second, I need help so I'm here to get it. I have Zimbra installed and working perfectly but I want to put it behind a reverse proxy server. The server is running ubuntu linux with apache and mod_proxy. Once I get it working I am going to enable mod_security and we'll be ready to rumble.

That said, the reverse proxy doesn't work properly. When I attempt to read email from a proxied connection I get communications errors upon clicking on the email. Then when I take a look at the log files I see:

172.16.15.82 - - [04/Mar/2009:20:20:02 -0500] "POST /service/soap/ModifyPrefsRequest HTTP/1.1" 503 437 "http://suck.netragard.com/" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_5_6; en-us)
AppleWebKit/525.27.1 (KHTML, like Gecko) Version/3.2.1 Safari/525.27.1"

So, every time there is a post, the error is generated. Can anyone give me any help on how to solve this? Does anyone have a working mod_proxy + Apache2 config that they could show me? Thanks much in advace!
Reply With Quote
  #2 (permalink)  
Old 03-05-2009, 01:55 AM
Moderator
 
Posts: 2,207
Default

Welcome to the forum.

Everything is in the wiki...
Zimbra with Apache using mod jk - mod proxy - mod proxy ajp - Zimbra :: Wiki
Reply With Quote
  #3 (permalink)  
Old 03-05-2009, 08:08 AM
New Member
 
Posts: 3
Default Thank you!

Also, is there a list of vulnerabilities anywhere out there for Zimbra? Or some sort of advisory database or maling list that we can monitor?
Reply With Quote
  #4 (permalink)  
Old 03-05-2009, 08:16 AM
Moderator
 
Posts: 2,207
Default

Any vulnerability found is posted to the forum (in the "Announcements").
Reply With Quote
  #5 (permalink)  
Old 03-05-2009, 08:24 AM
New Member
 
Posts: 3
Default Security Questions Now

Ok thats good. Thanks much for the quick responses. Does Zimbra use parameterized stored proceedures for its queries? Have there ever been any SQL Injection vulnerabilities or XSS issues discovered? Whats done to keep it safe? Do you follow the OWASP standards?
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.