ืฉื™ืคื•ืจ ื”ื’ื“ืจื•ืช ื”ืื‘ื˜ื—ื” ืฉืœ ื—ื™ื‘ื•ืจ SSL ื‘ืžื”ื“ื•ืจืช ื”ืงื•ื“ ื”ืคืชื•ื— ืฉืœ Zimbra Collaboration Suite

ื—ื•ื–ืง ื”ื”ืฆืคื ื” ื”ื•ื ืื—ื“ ื”ืžื“ื“ื™ื ื”ื—ืฉื•ื‘ื™ื ื‘ื™ื•ืชืจ ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืžืขืจื›ื•ืช ืžื™ื“ืข ืœืขืกืงื™ื, ืžื›ื™ื•ื•ืŸ ืฉื‘ื›ืœ ื™ื•ื ื”ื ืžืขื•ืจื‘ื™ื ื‘ื”ืขื‘ืจืช ื›ืžื•ืช ืขืฆื•ืžื” ืฉืœ ืžื™ื“ืข ืกื•ื“ื™. ืืžืฆืขื™ ืžืงื•ื‘ืœ ืœื”ืขืจื›ืช ืื™ื›ื•ืช ื—ื™ื‘ื•ืจ SSL ื”ื•ื ื‘ื“ื™ืงื” ืขืฆืžืื™ืช ืฉืœ Qualys SSL Labs. ืžื›ื™ื•ื•ืŸ ืฉืžื‘ื—ืŸ ื–ื” ื™ื›ื•ืœ ืœื”ื™ื•ืช ืžื•ืคืขืœ ืขืœ ื™ื“ื™ ื›ืœ ืื—ื“, ื—ืฉื•ื‘ ื‘ืžื™ื•ื—ื“ ืœืกืคืงื™ SaaS ืœืงื‘ืœ ืืช ื”ืฆื™ื•ืŸ ื”ื’ื‘ื•ื” ื‘ื™ื•ืชืจ ื”ืืคืฉืจื™ ื‘ืžื‘ื—ืŸ ื–ื”. ืœื ืจืง ืœืกืคืงื™ SaaS, ืืœื ื’ื ืœืืจื’ื•ื ื™ื ืจื’ื™ืœื™ื ืื›ืคืช ืžืื™ื›ื•ืช ื—ื™ื‘ื•ืจ ื”-SSL. ืขื‘ื•ืจื, ื”ื‘ื“ื™ืงื” ื”ื–ื• ื”ื™ื ื”ื–ื“ืžื ื•ืช ืžืฆื•ื™ื ืช ืœื–ื”ื•ืช ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืคื•ื˜ื ืฆื™ืืœื™ื•ืช ื•ืœืกื’ื•ืจ ืžืจืืฉ ืืช ื›ืœ ื”ืคืจืฆื•ืช ืขื‘ื•ืจ ืคื•ืฉืขื™ ื”ืกื™ื™ื‘ืจ.

ืฉื™ืคื•ืจ ื”ื’ื“ืจื•ืช ื”ืื‘ื˜ื—ื” ืฉืœ ื—ื™ื‘ื•ืจ SSL ื‘ืžื”ื“ื•ืจืช ื”ืงื•ื“ ื”ืคืชื•ื— ืฉืœ Zimbra Collaboration Suite
Zimbra OSE ืžืืคืฉืจ ืฉื ื™ ืกื•ื’ื™ื ืฉืœ ืชืขื•ื“ื•ืช SSL. ื”ืจืืฉื•ืŸ ื”ื•ื ืื™ืฉื•ืจ ื‘ื—ืชื™ืžื” ืขืฆืžื™ืช ืฉืžืชื•ื•ืกืฃ ืื•ื˜ื•ืžื˜ื™ืช ื‘ืžื”ืœืš ื”ื”ืชืงื ื”. ืื™ืฉื•ืจ ื–ื” ื”ื•ื ื—ื™ื ืžื™ ื•ืื™ืŸ ืœื• ื”ื’ื‘ืœืช ื–ืžืŸ, ืžื” ืฉื”ื•ืคืš ืื•ืชื• ืœืื™ื“ื™ืืœื™ ืขื‘ื•ืจ ื‘ื“ื™ืงืช Zimbra OSE ืื• ืฉื™ืžื•ืฉ ื‘ื• ืืš ื•ืจืง ื‘ืชื•ืš ืจืฉืช ืคื ื™ืžื™ืช. ืขื ื–ืืช, ื‘ืขืช ื›ื ื™ืกื” ืœืœืงื•ื— ื”ืื™ื ื˜ืจื ื˜, ื”ืžืฉืชืžืฉื™ื ื™ืจืื• ืื–ื”ืจื” ืžื”ื“ืคื“ืคืŸ ื›ื™ ืื™ืฉื•ืจ ื–ื” ืื™ื ื• ืžื”ื™ืžืŸ, ื•ื”ืฉืจืช ืฉืœืš ื‘ื”ื—ืœื˜ ื™ื™ื›ืฉืœ ื‘ื‘ื“ื™ืงื” ืžืžืขื‘ื“ื•ืช Qualys SSL.

