Release Notes CBS 7.2.48
Collax Business Server
09.09.2026
Installation Notes
Update Instructions
To install this update please follow the following steps:
Procedure
- It is highly recommended to backup of all server data with the Collax backup system before proceeding. Check that the backup was successful before proceeding with the update (this can be done within the backup information email).
- In the administration interface go to Menu → Software → System Update and press Get Package List. This will download the listed update packages. If successful the message Done! will be displayed on the screen.
- Click Get Packages to download the update packages.
- Click Install. This installs the update. The end of this process is indicated by the message Done!.
- A new kernel will now be installed. The system will reboot automatically after installing the update. An appropriate note will be shown if the update process is completed.
New in this version
New Application: Collax Chat
With this update, all users of Collax Business Server, Collax Groupware Suite, and the Collax Communication module will receive the new Collax Chat. Collax Chat is based on Zulip.
Users and groups are imported from the user management system and synchronized every five minutes. Newly created users are therefore automatically available in the chat without any further action, and removed users lose their access.
Login is via single sign-on. An entry automatically appears in the Web-Access user portal for authorized users. There are three permission levels available: User, Manager, and Administrator.
Important: To use the Zulip app on mobile devices, you must also log in via single sign-on. Logging in with an email address and password is not possible.
User Management: User Photo
In User Management, you can now add a user photo for each user. The image is automatically resized upon upload and is then available to all applications that display profile pictures—such as Collax Chat and the groupware address books. The photos are included in data backups and restored during a restore.
To ensure that photos maintained in Active Directory are also imported for users from Active Directory, there are two options:
- Edit each user with a photo in Active Directory again so that they receive a new Unique Serial Number.
- Stop the AD service via the console, clear the cache (/var/cache/adsuckd/), and restart the service. Our support team will be happy to assist you with this.
Toolbox: Checking Emails and Files
A new form for checking emails and files is now available in the Toolbox. Suspicious emails can be uploaded. A result is then displayed for each scanner; email containers are unpacked and their attachments are checked individually, including not only the standard email format but also winmail.dat and Outlook messages in .msg format.
Grommunio: Multiple Email Domains
Support for multiple email domains has been significantly expanded. It now includes sending and receiving email via the respective domains, public folders, and resources such as rooms and devices. The import of public folders from a Kopano migration now also supports multiple domains.
Grommunio: Resources Belong to a Single Email Domain
Resources such as rooms and devices belong to exactly one email domain. This is now clearly indicated on the admin interface. Resources can be reached via email even if they are not located in the main domain. Previously, invitations to such rooms were rejected with the message “user unknown.” The same name can now be used across multiple domains.
Important: Resources that were previously assigned to multiple domains will be automatically split into one resource per domain during the update. The existing mailboxes and their calendar data will be preserved.
Grommunio: Organizations
For larger environments, organizations can now be managed in the administration interface.
Firewall: Enable or Disable Port Forwarding with a Right-Click
In the port forwarding overview, you can now enable or disable individual rules directly with a right-click. Previously, you had to go through the details view each time to do this.
System Management: Daily License Check
The license status is now checked daily instead of weekly. This means that the automatic switch from expiring Avira licenses to Collax Virus Protection takes effect more quickly.
Issues fixed in this version
System Management: Linux Kernel 6.6.156
This update upgrades the Linux kernel to version 6.6.156.
A critical security vulnerability in the Linux kernel that allowed locally logged-in users to gain root privileges has been patched. As a general rule, no user should be granted SSH access to the server.
Security: Red Team Assessment of the Collax Security Gateway
The Collax Security Gateway was assessed as part of a red team assessment conducted by the external security service provider turingpoint GmbH from Hamburg. The vulnerabilities reported during this assessment have been addressed in this update. The fixes apply to shared components and therefore affect all Collax products.
Security: Login and Privilege Wrappers
The login process for the administration interface has been revised. Login credentials can no longer be read by scripts in the browser, and the previous login path used to access the interface has been removed. In addition, the privilege wrappers (suwrap) for the administration interface have been hardened.
