GFI Software

Welcome to the GFI Software community forum! For support please open a ticket from https://support.gfi.com.

Home » GFI User Forums » Kerio Connect » Kerio Connect 9.3.0 released (Kerio Connect 9.3.0 has been released on 23-Sep-2020)
Re: Kerio Connect 9.3.0 released [message #148837 is a reply to message #148716] Mon, 12 October 2020 18:42 Go to previous messageGo to next message
McIrish is currently offline  McIrish
Messages: 254
Registered: October 2011
Wow! I'm glad I have waited to install the new version. Life is stressful enough without crashes of the mail server. I'd love to hear some success stories for Windows Server 2012R2.
Re: Kerio Connect 9.3.0 released [message #148843 is a reply to message #148837] Tue, 13 October 2020 11:36 Go to previous messageGo to next message
ian.bugeja is currently offline  ian.bugeja
Messages: 666
Registered: March 2017
Location: Malta
We have identified an issue when decoding DKIM signatures which can cause a crash.

We are working on a fix, will update once a fix is available.


Ian Bugeja
GFI Software
icon8.gif  Re: Kerio Connect 9.3.0 released [message #148847 is a reply to message #148843] Thu, 15 October 2020 11:43 Go to previous messageGo to next message
Th.Bein is currently offline  Th.Bein
Messages: 1
Registered: April 2019
Our Kerio-Connect Server crashes from Time to time after update to 9.3.0. The reasons for crashing are well known, because here are a lot of detailed messages.

We are very unhappy with updates last time and the question is: Why GFI-Quality is so poor ?

My company gets into big problems and we lose money when the mail server is down...

Please Note we pay for your Service, Kerio-Connect is not freeware, so we must have safety for our mailserver.
So we need urgently a fix for the crashes!

But recently we as administrators have been really afraid of doing an update because something is always going wrong. That is totally unacceptable!
Please improve this situation as soon as possible if you do not want to lose your customers!
Re: Kerio Connect 9.3.0 released [message #148855 is a reply to message #148843] Fri, 16 October 2020 12:19 Go to previous messageGo to next message
han_swurst is currently offline  han_swurst
Messages: 11
Registered: February 2019
Location: Germany
@ian.bugeja
any news about the certificate issue?
Re: Kerio Connect 9.3.0 released [message #148856 is a reply to message #148855] Fri, 16 October 2020 14:09 Go to previous messageGo to next message
ian.bugeja is currently offline  ian.bugeja
Messages: 666
Registered: March 2017
Location: Malta
The certificate issue is basically due to the fact that the certificate is too weak for the latest guidelines from OpenSSL. We are planning to revert to the previous configuration allowing all certificates (in a future patch), however, I would suggest ensuring you have updated certificates that are strong and meet the latest security guidelines.


Quoting OpenSSL website:
"The security level corresponds to a minimum of 80 bits of security. Any parameters offering below 80 bits of security are excluded. As a result RSA, DSA and DH keys shorter than 1024 bits and ECC keys shorter than 160 bits are prohibited. All export cipher suites are prohibited since they all offer less than 80 bits of security. SSL version 2 is prohibited. Any cipher suite using MD5 for the MAC is also prohibited."


