amuck-landowner

Falling off the Grid

happel

New Member
Zpanel has a bad track record when it comes to security. I even recall one of the developers stating security wasn't relevant or something like that.


I moved away from Google services a few years back.


- owncloud for caldav/carddav


- postfix/dovecot/opendkim/dspam for mail (plain mysql for managing)


only I haven't found a satisfactory alternative for is dropbox..
 
Last edited by a moderator:

wdq

Quade
I've spoken to two of my customers how have tried zimbra and both hate it for various reasons. One is actually switching back to MS Exchange and the other would change to something else if there was money to do it.


Both customers migrated from already existing solutions to zimbra and they have no knowledge with Linux and by the looks of it, neither did the consultants how did the migration.

I spent a week with Zimbra and thought it was alright, but the web interface kind of sucked so I didn't stick with it. 

Has anyone use this? It comes with a panel just for the mail accounts.

http://www.iredmail.org/
I tried installing iRedMail at one point. RoundCube is really nice, but the free administration tools are very limited. The paid version might be a little more worthwhile. 
 

shawn_ky

Member
Zpanel has a bad track record when it comes to security. I even recall one of the developers stating security wasn't relevant or something like that.
It was one of the volunteer tech support guys (going through some bad things in life) that responded to a security analyst (who in the support techs defense, was extremely rude and belittling).  All issues were addressed immediately, tech stripped of his role, etc, etc. made it over to reddit even, so was pretty serious.

Needless to say, a lot of improvements and enhancements went into 10.1.0. Don't want to use it? Go ahead and let it setup the mail servers and remove what you do not want. Or use it personally. I like it. Working on a module now to extend someone else's module for webmail. I like to have options.  Using the default, you have RoundCube. With the module it adds,  AtMail, HastyMail2, AfterLogic mail, Squirrel Mail, and Iloha Mail.
 

perennate

New Member
Verified Provider
I run a personal mail server, use it for all of my domains. Running Postfix, with Dovecot for IMAPS. Simple install with system users (since all the mail accounts are trusted, have shell access anyway), also runs with DKIM (opendkim), basic antispam (amavisd-new/spamassassin -- although I have it just marking ***SPAM*** instead of blocking spam since it started blocking legitimate mail), backup mail server (postfix also, not really needed though since any mail senders will retry if first connect fails). Oh and mailman for some mailing lists.

Don't use a panel, a script to make install easier would be nice though.

Used to have some problems delivering mail (over relay server, since mail server is running on residential connection), but now it's fine. Actually only ever had problems with Hotmail, which no one ought to use anyway.
 
Last edited by a moderator:

HalfEatenPie

The Irrational One
Retired Staff
See...  My trust with ZPanel left after the founder/owner stated that he wasn't interested in security (and he expressed that by stating (I don't recall the exact words) "What do you expect from a free software that we donate our time to?").  Now I read over everything the security analyst you're speaking of wrote and from my understanding initially when he asked diplomatically his concerns were basically brushed off as in "I know better and you're wrong" and then immediately "It's a free software, what do you expect".  When he pursued it more aggressively that's when the development team (from my perspective) took his concerns more seriously (now the hacking just happened when another individual saw the opportunity).  

Maybe they fixed that initial problem, but I still can't trust ZPanel at all.  It's not the software but the people I have an issue with (and kind of why I don't have any interests to recommend the software).  No offense to you @shawn_ky, just wanted to share my opinions of ZPanel.  I do hope they don't have this self-entitled thought of themselves.  I mean it's as bad as curtisg showing his code and stating "it's just a small piece anyways, what do you care?  It's free work anyways!" when criticism about it's security is made.  

Of course, I am also a guy who writes pretty crappy code (can't write secure code to save my life) and should not be allowed near a compiler, so take what I say with a grain of salt.  

Edit: bringing this back to the topic of discussion, ownCloud has always been a pain in the ass for me to handle at times.  I mean sometimes it works and sometimes it just fights with me every step of the way.  It's like PMSing every other day.  Entire reason why I ended up sticking with dropbox.  
 
Last edited by a moderator:

jarland

The ocean is digital
Maybe do a little reading about lavabit.com. Some recent press in favor of their security, trusted by none other than the guy currently evading the NSA. From what I gather, made by a couple guys in Dallas who wanted true privacy and security.
 

wdq

Quade
Edit: bringing this back to the topic of discussion, ownCloud has always been a pain in the ass for me to handle at times.  I mean sometimes it works and sometimes it just fights with me every step of the way.  It's like PMSing every other day.  Entire reason why I ended up sticking with dropbox.  

I have also never quite gotten ownCloud to work properly. Recently I have been using BitTorrent Sync with the combination of SFTP for my file syncing needs. It's not really an all in one solution, and BitTorrent Sync still has some issues, but it seems to work more reliably than ownCloud for me.
 
Last edited by a moderator:

perennate

New Member
Verified Provider
I have also never quite gotten ownCloud to work properly. Recently I have been using BitTorrent Sync with the combination of SFTP for my file syncing needs. It's not really an all in one solution, and BitTorrent Sync still has some issues, but it seems to work more reliably than ownCloud for me.
What about NFS?
 

drmike

100% Tier-1 Gogent
Maybe do a little reading about lavabit.com. Some recent press in favor of their security, trusted by none other than the guy currently evading the NSA. From what I gather, made by a couple guys in Dallas who wanted true privacy and security.
Lavabit has long tempted me.  They sorely need to update their site and raise the packages some:

All of the Lavabit servers use CentOS 4.8. The application servers are Dell PowerEdge 1650s with dual 1.4 GHz Pentium III processors, 4 GB of RAM and 36 GB SCSI hard drives. The database servers have dual Opteron 246 processors with 8 GB of memory and six 146 GB SCSI drives in a RAID 5 configuration. The storage servers have dual Opteron 242 processors, 2 GB of RAM, a 36 GB SATA boot drive, and 12 250 GB SATA drives in a RAID 5 configuration. The load balancer is an Alteon AD4. For our network, we use unmanaged Linksys gigabit switches.
 

KuJoe

Well-Known Member
Verified Provider
Also throwing this out there in the event you have your own hardware to use and want something free: ClearOS

I install this on every one of my ESXi hosts as a simple virtual gateway but it can do a lot more if you want it to. I'd still go with Synology if you have the money for the hardware + drives but if you want to go the cheapest route, ClearOS will run on any old PC you have laying around or you can even virtualize it.
 

HalfEatenPie

The Irrational One
Retired Staff
Yep.  Our house's internal network was managed by ClearOS.  While it did work I wouldn't say I 100% enjoyed the experience.  
 
Top
amuck-landowner