Security: ClamAV 1.4.5
The ClamAV virus scanner has been updated to the current LTS version, 1.4.5. Version 1.0.x, which was previously in use, is no longer supported by the developers, which is why the warning “Your ClamAV installation is OUTDATED!” appeared in the log. This warning no longer appears; detection itself was not affected by this issue.
Security: ProFTPD
Security vulnerabilities that had been reported for the ProFTPD FTP server have been patched.
DHCP: Address Assignment from a Different Pool
Under certain circumstances, the DHCP server might have assigned an address from a different pool to a computer. This issue has been resolved.
Please note: If a pool is exhausted, addresses from another pool will no longer be assigned to the affected computers. They will then remain without an address.
System Management: Minibus on Processors Without AVX2
On older processors without AVX2 support, the Minibus service would not start and was reported as an error in the monitoring system. This has now been fixed.
File: User Quota from a Group
In rare cases, if a user quota was removed from a group, the old limit remained active. Write access was then denied, even though the remaining group limit would have been sufficient.
Mail: REDIRECT Rules in the Mail Filter
In the mail filter, REDIRECT rules pointing to an address within the organization’s own mail domain resulted in a bounce with the message “User unknown in virtual alias table.” The addresses are now resolved correctly.
Email: Distribution List with the Same Name as a Group
If an email distribution list has the same name as a group, a warning will now appear when saving. Previously, the list was silently discarded in such cases.
Certificates: Error Messages from Let’s Encrypt
If the issuance of a Let’s Encrypt certificate failed, the process previously resulted in a generic timeout. The job log now includes the affected domain and the reason reported by Let’s Encrypt.
Kopano: Let’s-Encrypt-Zertifikate für IMAPS
Bei der Groupware Kopano wurden Let’s-Encrypt-Zertifikate für IMAPS nicht akzeptiert. Mail-Programme lehnten die verschlüsselte Verbindung deshalb ab. Das ist nun korrigiert.
Proxy: Collax URL Filter
The URL filtering functionality of the Collax URL Filter in the web proxy has been revised.
Grommunio: Multi-Domain Configuration After an Update
A bug that caused the multi-domain configuration to stop working after an update has been fixed.
Grommunio: Shared Mailboxes and Resources
Several bugs have been fixed regarding shared mailboxes and resources: Emails sent to a shared mailbox resource were not delivered, rooms were rejected with the message “user unknown,” and shared users and shared mailboxes did not function reliably.
Grommunio: Full-Text Search
The full-text search has been accelerated by the inclusion of grommunio-index. As a result, searching within the groupware web interface is once again reliable.
Grommunio: Logouts in the WebApp
There were instances where users from Active Directory were logged out of the WebApp too quickly. This issue has now been resolved.
Grommunio: Deputy Function and Assistant
The deputy function and the setup assistant have been revised.
Grommunio: Updated Components
The Grommunio components have been updated.
Notes
Additional software: Bitdefender - pattern update after commissioning
After starting up the Collax Antivirus powered by Bitdefender module, it may take a few minutes for the current virus patterns to be downloaded. If you click on Update Bitdefender in the virus scanner form during this time, you will receive an error message “Error connecting to server at /opt/lib/bitdefender//bdamsocket: -3”, because the background process has not yet been fully executed.
GUI: Sporadic hangs during running jobs
The progress of configuration jobs is displayed in the top right-hand corner of the web administration. In the case of extensive changes in the network area, especially with country locks (geo-ip), it can happen in rare cases that the job display hangs during activation. As of release 7.2.28, you will now receive the message “Network connection has been interrupted: Messages may be lost until the connection can be re-established.” informs you about such situations.
VPN: Fix for IKEv2 with Microsoft Windows crashes after 7.6 hours
VPN connections with IKEv2 and the on-board tools of Microsoft Windows are interrupted after interrupted after exactly 7.6 hours. The error occurs because Microsoft Windows proposes different algorithms during the IKE re-encryption than during the first connection. The problem can be solved with a registry fix by the value “NegotiateDH2048_AES256” under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\Parameters to 1 is set.
Under the following link you will find a REG file (registry entry) that adds the registry key. Collax accepts no liability for system errors resulting from this.