Ian Bugeja
GFI Software
Re: Kerio Connect 9.3.0 released [message #148865 is a reply to message #148856] Fri, 16 October 2020 17:47 Go to previous messageGo to next message
McIrish is currently offline  McIrish
Messages: 254
Registered: October 2011
Ian, if my RSA is 2048 bits, would it then be safe to install this new version? I'm just looking for a little direction before I upgrade.
Re: Kerio Connect 9.3.0 released [message #148866 is a reply to message #148865] Fri, 16 October 2020 18:32 Go to previous messageGo to next message
tiberiusQ is currently offline  tiberiusQ
Messages: 9
Registered: April 2019
Any ideas when you will release 9.3.0 patch 1 !!?
Re: Kerio Connect 9.3.0 released [message #148870 is a reply to message #148843] Sat, 17 October 2020 10:55 Go to previous messageGo to next message
a.barabanov is currently offline  a.barabanov
Messages: 1
Registered: October 2020
GFI
so what's up with the post-crash patch? it's horror! my company works 24/7 with mail - it is a global problem for us that our server takes a reboot every 15-20 minutes
icon13.gif  Re: Kerio Connect 9.3.0 released [message #148871 is a reply to message #148725] Mon, 19 October 2020 07:43 Go to previous messageGo to next message
pjandl is currently offline  pjandl
Messages: 1
Registered: October 2020
Version 9.3.0 has minimal 3 errors:
1) The service stops (specifically on CentOS8 and CentOS7) it runs for a maximum of 70 minutes (on CentOS7 exactly always 70 minutes.) BUT only in real operation, if the server is disconnected from the Internet it does not crash
2) The antivirus update is not downloaded unless the ValidateUpdateServer parameter in mailserver.cfg changes to 0. Don't have money for a certificate on the server with the update? This needs to be done on version 9.2.12 patch 1 (5027), so I assume there is a problem on the server side.
3) Version 9.3.0 marks a valid letsencrypt certificate as revoked. In last version 9.2.12 patch 1 (5027) is certifikate valid.
Re: Kerio Connect 9.3.0 released [message #148872 is a reply to message #148865] Mon, 19 October 2020 09:47 Go to previous messageGo to next message
han_swurst is currently offline  han_swurst
Messages: 11
Registered: February 2019
Location: Germany
@ian.bugeja
So, LetsEncrypt Certificates should be suitable as it has 2048Bit RSA key. But user <_at_>centros wrote on page 2 that his LetsEncrypt certificate does not work.
Has anyone running kerio connect 9.3 with LetsEncrypt certificates?
Re: Kerio Connect 9.3.0 released [message #148879 is a reply to message #148872] Tue, 20 October 2020 07:56 Go to previous messageGo to next message
freakinvibe is currently offline  freakinvibe
Messages: 588
Registered: April 2004
Yes, I have 3 KC servers on 9.3 and they are running with Letsencrypt certs without problem (on Windows Server 2019).

Dexion Services AG - IT Support Services in Basel, Switzerland
https://dexionag.ch
Re: Kerio Connect 9.3.0 released [message #148882 is a reply to message #148872] Tue, 20 October 2020 10:18 Go to previous messageGo to next message
nibs is currently offline  nibs
Messages: 86
Registered: November 2007

I'm running my server using a ZeroSSL 2048-bit RSA certificate with no problems
Re: Kerio Connect 9.3.0 released [message #148885 is a reply to message #148882] Tue, 20 October 2020 15:50 Go to previous messageGo to next message
centros is currently offline  centros
Messages: 14
Registered: April 2018
Maybe the SSL-certificate issue only effects Linux distros or Centos in particular.

As I wrote before, we tried a freshly generated GeoTrust TLS DV RSA Mixed SHA256 2020 CA-1 with a size of 2.048 (version 3)
We also tried LetsEncrypt with a size of 4.096

Quoting Ian quoting OpenSSL website:
"The security level corresponds to a minimum of 80 bits of security. Any parameters offering below 80 bits of security are excluded. As a result RSA, DSA and DH keys shorter than 1024 bits and ECC keys shorter than 160 bits are prohibited. All export cipher suites are prohibited since they all offer less than 80 bits of security. SSL version 2 is prohibited. Any cipher suite using MD5 for the MAC is also prohibited."

I can't see where our certificates don't match these requirements.
This is not a weak-certificate-issue...
Re: Kerio Connect 9.3.0 released [message #148886 is a reply to message #148716] Tue, 20 October 2020 15:56 Go to previous messageGo to next message
ian.bugeja is currently offline  ian.bugeja
Messages: 666
Registered: March 2017
Location: Malta
Hi all

Regarding the crash (due to DKIM signatures) we have a hotfix. An automated update is expected soon as well in the coming days.

Steps for installation

1) Download the respective zip archive relative to your system from https://drive.google.com/drive/folders/1IABNr2Jd-KmiWjfC9kuD QSB3zkvtAjJn?usp=sharing
2) Take a backup copy of the mailserver binary
3) Stop the Kerio Connect service
4) Extract and Replace the mailserver binary from the one downloaded in 1.
5) Start the Kerio Connect service

NOTE this patch is only to be installed on 9.3.0


Ian Bugeja
GFI Software
Re: Kerio Connect 9.3.0 released [message #148887 is a reply to message #148885] Tue, 20 October 2020 16:22 Go to previous messageGo to previous message
weidl
Messages: 28
Registered: December 2016
same ssl issue here!
We have 9.3.0 on CentOS 7.8 with Thawte cert.
The cert appears as rejected in Kerio Connect, but each browser and external test site says its ok.
Previous Topic: Apple Mail & Server Rules/Filter Integration
Next Topic: Install on Windows Server (2019) core possible?
Goto Forum:
  


Current Time: Mon Mar 27 03:49:36 CEST 2023

Total time taken to generate the page: 0.06226 seconds