From thomas at intevation.de Wed Jan 17 19:16:02 2007 From: thomas at intevation.de (Thomas Arendsen Hein) Date: Wed, 17 Jan 2007 19:16:02 +0100 Subject: [Kolab-announce] Kolab Server 2.1 Beta 4 released Message-ID: <20070117181602.GA8545@intevation.de> Hi! I've just uploaded Kolab Server 2.1 Beta 4, which fixes more than 20 problems found in Beta 3 and includes the security updates published until now. Documentation and OpenPKG source packages will be available in the directory server/beta/kolab-server-2.1-beta-4/ of the mirrors listed on http://kolab.org/mirrors.html soon. Included is a gpg signed MD5SUMS file to verify if your download is correct: $ gpg --verify MD5SUMS $ md5sum -c MD5SUMS Please look at 1st.README and release-notes.txt for more information about this release. The changes since server 2.1 beta 3 are listed below for your convenience. UPGRADING.20-21 contains instructions for upgrading from Kolab server 2.0 to 2.1, but they need testing on more live systems. Please report failed and successful upgrades to the mailing list. (These instructions didn't change since 2.1 beta 3) Regards, Thomas Arendsen Hein Changes since 2.1 beta 3: - clamav-0.88.7-20061211 bypass virus detection (CVE-2006-6406), denial of service, remotely exploitable (CVE-2006-6481) (http://kolab.org/security/kolab-vendor-notice-14.txt) - kolabd-2.0.99-20070117 Updated proftpd.conf template: LDAPHomedirOnDemand(Prefix) is now named LDAPGenerateHomedir(Prefix). Set imapidlepoll to 5 seconds in imapd.conf.template.in. kolab/issue1433 (Some files in /kolab/etc/postfix have wrong ownership) kolab/issue1484 (Warnings using openldap = 2.3.27-2.20061018_kolab) kolab/issue1487 (amavisd.conf mynetworks incomplete) kolab/issue1531 (amavisd.conf local_domains only contains primary domain) kolab/issue1532 (Set "duplicatesuppression: 0" in imapd.conf.template?) - kolab-horde-fbview-2.0.99-20070112 Improvements to the week view (part of kolab/issue666) Removed dangerous php scripts (part of kolab/issue1507) - kolab-resource-handlers-2.0.99-20070117 kolab/issue1490 (freebusy cache written to /kolab/kolab/...) kolab/issue1512 (No FB information for resource accounts) kolab/issue1558 (kolab-webadmin and php 5.2.0) - kolab-webadmin-2.0.99-20070117 kolab/issue1013 (user passwords sha1 encoded without salt) kolab/issue1262 (Setting quota to 4096+ MB breaks message delivery) kolab/issue1418 (fields visible even when attribute_access is "hidden" in session_vars.php) kolab/issue1540 (Typo on kolab/admin/service page) kolab/issue1555 (Login screen shows error msg for no good reason) - openldap-2.3.29-2.20061110_kolab New upstream version, fixes CVE-2006-5779 (Bugtraq ID 20939) - perl-kolab-5.8.7-20070117 Only print warning about missing configuration variable if relevant. kolab/issue1550 (Masquerade problem) -- Email: thomas at intevation.de http://intevation.de/~thomas/ -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 189 bytes Desc: not available Url : http://kolab.org/pipermail/kolab-announce/attachments/20070117/4c375826/attachment.bin From thomas at intevation.de Mon Feb 5 19:18:26 2007 From: thomas at intevation.de (Thomas Arendsen Hein) Date: Mon, 5 Feb 2007 19:18:26 +0100 Subject: [Kolab-announce] Kolab Server 2.1 Release Candidate 1 released Message-ID: <20070205181826.GF13126@intevation.de> Hi! I've just uploaded Kolab Server 2.1 release candidate 1, which fixes more than 10 problems found in Beta 4 and includes the security updates published until now. Documentation and OpenPKG source packages will be available in the directory server/beta/kolab-server-2.1-rc-1/ of the mirrors listed on http://kolab.org/mirrors.html soon. Included is a gpg signed MD5SUMS file to verify if your download is correct: $ gpg --verify MD5SUMS $ md5sum -c MD5SUMS