[BlueOnyx:16208] Re: Question 5107R Systemadmin - No Add New Site Button

2014-10-17 Thread Dirk Estenfeld
Michael, unfortunately not. I removed all capabilities in the GUI which left me with 102 DATA capLevels = "&adminUser&menuServerServerStats&manageSite&" Afterwards I added nearly all capabilities again and get 102 DATA capLevels = "&adminUser&menuServerServerStats&manageSite&siteDNS&serverSho

[BlueOnyx:16209] Re: SSL v3 POODLE vulnerability

2014-10-17 Thread Dogsbody
On 15/10/14 02:17, Michael Stauber wrote: > > So as is SSL v3.0 allows snooping via a man-in-the-middle attack. > > This is bad enough. They kind of confirm that SSL v3.0 is pretty much > dead and recommend to move to TLSv1.2 for secure connections. Think > HTTPS, SMTPS, POP3S, IMAPS and FTPS in o

[BlueOnyx:16210] syncEmailService run at startup

2014-10-17 Thread Simone Capra
Hi all! i have a problem with: /usr/sausalito/constructor/base/email/syncEmailService.pl this script is now run at boot time by cce (i think that before BlueOnyx-5208R-SL-6.5-20140824 was not run at boot) This is a problem since i have to wait fo mysql and then run sendmail after that... Is

[BlueOnyx:16211] Re: SSL v3 POODLE vulnerability

2014-10-17 Thread Matt James
Hi Michael, Thanks for the great instructions! We really appreciate how on top of this you are. I was able to shut off SSL3 for ProFTPd no problem, but my work to turn it off for Apache came up short. I'm running a 5107R and was unable to find the "SSLProtocol +ALL -SSLv2" reference in /usr

[BlueOnyx:16212] Re: SSL v3 POODLE vulnerability

2014-10-17 Thread Dirk Estenfeld
Hello, modify line 138 in file /etc/httpd/conf.d/ssl_perl.conf and restart apache for the VSites. And modify line 46 in file /etc/admserv/conf.d/ssl.conf for admserv. Restart admserv after change. Best regards, Dirk Black Point Arts Internet Solutions GmbH - Hanauer Landstrasse 423a - 60314

[BlueOnyx:16213] Re: SSL v3 POODLE vulnerability

2014-10-17 Thread Michael Stauber
Hi Dirk. > modify line 138 in file /etc/httpd/conf.d/ssl_perl.conf and restart apache > for the VSites. > And modify line 46 in file /etc/admserv/conf.d/ssl.conf for admserv. Restart > admserv after change. Correct. 5207R and 5209R write the SSL config into the siteX include files of Apache vi

[BlueOnyx:16214] Re: SSL v3 POODLE vulnerability

2014-10-17 Thread Michael Stauber
Hi Dan, > I still think we should disable SSL 3 but it does > help a lot. Yeah, it should be disabled. The tricky part is Dovecot. Need to build an all new version for that, so this will take time. -- With best regards Michael Stauber ___ Blueonyx m