ื”ืฉื ื™ ื”ื•ื ืชืขื•ื“ืช SSL ืžืกื—ืจื™ืช ื—ืชื•ืžื” ืขืœ ื™ื“ื™ ืจืฉื•ืช ืื™ืฉื•ืจื™ื. ืื™ืฉื•ืจื™ื ื›ืืœื” ืžืชืงื‘ืœื™ื ื‘ืงืœื•ืช ืขืœ ื™ื“ื™ ื“ืคื“ืคื ื™ื ื•ื”ื ืžืฉืžืฉื™ื ื‘ื“ืจืš ื›ืœืœ ืœืฉื™ืžื•ืฉ ืžืกื—ืจื™ ืฉืœ Zimbra OSE. ืžื™ื“ ืœืื—ืจ ื”ื”ืชืงื ื” ื”ื ื›ื•ื ื” ืฉืœ ื”ืชืขื•ื“ื” ื”ืžืกื—ืจื™ืช, Zimbra OSE 8.8.15 ืžืฆื™ื’ ืฆื™ื•ืŸ A ื‘ืžื‘ื—ืŸ ืฉืœ Qualys SSL Labs. ื–ื• ืชื•ืฆืื” ืžืฆื•ื™ื ืช, ืื‘ืœ ื”ืžื˜ืจื” ืฉืœื ื• ื”ื™ื ืœื”ื’ื™ืข ืœืชื•ืฆืื” A+.

ืฉื™ืคื•ืจ ื”ื’ื“ืจื•ืช ื”ืื‘ื˜ื—ื” ืฉืœ ื—ื™ื‘ื•ืจ SSL ื‘ืžื”ื“ื•ืจืช ื”ืงื•ื“ ื”ืคืชื•ื— ืฉืœ Zimbra Collaboration Suite

ืฉื™ืคื•ืจ ื”ื’ื“ืจื•ืช ื”ืื‘ื˜ื—ื” ืฉืœ ื—ื™ื‘ื•ืจ SSL ื‘ืžื”ื“ื•ืจืช ื”ืงื•ื“ ื”ืคืชื•ื— ืฉืœ Zimbra Collaboration Suite

ืขืœ ืžื ืช ืœื”ืฉื™ื’ ืืช ื”ืฆื™ื•ืŸ ื”ืžืงืกื™ืžืœื™ ื‘ืžื‘ื—ืŸ ืžืžืขื‘ื“ื•ืช Qualys SSL ื‘ืขืช ืฉื™ืžื•ืฉ ื‘-Zimbra Collaboration Suite-ืžื”ื“ื•ืจืช ืงื•ื“ ืคืชื•ื—, ืขืœื™ืš ืœื‘ืฆืข ืžืกืคืจ ืฉืœื‘ื™ื:

