Release Notes CGS 7.0.2

Collax Groupware Suite
07.02.2017

Installation Notes

Update Instructions

To install this update please follow the following steps:

Procedure

  1. It is highly recommended to backup of all server data with the Collax backup system before proceeding. Check that the backup was successful before proceeding with the update (this can be done within the backup information email).
  2. In the administration interface go to System → System Operation → Software → System Update and press Get Package List. This will download the listed update packages. If successful the message Done! will be displayed on the screen.
  3. Click Get Packages to download the update packages.
  4. Click Install. This installs the update. The end of this process is indicated by the message Done!.
  5. A new kernel will now be installed. The system will reboot automatically after installing the update. An appropriate note will be shown if the update process is completed.

New in this Version

Kopano Groupware: Kopano Core replaces Zarafa Collaboration Platform

With this Collax software update Kopano Core is beeing implemented. The previous Zarafa Collaboration Platform is going to be replaced. Kopano Core is a enhancement of the Zarafa Collaboration Platform. The specialty is that the change to Kopano Groupware happens automatically so that the administrative effort is very low. Additionally the plugins File with owncloud support and RTC-baces webmeetings are implemented. Within this update Kopano Core 8.1.1 is going to be installed. Find more information about Kopano on:

Kopano Core Info und Release Notes

Kopano Groupware: WebApp 3.2.0

With this Collax software update the new version 3.2.0 of Kopano WebApp is going to be installed. Please find details here:

https://documentation.kopano.io

Kopano Groupware: Compatibility to Kopano DeskApp

With this Collax software update the new version Kopano Core 8.1.1 is going to be installed. Please note that this version is compatible to Kopano DeskApp. Find more information about Kopano DeskApp on

Kopano Deskapp

Kopano Groupware: Integration of Z-Push for ActiveSync Clients

With this Collax software update the support for ActiveSync Clients by Z-Push is going to be implemented through the Collax administration interface. Outlook 2013 and Outlook 2016 can therefore sync their data via Z-Push.

Mobiler Zugriff

Kopano Groupware: Z-Push Active-Sync Provisioning policies

With this Collax software update an individual set of policy and security settings to the Z-Push synchronization process can be applied. Find more information about it on:

Mobile Policies

Kopano Groupware: Kopano Outlook Extension

With this Collax software update the support for ActiveSync Clients by Z-Push is going to be implemented through the Collax administration interface. Outlook 2013 and Outlook 2016 can therefore sync their data via Z-Push. With the additional Kopano OL Extension some features have also been added otherwise missing in Outlook, like reply/forward-flags, the global address book (GAB) or out-of-office notifications are added on top of the regular Outlook.

Kopano Outlook Extension und Client Gegenüberstellung

Kopano Groupware: Kopano Backup replaces Zarafa Backup Plus

You can back up the mailboxes, tasks, contacts and appointments with the new performance optimized Kopano Backup. It merely serves as a supplement to common backup mechanisms. The collax integration enables the same administration procedures as before.

Kopano Groupware: Kopano Files-Plug-In

With this Collax software update Kopano Files-Plug-In is beeing implemented. The plugin boosts your productivity by allowing you to use your existing storage solutions right from the WebApp interface. The function Kopano Files for Teams needs a special licence. Find more information on:

File Management im Web

Kopano Groupware: Kopano Webmeetings

With this Collax software update Kopano Webmeetings-Plug-In is beeing implemented. Meet online with unparalleled video and audio quality, right within WebApp. The function Kopano Webmeetings needs a special licence. Find more information on:

Webmeetings

GUI: GUI-Design

With this update the Web interface is going to be improved and more detailed. Based on the recommendation from Google and the tenets and specifics of material design.

GUI: Network Groups

Within this release network groups can be used. Network groups offer a new configuration approach. In the past, permissions have been configured using the user groups. Network and service permissions have been used in one group together. From now on network groups are created and can be used seperately. All services on the Collax Server whose permissions are assigned exclusively on the basis of an IP address from now on use network groups. If a permission is set, the respective network port is opened in the firewall for the associated networks or hosts.

GUI: Transparent user and network permissions

Within this release permissions for users and permissions for networks are differentiated. So there are user groups and network groups from now on. A number of network groups are created by default. The Internet group contains the “Internet” network as member, i.e. all IP addresses outside the local network ranges. Thus, all permissions granted over this network group apply to all computers anywhere on the Internet.

GUI: Host-Elements

There are various input boxes where ip addresses have been used in the previous version. Within this release the usage of ip addresses has been renewed. Collax Server V7 now uses host-elements. The term “host” refers to individual computers that are known to the Server. A host as an existing element is needed for various settings regarding the services. Host-elements replace the input boxes for ip addresses.

GUI: Clean-up form history and popups

In the dialog “Clean-up” in the menu Status->Toolbox->Clean-up it is possible to remove the browserdata saved by the GUI. Its the form history and the form popups.

Authentication: Status of Active Directory Integration

Within this update the integration of Collax Servers into Active-Directory environments have been extended. An additional field with extended runtime information is displayed. Therefore the Active-Directory-Proxy must be activated. Information regarding the connected Domain-Controller (DC) and other useful information is displayed.

Authentication: Importable Active Directory Groups

For groups from the Active Directory management to be displayed, the system must have joined an Active Directory as member, and the Active Directory proxy must be activated on the system. The listed group can be integrated in the local policies after these have been included in the management. The users of the AD groups will continue to be managed via the Active Directory and are not part of the local system. Within this release some improvements have been implemented.