Please look at 1st.README and release-notes.txt for more information about this release. The changes since server 2.1 beta 4 are listed below for your convenience. UPGRADING.20-21 contains instructions for upgrading from Kolab server 2.0 to 2.1, but they need testing on more live systems. Please report failed and successful upgrades to the mailing list. (These instructions didn't change since 2.1 beta 3) Regards, Thomas Arendsen Hein Changes since 2.1 beta 4: - kolabd-2.0.99-20070205 kolab/issue1335 (pfbcache.db locking problems) kolab/issue1507 (Public viewable phpinfo() and more in Server default installation) kolab/issue1550 (Masquerade problem, corrected template) kolab/issue1563 (freebusy.conf template doesn't match freebusy.conf from package) kolab/issue1575 (Openldap enhanced data integrity) - kolab-webadmin-2.0.99-20070205 Disabled Spanish language selection from web admin interface, because of missing translation. kolab/issue1479 ("Type" of shared folder can only be modified in 2nd try) kolab/issue1486 ("About Kolab" in Webinterface needs work over) kolab/issue1539 (extension to the opening text, when the manager logs in for the 1st time) kolab/issue1559 (Domain Maintainer cannot delete "his" users) kolab/issue1586 ("Required field" not translated to German in web admin) kolab/issue1592 (LANGUAGE variable overrides web admin language selection) -- thomas at intevation.de - http://intevation.de/~thomas/ - OpenPGP key: 0x5816791A Intevation GmbH, Osnabr?ck - USt-ID: DE 204 854 484 - AG Osnabr?ck, HR B 18998 Gesch?ftsf?hrer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 189 bytes Desc: not available Url : http://kolab.org/pipermail/kolab-announce/attachments/20070205/39de7086/attachment.bin From bh at intevation.de Tue Feb 13 20:05:48 2007 From: bh at intevation.de (Bernhard Herzog) Date: Tue, 13 Feb 2007 20:05:48 +0100 Subject: [Kolab-announce] Kolab KDE Client 2.1.6 released Message-ID: <200702132005.52529.bh@intevation.de> Kolab KDE Client 2.1.6 has been released at the end of January. This release contains some new features as well as several bug fixes. Among the new feature are: * Better Outlook/Toltec connector interoperability * Improved documentation * Better tooltips and alarms for recurring events A detailed list of the changes can be found in the release notes. Bernhard Herzog -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 189 bytes Desc: not available Url : http://kolab.org/pipermail/kolab-announce/attachments/20070213/0cd0b550/attachment.bin From thomas at intevation.de Fri Apr 20 19:08:35 2007 From: thomas at intevation.de (Thomas Arendsen Hein) Date: Fri, 20 Apr 2007 19:08:35 +0200 Subject: [Kolab-announce] Kolab Server 2.1 Release Candidate 2 released Message-ID: <20070420170835.GA29371@intevation.de> Hi! I've just uploaded Kolab Server 2.1 release candidate 2, which fixes more than 20 problems found in RC 1 and contains updated translations. Some security issues were fixed in clamav, spamassassin and file. Documentation and OpenPKG source packages will be available in the directory server/beta/kolab-server-2.1-rc-2/ of the mirrors listed on http://kolab.org/mirrors.html soon. Included is a gpg signed MD5SUMS file to verify if your download is correct: $ gpg --verify MD5SUMS $ md5sum -c MD5SUMS We had to remove the old binary packages for previous releases and snapshots due to licensing issues between gdbm and php. New binaries for the Debian GNU/Linux (sarge/oldstable) on x86 platforms can be found in the ix86-debian3.1 directory next to the sources. Please look at 1st.README and release-notes.txt for more information about this release. The changes since server 2.1 rc 1 are listed below for your convenience. UPGRADING.20-21 contains instructions for upgrading from Kolab server 