1. ื”ื’ื“ืœืช ื”ืคืจืžื˜ืจื™ื ืฉืœ ืคืจื•ื˜ื•ืงื•ืœ ื“ื™ืคื™-ื”ืœืžืŸ

ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ืœื›ืœ ืจื›ื™ื‘ื™ Zimbra OSE 8.8.15 ื”ืžืฉืชืžืฉื™ื ื‘-OpenSSL ื”ื’ื“ืจื•ืช ืคืจื•ื˜ื•ืงื•ืœ Diffie-Hellman ืžื•ื’ื“ืจื•ืช ืœ-2048 ืกื™ื‘ื™ื•ืช. ื‘ืื•ืคืŸ ืขืงืจื•ื ื™, ื–ื” ื“ื™ ื•ื”ื•ืชืจ ื›ื“ื™ ืœืงื‘ืœ ืฆื™ื•ืŸ A+ ื‘ืžื‘ื—ืŸ ืžืžืขื‘ื“ื•ืช Qualys SSL. ืขื ื–ืืช, ืื ืืชื” ืžืฉื“ืจื’ ืžื’ืจืกืื•ืช ื™ืฉื ื•ืช ื™ื•ืชืจ, ื™ื™ืชื›ืŸ ืฉื”ื”ื’ื“ืจื•ืช ื™ื”ื™ื• ื ืžื•ื›ื•ืช ื™ื•ืชืจ. ืœื›ืŸ, ืžื•ืžืœืฅ ืœืื—ืจ ื”ืฉืœืžืช ื”ืขื“ื›ื•ืŸ ืœื”ืคืขื™ืœ ืืช ื”ืคืงื•ื“ื” zmdhparam set -new 2048, ืฉืชื’ื“ื™ืœ ืืช ื”ืคืจืžื˜ืจื™ื ืฉืœ ืคืจื•ื˜ื•ืงื•ืœ ื“ื™ืคื™-ื”ืœืžืŸ ืœ-2048 ืกื™ื‘ื™ื•ืช ืžืงื•ื‘ืœื™ื, ื•ืื ืชืจืฆื”, ื‘ืืžืฆืขื•ืช ืื•ืชื” ืคืงื•ื“ื”, ืชื•ื›ืœ ืœื”ื’ื“ื™ืœ ืขืจืš ื”ืคืจืžื˜ืจื™ื ืœ-3072 ืื• 4096 ืกื™ื‘ื™ื•ืช, ืžื” ืฉืžืฆื“ ืื—ื“ ื™ื•ื‘ื™ืœ ืœื”ื’ื“ืœืช ื–ืžืŸ ื”ื™ืฆื™ืจื”, ืืš ืžืฆื“ ืฉื ื™ ื™ืฉืคื™ืข ืœื˜ื•ื‘ื” ืขืœ ืจืžืช ื”ืื‘ื˜ื—ื” ืฉืœ ืฉืจืช ื”ื“ื•ืืจ.

2. ื›ื•ืœืœ ืจืฉื™ืžื” ืžื•ืžืœืฆืช ืฉืœ ืฆืคื ื™ื ื‘ืฉื™ืžื•ืฉ

ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ืžื”ื“ื•ืจืช ืงื•ื“ ืคืชื•ื— ืฉืœ Zimbra Collabortaion Suite ืชื•ืžื›ืช ื‘ืžื’ื•ื•ืŸ ืจื—ื‘ ืฉืœ ืฆืคื ื™ื ื—ื–ืงื™ื ื•ื—ืœืฉื™ื, ื”ืžืฆืคื™ื ื™ื ื ืชื•ื ื™ื ื”ืขื•ื‘ืจื™ื ื“ืจืš ื—ื™ื‘ื•ืจ ืžืื•ื‘ื˜ื—. ืขื ื–ืืช, ื”ืฉื™ืžื•ืฉ ื‘ืฆืคื ื™ื ื—ืœืฉื™ื ื”ื•ื ื—ื™ืกืจื•ืŸ ืจืฆื™ื ื™ ื‘ืขืช ื‘ื“ื™ืงืช ื”ืื‘ื˜ื—ื” ืฉืœ ื—ื™ื‘ื•ืจ SSL. ื›ื“ื™ ืœื”ื™ืžื ืข ืžื›ืš, ืขืœื™ืš ืœื”ื’ื“ื™ืจ ืืช ืจืฉื™ืžืช ื”ืฆืคื ื™ื ื‘ืฉื™ืžื•ืฉ.

ื›ื“ื™ ืœืขืฉื•ืช ื–ืืช, ื”ืฉืชืžืฉ ื‘ืคืงื•ื“ื” zmprov mcf zimbraReverseProxySSLCiphers 'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA-AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128:AES256:HIGH:!aNULL:!eNULL:!EXPORT:!DES:!MD5:!PSK:!RC4'

