Blog Entry

aevans's picture
blog
Reads:

4107

Score:
5
5
1
 
Comments:

11

GroupWise Security Vulnerability

Author Info

1 June 2007 - 11:13am
Submitted by: aevans

Tags

Yesterday we announced that we had fixed a GroupWise security vulnerability. I am not posting to discuss the details of the vulnerability but I want to, again, give you pointers on how to update your system. First, the TID - here.

Next, the files - they are all linked from the TID but for completeness 6.5 and 7.

Lastly, how to update - well I already blogged on this so I am just going to link you there and then add a couple of fine points specific to this update.

A couple of differences on this one are that the POA's all need to be updated before you can install the new client or new GWIA and WebAccess. So, from this point forwards, the 7.02 Hot Patch client can no longer connect to an older POA. This is kind of a stake in the sand as, after this, the rule will reapply, you're just not going to be able to connect to a POA older than May 24 2007 with a client dated May 24 2007 or later.





User Comments

An old CPK dude's picture

S0 when will this update be

Submitted by An old CPK dude (not verified) on 1 June 2007 - 12:01pm.

S0 when will this update be available as a CPK????

Imagine we could then do 400 POS in one night and rest safe and sure all weekend long!!!

Eric's picture

The "Known issues" section

Submitted by Eric (not verified) on 4 June 2007 - 6:58am.

The "Known issues" section of TID3382383 needs updating asap.. There is a problem with right-clicking and printing attachments that causes Groupwise to crash now. There is also a problem with SETUPIP/auto-update rollouts, causing botched client installs.

Nick's picture

I cant find the hot path for

Submitted by Nick (not verified) on 5 June 2007 - 5:32am.

I cant find the hot path for linux servers (agents), is it avaliable?

Alex Evans's picture

Yes, it's there. Follow the

Submitted by Alex Evans (not verified) on 6 June 2007 - 8:29am.

Yes, it's there. Follow the link up in my blog and look for the one named Full Linux.

Alex Evans's picture

I forwarded this on to the

Submitted by Alex Evans (not verified) on 6 June 2007 - 8:31am.

I forwarded this on to the GroupWise team - though without more detail on the setupip issue we don't know what to fix. I am assuming you are installing the multilingual client and attempting to use the setup.cfg?

Alex Evans's picture

Martin, Martin,

Submitted by Alex Evans (not verified) on 6 June 2007 - 8:33am.

Martin, Martin, Martin......If I didn't have to write all the documentation it would already be out there. I am actually contemplating ripping out all the linux and windows stuff from the SPK for now and releasing it as a NetWare SPK, then follow up later with the other 2. I am also thinking I may do a linux CPK instead of an SPK so people don't have to mess with the SPK themselves. Now get back to your golf :)

Eric's picture

We're using the US client,

Submitted by Eric (not verified) on 6 June 2007 - 11:11am.

We're using the US client, not multilingual. Rather than duplicate the description of what others have experienced, take a look at Tom Hafemann's threads from 6/1 and 6/5 in novell.support.groupwise.7x.clients and novell.support.groupwise.7x.install-setup-admin.

Alex Evans's picture

Thing is I tested it myself

Submitted by Alex Evans (not verified) on 6 June 2007 - 11:48am.

Thing is I tested it myself for my own customer and it works. You need to make sure you have enough rights on the webserver for all the language specific stuff to be downloaded - to do this enter in the URL you embedded in setupip in a browser, if you get an error then you don't have sufficient rights.

Berndt Waltje's picture

We have 7 domains, each with

Submitted by Berndt Waltje (not verified) on 7 June 2007 - 4:05am.

We have 7 domains, each with a postoffice, connected by a WAN. Additionally 1 GWIA and 1 WA. Do I get it right that I have to update all of the POAs before I may update the GWIA + WA ?

Alex Evans's picture

Yes, you are mostly correct.

Submitted by Alex Evans (not verified) on 7 June 2007 - 6:04am.

Yes, you are mostly correct. The POAs need to be updated before a client of any kind can get updated. That does mean that if you are not using POP or IMAP on the GWIA then you are free to update that at any time.

Marvin Scott's picture

When we upgraded to GW 7.01

Submitted by Marvin Scott (not verified) on 28 June 2007 - 10:33am.

When we upgraded to GW 7.01 and now with this hot patch, it is not possible to deliver the client to workstations where the user (local user group membership) is locked down, using ZENWorks to deliver the client. We have ZEN 7.01 for desktops and the best solution I see available is to install the groupwise.msi dependant on the isscript1050.msi. This doesn't work using force run and so we have been delivering an icon on the desktop that the user needs to invoke. Isn't there a way to do this without user intervention?

Also, there seems to be a timing issue with the is1050. It will load and then the groupwise.msi will run and end in an error 1603. If you reboot the system and repeat the process, the install shield piece won't run (it's already installed) and the groupwise.msi will install successfully. Any info you can provide will be greatly appreciated. I have a call in to tech support but haven't gotten a resolution.

Marvin

© 2013 Novell