2.0 to 2.1, with new details since 2.1rc1. Please report failed and successful upgrades to the mailing list. Regards, Thomas Arendsen Hein Changes since 2.1 rc 1: - apache-1.3.33-2.5.6_kolab2 kolab/issue1607 (need to replace gdbm for pfbcache, because of license clash gdbm vs php) - clamav-0.90.2-20070413_kolab New upstream version, fixes various security issues. - file-4.15-2.5.0_kolab2 Fix for security issue described in CVE-2007-1536: buffer overflow, remotely exploitable due to the usage of file in amavisd-new - fsl-1.7.0-20070303 New upstream version. kolab/issue1172 (Cyrus Imapd dies when logfile exceeds 2 GiB) - php-4.4.0-2.5.2_kolab2 kolab/issue1607 (need to replace gdbm for pfbcache, because of license clash gdbm vs php) - spamassassin-3.1.0-2.5.1_kolab Fix for security issue described in CVE-2007-0451: possible DoS due to incredibly long URIs found in the message content Disabled external DNS and URI blacklists, because some of these services require payment if used for many mailboxes. Ignore headers inserted on the receiving side for bayes filtering. - perl-kolab-5.8.7-20070420 Added debug option for verbose logging to stderr. - kolabd-2.1.0-20070420 Fix the path to the freebusy directory for non-OpenPKG installations. Fix usage of tar and modification of rc.conf during slave setup for non-OpenPKG installations. Don't pass notifications and quarantined mails through amavisd-new. Updated configuration templates for ClamAV 0.90 Updated openldap monitor configuration. Updated cyrus imapd configuration to use cyr_expire. kolab/issue954 (kolab server rejects mails that should be marked untrusted) kolab/issue1607 (need to replace gdbm for pfbcache, because of license clash gdbm vs php) kolab/issue1609 ("kolab --help" tries to execute *all* commands) kolab/issue1638 (kolabconf generates broken resmgr.conf) kolab/issue1680 (/kolab/bin/kolab fix) - kolab-horde-fbview-2.1.0-20070420 Updated version number, no other changes since 2.1rc1 - kolab-resource-handlers-2.1.0-20070420 Improved logging for opening pfbcache.db kolab/issue954 (kolab server rejects mails that should be marked untrusted) kolab/issue1607 (need to replace gdbm for pfbcache, because of license clash gdbm vs php) kolab/issue1659 (Freebusy assumes that all day events last exactly one day) - kolab-webadmin-2.1.0-20070420 Updated Dutch and German translations. kolab/issue1457 (updated French translation) kolab/issue1612 (modify user ignores account type) kolab/issue1614 (ldap_add() - Constraint violation on change user account type) kolab/issue1630 (Domain maintainer can see distribution lists from other domains) kolab/issue1652 (Import users from ldif and LDAP Constraint violation) kolab/issue1654 (New LDAP overlay prevents modification of distribution lists) kolab/issue1663 (It is possible to create domain maintainers without domains) kolab/issue1670 (Renaming a domain maintainer twice within the same form fails) -- thomas at intevation.de - http://intevation.de/~thomas/ - OpenPGP key: 0x5816791A Intevation GmbH, Osnabr?ck - Registereintrag: Amtsgericht Osnabr?ck, HR B 18998 Gesch?ftsf?hrer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 189 bytes Desc: not available Url : http://kolab.org/pipermail/kolab-announce/attachments/20070420/a5acfab7/attachment.bin From bh at intevation.de Tue May 8 17:56:06 2007 From: bh at intevation.de (Bernhard Herzog) Date: Tue, 8 May 2007 17:56:06 +0200 Subject: [Kolab-announce] Kolab KDE Client 2.1.7 released Message-ID: <200705081756.09873.bh@intevation.de> Kolab KDE Client 2.1.7 has been released. This release contains bug fixes and some new minor features. A tarball and release notes with a list of the changes can be found in the Kolab download area once the mirrors have been updated. Bernhard Herzog -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 189 bytes Desc: not available Url : http://kolab.org/pipermail/kolab-announce/attachments/20070508/dbc8a98d/attachment.bin From thomas at intevation.de Thu May 10 16:09:28 2007 From: thomas at intevation.de (Thomas Arendsen Hein) Date: Thu, 10 May 2007 16:09:28 +0200 Subject: [Kolab-announce] Kolab Server 2.1.0 Final Release Message-ID: <20070510140928.GA4789@intevation.de> Hi! I've just uploaded the final release of Kolab Server 2.1.0, more than one year after the first beta was published. Many thanks to all the people who helped with this! Documentation and OpenPKG source packages will be available in the directory server/release/kolab-server-2.1.0/ of the mirrors listed on http://kolab.org/mirrors.html soon: http://www.erfrakon.de/mirrors/ftp.kolab.org/server/release/kolab-server-2.1.0/ http://ftp.belnet.be/packages/kolab/server/release/kolab-server-2.1.0/ ftp://ftp.belnet.be/packages/kolab/server/release/kolab-server-2.1.0/ Use the gpg signed MD5SUMS file to verify your download: $ gpg --verify MD5SUMS $ md5sum -c MD5SUMS Binary packages for Debian GNU/Linux (sarge/oldstable) on x86 platforms can be found in the ix86-debian3.1 directory next to the sources. Please look at 1st.README for install and upgrade instructions and for a list of known problems and workarounds. The file release-notes.txt lists the changes in this release. UPGRADING.20-21 contains instructions for upgrading from Kolab server 2.0 to 2.1, with new details since 2.1rc2. Please report failed and successful upgrades to the mailing list. The three text files are attached for your convenience. Regards, Thomas Arendsen Hein -- thomas at intevation.de - http://intevation.de/~thomas/ - OpenPGP key: 0x5816791A Intevation GmbH, Osnabr?ck - Registereintrag: Amtsgericht Osnabr?ck, HR B 18998 Gesch?ftsf?hrer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner -------------- next part -------------- Kolab2 Server Release Notes =========================== (Version 20070510, Kolab Server 2.1.0) For upgrading and installation instructions, please refer to the 1st.README file in the package directory. Upgrading from Kolab 2.0 servers is documented in the file UPGRADING.20-21 Differences between Kolab 2.0 and 2.1: - Simple multi-domain support The Kolab server can now accept mail for multiple email domains. There is also a new class of maintainers which are only allowed to manage settings for a subset of the mail domains of the kolab server. - Hashed IMAP spool The default imapd configuration has been changed to enable the hashimapspool option, which allows the Cyrus IMAP server to run more efficiently especially when you have many mailboxes. - Improvements, bugfixes and upgraded software components The 2.1 release received many improvements and bugfixes for issues found in the 2.0 versions and during the long beta and rc phase. Additionally many software components have been upgraded to new upstream versions. Changes between 2.1-rc-2 and 2.1.0: - Documentation Documented workaround for libdb3 conflict in README.1st Added instructions for automatically upgrading the free/busy cache. - amavisd-2.3.3-2.5.0_kolab kolab/issue1447 (Virus Scanning: Inserted note when partially scanned ugly) - kolabd-2.1.0-20070510 kolab/issue974 (Localize the text for rewritten From: headers) kolab/issue1560 (postfix modifies message/rfc822 MIME parts) kolab/issue1608 (A patch for kolabd to include the horde LDAP schema) - kolab-resource-handlers-2.1.0-20070510 Generate a single To: header listing all recipients when forwarding encapsulated iCal messages. kolab/issue974 (Localize the text for rewritten From: headers) kolab/issue1422 (Dummy freebusy info) - kolab-webadmin-2.1.0-20070510 kolab/issue1616 (Use different cursor for