Page 7 of 7

Re: 8.8.12 Patch 3 breaks inline signatures and creates multiple attachments

Posted: Thu Jun 27, 2019 2:00 pm
by jered
andrey.ivanov wrote:An easier workaround from Zimbra support :

Code: Select all

As a workaround please do the following on all mailbox servers
zmlocalconfig -e zimbra_use_owasp_html_sanitizer=FALSE
zmmailboxdctl restart

It did help me. Unfortunately it means that their new owasp sanitizing framework is disabled (https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.12/P3). But it fixes both attachments and printing problems,


THANK YOU!!!!

This is the simplest and best solution -- the above rebuilding zgz files works for the attachment hell, but doesn't fix the unreadable HTML mail. I wish Zimbra were more responsive as an organization, and told us this two weeks ago.

Re: 8.8.12 Patch 3 breaks inline signatures and creates multiple attachments

Posted: Thu Jun 27, 2019 6:10 pm
by rotorboy
Thanks for the post with the working solution!

Re: 8.8.12 Patch 3 breaks inline signatures and creates multiple attachments

Posted: Mon Jul 01, 2019 9:00 am
by ggoidin
Hello, is there any date from Zimbra for a fix update ?

Re: 8.8.12 Patch 3 breaks inline signatures and creates multiple attachments

Posted: Fri Jul 05, 2019 7:31 am
by r13e
Got an anwer about my concerns disabling the owasp sanitizer:

No, there aren't any security implications after disabling the owasp sanitizer. When you disable it, the defanger is active and protects the system. Owasp sanitizer introduces performance enhancement over defanger but there are no such known security issues which are introduced after disabling the owasp sanitizer.

Re: 8.8.12 Patch 3 breaks inline signatures and creates multiple attachments

Posted: Thu Oct 24, 2019 8:05 am
by G2M2
Hello,

I've installed Patch 6 on Zimbra FOSS 8.8.12 and I still have the issue.
I know there is a workaround :

Code: Select all

zmlocalconfig -e zimbra_use_owasp_html_sanitizer=false


But is there another solution yet?

Regards,
Geoffroy

Re: 8.8.12 Patch 3 breaks inline signatures and creates multiple attachments

Posted: Thu Oct 24, 2019 1:14 pm
by Pierre C.
G2M2 wrote:Hello,

I've installed Patch 6 on Zimbra FOSS 8.8.12 and I still have the issue.
I know there is a workaround :

Code: Select all

zmlocalconfig -e zimbra_use_owasp_html_sanitizer=false


But is there another solution yet?

Regards,
Geoffroy


Hello Geoffroy, Hello all,

I'm not sure for the 8.8.12 Patch 6 version, but for my part (8.8. 15 Patch 3) I recently had an exchange with Zimbra support.

They explained to me that this only works for new emails.

For historical emails, there is no patch.

Re: 8.8.12 Patch 3 breaks inline signatures and creates multiple attachments

Posted: Tue Oct 29, 2019 1:10 am
by jered
I just upgraded to 8.8.15p3 [Zimbra 8.8.15_GA_3869 (build 20190917004220)] and seem to have a regression where images and HTML layouts no longer render correctly again. Is this a known problem?

Re: 8.8.12 Patch 3 breaks inline signatures and creates multiple attachments

Posted: Tue Oct 29, 2019 1:28 am
by jered
jered wrote:I just upgraded to 8.8.15p3 [Zimbra 8.8.15_GA_3869 (build 20190917004220)] and seem to have a regression where images and HTML layouts no longer render correctly again. Is this a known problem?


Nevermind -- this is Firefox's new "Enhanced Tracking Protection" blocking all social media site images (Facebook, LinkedIn, etc.)

Re: 8.8.12 Patch 3 breaks inline signatures and creates multiple attachments

Posted: Tue Oct 29, 2019 2:27 am
by L. Mark Stone
jered wrote:I just upgraded to 8.8.15p3 [Zimbra 8.8.15_GA_3869 (build 20190917004220)] and seem to have a regression where images and HTML layouts no longer render correctly again. Is this a known problem?


Try running apt-get update && apt-get dist-upgrade.

You may be offered some Zimbra updates.

Hope that helps,
Mark