ืคืงื•ื“ื” ื–ื• ื›ื•ืœืœืช ืžื™ื“ ืงื‘ื•ืฆื” ืฉืœ ืฆืคื ื™ื ืžื•ืžืœืฆื™ื ื•ื‘ื–ื›ื•ืชื”, ื”ืคืงื•ื“ื” ื™ื›ื•ืœื” ืœื›ืœื•ืœ ืžื™ื“ ืฆืคื ื™ื ืžื”ื™ืžื ื™ื ื‘ืจืฉื™ืžื” ื•ืœื ืœื›ืœื•ืœ ื›ืืœื” ืฉืื™ื ื ืืžื™ื ื™ื. ื›ืขืช ื›ืœ ืžื” ืฉื ื•ืชืจ ื”ื•ื ืœื”ืคืขื™ืœ ืžื—ื“ืฉ ืืช ืฆืžืชื™ ื”-proxy ื”ื”ืคื•ืš ื‘ืืžืฆืขื•ืช ืคืงื•ื“ืช zmproxyctl restart. ืœืื—ืจ ืืชื—ื•ืœ ืžื—ื“ืฉ, ื”ืฉื™ื ื•ื™ื™ื ืฉื‘ื•ืฆืขื• ื™ื™ื›ื ืกื• ืœืชื•ืงืฃ.

ืื ืจืฉื™ืžื” ื–ื• ืื™ื ื” ืžืชืื™ืžื” ืœืš ืžืกื™ื‘ื” ื–ื• ืื• ืื—ืจืช, ืชื•ื›ืœ ืœื”ืกื™ืจ ืžืžื ื” ืžืกืคืจ ืฆืคื ื™ื ื—ืœืฉื™ื ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื” zmprov mcf +zimbraSSLExcludeCipherSuites. ืื–, ืœืžืฉืœ, ื”ืคืงื•ื“ื” zmprov mcf +zimbraSSLExcludeCipherSuites TLS_RSA_WITH_RC4_128_MD5 +zimbraSSLExcludeCipherSuites TLS_RSA_WITH_RC4_128_SHA +zimbraSSLExcludeCipherSuites SSL_RSA_WITH_RC4_128_MD5 +zimbraSSLExcludeCipherSuites SSL_RSA_WITH_RC4_128_SHA +zimbraSSLExcludeCipherSuites TLS_ECDHE_RSA_WITH_RC4_128_SHA, ืžื” ืฉื™ื‘ื˜ืœ ืœื—ืœื•ื˜ื™ืŸ ืืช ื”ืฉื™ืžื•ืฉ ื‘ืฆืคื ื™ RC4. ื ื™ืชืŸ ืœืขืฉื•ืช ืืช ืื•ืชื• ื”ื“ื‘ืจ ืขื ืฆืคื ื™ AES ื•-3DES.

3. ืืคืฉืจ HSTS

ื’ื ืžื ื’ื ื•ื ื™ื ืžื•ืคืขืœื™ื ืœื›ืคื•ืช ื”ืฆืคื ืช ื—ื™ื‘ื•ืจ ื•ืฉื—ื–ื•ืจ ื”ืคืขืœื” ืฉืœ TLS ื ื“ืจืฉื™ื ื›ื“ื™ ืœื”ืฉื™ื’ ืฆื™ื•ืŸ ืžื•ืฉืœื ื‘ืžื‘ื—ืŸ Qualys SSL Labs. ื›ื“ื™ ืœื”ืคืขื™ืœ ืื•ืชื ืขืœื™ืš ืœื”ื–ื™ืŸ ืืช ื”ืคืงื•ื“ื” zmprov mcf +zimbraResponseHeader "Strict-Transport-Security: max-age=31536000". ืคืงื•ื“ื” ื–ื• ืชื•ืกื™ืฃ ืืช ื”ื›ื•ืชืจืช ื”ื“ืจื•ืฉื” ืœืชืฆื•ืจื”, ื•ื›ื“ื™ ืฉื”ื”ื’ื“ืจื•ืช ื”ื—ื“ืฉื•ืช ื™ื™ื›ื ืกื• ืœืชื•ืงืฃ ืชืฆื˜ืจืš ืœื”ืคืขื™ืœ ืžื—ื“ืฉ ืืช Zimbra OSE ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื” ื”ืคืขืœื” ืžื—ื“ืฉ ืฉืœ zmcontrol.

ื›ื‘ืจ ื‘ืฉืœื‘ ื–ื”, ื”ื‘ื“ื™ืงื” ืฉืœ Qualys SSL Labs ืชืฆื™ื’ ื“ื™ืจื•ื’ A+, ืืš ืื ืชืจืฆื• ืœืฉืคืจ ืขื•ื“ ื™ื•ืชืจ ืืช ื”ืื‘ื˜ื—ื” ืฉืœ ื”ืฉืจืช ืฉืœื›ื, ื™ืฉื ื ืžืกืคืจ ืืžืฆืขื™ื ื ื•ืกืคื™ื ืฉืชื•ื›ืœื• ืœื ืงื•ื˜.