Authentication: Synchronisation with Active Directory

Until now, the synchronisation of directoy objects in Active-Directory (AD) environments stopped, when the Domain Controller wasn’t reachable during a configuration activation. The synchronisation worked only after a restart of the service or another config activation. The behaviour has been improved within this release through frequent runtime checks if the server is reachable again.

Security: Linux Kernel 4.4.44

Collax Server 7 is based on the long time support (LTS) Kernel 4.4. It provides better hardware support und more security fixes und is supported until Februar 2018.

Security: System Security

The new Collax V7 Server is a system which is almost 100% (97%) deterministic/reproducable. The collax build system guarantees that binary-files and system-packages (.deb) are build deterministically. All Collax Servers are hardened to reduce the vulnerability and secure the system.

Security: Amavis - Filter engine and Virus notification

AMaViS (A Mail Virus Scanner) is a high-performance and reliable interface between the mailer (MTA) and one or more virus scanners. The inspection of emails will now result in a more detailled description of the virus and the used scanengine in the virus notification email and the system logfile.

System Management: New Supervisor

A new service supervisor for the Collax platform is beeing implemented. The supervisor manages system processes and services likemonitoring, logging and starting of processes and services.

System Management: Active Monitoring

Within this update the active monitoring (Nagios) is activated per default after installing the system.

Net: Host Analysis

The new function “Host Analsys” located under “System -> Network -> Firewall” can be used to determine the netgroups which are responsible for a given host. You can use that information to determine which netgroup need to be configured to allow access to specific services.

Add-on Software: New Version of Collax Virus Protection

The virus scanner Collax Virus Protection offers comprehensive antivirus protection for email services. Within this Collax system update the scanner is updated to the newest version.

Add-on Software: New Version of Avira Antivir

The virus scanner Avira Antivir offers comprehensive antivirus protection for email services. Within this Collax system update the scanner is updated to the newest version.

Add-on Software: New Version of Clam-AV

The Open Source virus scanner Clam-AV offers comprehensive antivirus protection for email services. Within this Collax system update the scanner is updated to the newest version.

Hardware: Partitionschema

Within this release new installations get a new paritionschema. A new minimal size should be 16GB and the service partition will be removed.

Hardware: PVSCSI Driver for VMWare

VMware’s PVSCSI SCSI-driver has been added to simplify the installation in VMWare environments. The driver supporte VMWare’s para virtualized SCSI HBA.

Hardware: VMCI Driver for VMWare

VMware’s Virtual Machine Communication Interface drivers have been added to simplify the installation in VMWare environments. The driver enables high-speed communication through the VMCI-device.

Hardware: Microsoft Hyper-V-Support

Microsofts Hyper-V Linux Integration Services drivers have been added to simplify the installation in Microsoft Hyper-V environments. The driver enables high-speed communication through the VMBus-network-controller and the SCSI-controller.

Hardware: Additional hardware support for NVMe-devices

This update brings support for NVM Express (NVMe) Devices.

Misc: Important System Components

This update will also install/update the following important system components:

  • apache2 2.2.31
  • php5 5.6.30
  • perl5.8 5.22.1
  • python 2.7.12
  • openssl 1.0.2k
  • libc6 2.18
  • kernel 4.4.45
  • mariadb 10.0.29
  • samba 4.3.13
  • bind 9.9.9.5
  • spamassassin 3.4.1
  • cyrus imap 2.5.10
  • zpush 2.3.4
  • zarafa-client 7.2.4-52167
  • postfix 3.1.1

Misc: SSL/TLS Version and local services

By connecting to various local services like the Webadministration-Service or IMAP, from now on you can choose the encryption method for SSL/TLS. You can either choose “compatible” or “modern” now. Not all clients support modern TLS (TLS 1.2). That’s why due to compatibility reason you can still configure weak TLS (TLS 1.0) for older clients.

Misc: IPv6 Support Preparation ready

All services on the new Collax Server platform are prepared to beeing integrated into IPv6 networks. The IPv6 support will be completed in a future release.

Issues Fixed in this Version

GUI: Revoke certificates

Using the action “Revoke Certificates” the certificate is deleted and entered in the CRL (Certificate Revocation List) for the CA. From this time on, the certificate is blocked on the Collax Security Gateway. In this juncture the GUI output details have been to small. With this release we maximize it to the uses screen view.

GUI: Add hosts to Network group

A Network groupd can consist of a network and mutliple hosts. Within this update its possible to add a host to a Network group directly within the dialog of the network group via a multilist element.

Notes

Kopano Groupware: Multi-Server setup

Within this release Multi-Server setup is suppressed at the moment.

Hardware: 32-Bit CPU

Within this release 32-Bit Hardware is not supported any more. This affects installaing and upgrading 32-Bit hardware.

Hardware: HP Smart Array CCISS Driver

The existing Smart Array CCISS-driver is replaced with the new HP Smart Array SCSI (HPSA) driver during the upgrade.

Misc: Kopano and MySQL Performance Tuning Paramater

This version will extend and adjust tuning parameters for Kopano. For an optimal tuning, the settings of the MySQL database should be optimized. Especially the values for the innodb_buffer_pool_size will be increased.

Table of Contents