Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Installation

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 02-23-2007, 07:41 PM
Senior Member
 
Posts: 58
Question Secure URL

I installed my SSL Certificate. When I type http://mydomain.com it will automatically redirect to https://mydomain.com. However, once I log in, it redirects back to http://mydomain.com.

If I type https://mydomain and log in, it stays at https://mydomain.com.

Any ideas why it won't stay at https???
Reply With Quote
  #2 (permalink)  
Old 02-23-2007, 09:44 PM
Former Zimbran
 
Posts: 5,606
Default

Is this bug what you mean:
http://bugzilla.zimbra.com/show_bug.cgi?id=5594

-john
Reply With Quote
  #3 (permalink)  
Old 02-24-2007, 11:58 AM
Moderator
 
Posts: 1,209
Default

Quote:
Originally Posted by jholder View Post
Is this bug what you mean:
http://bugzilla.zimbra.com/show_bug.cgi?id=5594

-john
This bug is a big issue for us; we are trying to deploy Zimbra as a HIPAA-compliant intra-domain system and of course it means we need a workaround.

The behaviour we want is for a user to be able to type the server's FQDN in a browser (which means http initially), get redirected to an https login screen, and then stay https thereafter.

Right now, the only way to have an https-only session for some users and still have http work for others is to ask the https users to use a predefined shortcut, e.g.:

https://ourzimbraserver.ourdomain.co...initMode=https

That's a real detriment for deploying Zimbra for secure email usage.

Mark
__________________
___________________________________
L. Mark Stone, CIO


"Uptime. All the time."

477 Congress Street | Portland, ME 04101-3431 | (207) 772-5678

proactive maintenance and monitoring | technology consulting
Zimbra groupware | EMR implementations | private cloud hosting
Reply With Quote
  #4 (permalink)  
Old 02-24-2007, 12:08 PM
Zimbra Consultant & Moderator
 
Posts: 20,317
Default

Quote:
Originally Posted by LMStone View Post
This bug is a big issue for us; we are trying to deploy Zimbra as a HIPAA-compliant intra-domain system and of course it means we need a workaround.
If that's important to you then you need to vote on it and raise a support case with Zimbra so they can attach it to the bug.
__________________
Regards


Bill
Reply With Quote
  #5 (permalink)  
Old 02-24-2007, 04:11 PM
Moderator
 
Posts: 1,209
Default

Quote:
Originally Posted by phoenix View Post
If that's important to you then you need to vote on it and raise a support case with Zimbra so they can attach it to the bug.
I had already had a conversation with support about this when we first deployed Zimbra.
__________________
___________________________________
L. Mark Stone, CIO


"Uptime. All the time."

477 Congress Street | Portland, ME 04101-3431 | (207) 772-5678

proactive maintenance and monitoring | technology consulting
Zimbra groupware | EMR implementations | private cloud hosting
Reply With Quote
  #6 (permalink)  
Old 02-24-2007, 10:35 PM
Zimbra Employee
 
Posts: 2,103
Default

If you want https only access, search the docs for the zmtlsctl command, which will do exactly that.

Or search the forums. Or the wiki.
__________________
Bugzilla - Wiki - Downloads - Before posting... Search!
Reply With Quote
  #7 (permalink)  
Old 02-25-2007, 03:51 AM
Moderator
 
Posts: 1,209
Default

Quote:
Originally Posted by marcmac View Post
If you want https only access, search the docs for the zmtlsctl command, which will do exactly that.

Or search the forums. Or the wiki.
Sorry, I probably didn't describe the behaviour I'm seeking clearly so let me try again.

Non-technical users don't type "http.." in a browser, they type the FQDN of the Zimbra server only. Indeed, they resent having to type "htt..." and often incorrectly type (or forget to type) the colon and slashes.

Here is the use case I would like:

1. User types the FQDN of the Zimbra server in a browser.
2. Zimbra redirects the login screen to an https session to ensure the login credentials are encrypted when transmitted.
3. After a successful login, the session remains https, so all email traffic is also encrypted.

After speaking with Zimbra support after first installing 4.0.3NE and trying all of the zmtlsctl options, the above use case to my knowledge is not available in Zimbra.

If I'm wrong, apologies first, and then a request as to how I can correctly use the zmtlsctl command.

Thanks,
Mark
__________________
___________________________________
L. Mark Stone, CIO


"Uptime. All the time."

477 Congress Street | Portland, ME 04101-3431 | (207) 772-5678

proactive maintenance and monitoring | technology consulting
Zimbra groupware | EMR implementations | private cloud hosting
Reply With Quote
  #8 (permalink)  
Old 02-25-2007, 05:39 AM
Zimbra Consultant & Moderator
 
Posts: 20,317
Default

Quote:
Originally Posted by LMStone View Post
Here is the use case I would like:

1. User types the FQDN of the Zimbra server in a browser.
2. Zimbra redirects the login screen to an https session to ensure the login credentials are encrypted when transmitted.
3. After a successful login, the session remains https, so all email traffic is also encrypted.

After speaking with Zimbra support after first installing 4.0.3NE and trying all of the zmtlsctl options, the above use case to my knowledge is not available in Zimbra.
As far as I know it's not available. The same answer from earlier applies - if you want a specific enhancement then you must create a bug report, vote on it and also raise a case with tech support so they can get it attached to the bug entry. Without that, nothing will be done. If there's no bug report then it will never get looked at. Do you have a bug report that describes your problem/requirement?
__________________
Regards


Bill
Reply With Quote
  #9 (permalink)  
Old 02-25-2007, 01:05 PM
Moderator
 
Posts: 1,209
Default

Quote:
Originally Posted by phoenix View Post
As far as I know it's not available. The same answer from earlier applies - if you want a specific enhancement then you must create a bug report, vote on it and also raise a case with tech support so they can get it attached to the bug entry. Without that, nothing will be done. If there's no bug report then it will never get looked at. Do you have a bug report that describes your problem/requirement?
The bug is http://bugzilla.zimbra.com/show_bug.cgi?id=7631.

It seems to have been around since 3.1.1, which probably explains why support knew about it when I asked originally. I just voted for it and I'll call support tomorrow as you suggested to raise a more formal case regarding it.

Thanks for the help to get more attention focused on this bug.

All the best,
Mark
__________________
___________________________________
L. Mark Stone, CIO


"Uptime. All the time."

477 Congress Street | Portland, ME 04101-3431 | (207) 772-5678

proactive maintenance and monitoring | technology consulting
Zimbra groupware | EMR implementations | private cloud hosting
Reply With Quote
  #10 (permalink)  
Old 02-25-2007, 01:11 PM
Zimbra Consultant & Moderator
 
Posts: 20,317
Default

That bug seems to be scheduled to be fixed in the next major release, just send an email to support with your comments and ask for your case to be added to the bug - that will do it.
__________________
Regards


Bill
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.