ืฉื™ืคื•ืจ ื”ื’ื“ืจื•ืช ื”ืื‘ื˜ื—ื” ืฉืœ ื—ื™ื‘ื•ืจ SSL ื‘ืžื”ื“ื•ืจืช ื”ืงื•ื“ ื”ืคืชื•ื— ืฉืœ Zimbra Collaboration Suite

ืœื“ื•ื’ืžื”, ืืชื” ื™ื›ื•ืœ ืœืืคืฉืจ ื”ืฆืคื ื” ื›ืคื•ื™ื” ืฉืœ ื—ื™ื‘ื•ืจื™ื ื‘ื™ืŸ ืชื”ืœื™ื›ื™ื, ื•ืชื•ื›ืœ ื’ื ืœื”ืคืขื™ืœ ื”ืฆืคื ื” ื›ืคื•ื™ื” ื‘ืขืช ื—ื™ื‘ื•ืจ ืœืฉื™ืจื•ืชื™ Zimbra OSE. ื›ื“ื™ ืœื‘ื“ื•ืง ื—ื™ื‘ื•ืจื™ื ื‘ื™ืŸ ืชื”ืœื™ื›ื™ื, ื”ื–ืŸ ืืช ื”ืคืงื•ื“ื•ืช ื”ื‘ืื•ืช:

zmlocalconfig -e ldap_starttls_supported=1
zmlocalconfig -e zimbra_require_interprocess_security=1
zmlocalconfig -e ldap_starttls_required=true

ื›ื“ื™ ืœืืคืฉืจ ื”ืฆืคื ื” ื›ืคื•ื™ื” ืขืœื™ืš ืœื”ื–ื™ืŸ:

zmprov gs `zmhostname` zimbraReverseProxyMailMode
zmprov ms `zmhostname` zimbraReverseProxyMailMode https

zmprov gs `zmhostname` zimbraMailMode
zmprov ms `zmhostname` zimbraMailMode https

zmprov gs `zmhostname` zimbraReverseProxySSLToUpstreamEnabled
zmprov ms `zmhostname` zimbraReverseProxySSLToUpstreamEnabled TRUE

ื”ื•ื“ื•ืช ืœืคืงื•ื“ื•ืช ืืœื•, ื›ืœ ื”ื—ื™ื‘ื•ืจื™ื ืœืฉืจืชื™ ืคืจื•ืงืกื™ ื•ืœืฉืจืชื™ ื“ื•ืืจ ื™ื•ืฆืคื ื•, ื•ื›ืœ ื”ื—ื™ื‘ื•ืจื™ื ื”ืœืœื• ื™ืขื‘ืจื• ืคืจื•ืงืกื™.

ืฉื™ืคื•ืจ ื”ื’ื“ืจื•ืช ื”ืื‘ื˜ื—ื” ืฉืœ ื—ื™ื‘ื•ืจ SSL ื‘ืžื”ื“ื•ืจืช ื”ืงื•ื“ ื”ืคืชื•ื— ืฉืœ Zimbra Collaboration Suite

ื›ืš, ื‘ืขืงื‘ื•ืช ื”ื”ืžืœืฆื•ืช ืฉืœื ื•, ืชื•ื›ืœื• ืœื ืจืง ืœื”ืฉื™ื’ ืืช ื”ืฆื™ื•ืŸ ื”ื’ื‘ื•ื” ื‘ื™ื•ืชืจ ื‘ืžื‘ื—ืŸ ืื‘ื˜ื—ืช ื—ื™ื‘ื•ืจื™ SSL, ืืœื ื’ื ืœื”ื’ื‘ื™ืจ ืžืฉืžืขื•ืชื™ืช ืืช ื”ืื‘ื˜ื—ื” ืฉืœ ื›ืœ ืชืฉืชื™ืช ื”-Zimbra OSE.

ืœื›ืœ ื”ืฉืืœื•ืช ื”ืงืฉื•ืจื•ืช ืœ-Zextras Suite, ื ื™ืชืŸ ืœื™ืฆื•ืจ ืงืฉืจ ืขื ื ืฆื™ื’ืช Zextras Ekaterina Triandafilidi ื‘ื“ื•ืืจ ืืœืงื˜ืจื•ื ื™ [ืžื•ื’ืŸ ื‘ื“ื•ื"ืœ]

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”