<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.open-xchange.com/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=WolfgangRosenauer</id>
	<title>Open-Xchange - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.open-xchange.com/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=WolfgangRosenauer"/>
	<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=Special:Contributions/WolfgangRosenauer"/>
	<updated>2026-10-01T13:10:02Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.39.7</generator>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:PushToUI_8&amp;diff=28936</id>
		<title>AppSuite:PushToUI 8</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:PushToUI_8&amp;diff=28936"/>
		<updated>2025-07-09T10:43:50Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Howto configure push into the App Suite Web UI and PWA for App Suite 8 =&lt;br /&gt;
&lt;br /&gt;
__TOC__&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
This HOWTO should provide a guideline to configure a push mechanism into the App Suite UI based on websockets and webpush. The push implementation in the current version of App Suite can provide push methods for email and calendar events.&lt;br /&gt;
&lt;br /&gt;
== Setup ==&lt;br /&gt;
The general method to transport push to the UI is based on [https://en.wikipedia.org/wiki/WebSocket websockets] which is a web-technology to allow a web page to communicate with the web server full duplex.&lt;br /&gt;
&lt;br /&gt;
This also means that any loadbalancers or reverse proxies in front of the kubernetes environment used for App Suite need to support websockets transparently.&lt;br /&gt;
&lt;br /&gt;
Implementing this part already allows the system to push appointment updates via push to the webinterface.&lt;br /&gt;
&lt;br /&gt;
In addition to websocket based push App Suite 8 also supports [https://developer.mozilla.org/en-US/docs/Web/API/Push_API WebPush] alternatively. Especially for the PWA this is a requirement.&lt;br /&gt;
&lt;br /&gt;
In order to support new mail notifications and direct appearance of new mails in the mailbox there are the following components to be configured:&lt;br /&gt;
&lt;br /&gt;
=== Mail push implementation ===&lt;br /&gt;
There needs to be a suitable [https://documentation.open-xchange.com/8/middleware/mail/mail_push.html push implementation]. It is highly recommended to use the Dovecot push integration described here: https://documentation.open-xchange.com/8/middleware/mail/dovecot/dovecot_push.html&lt;br /&gt;
&lt;br /&gt;
=== Push Notification Service ===&lt;br /&gt;
In addition it is required to install and configure the generic push notifications and webhook support&lt;br /&gt;
* in the middleware: [https://documentation.open-xchange.com/8/middleware/push_notifications/push_notification_service.html PNS] and [https://documentation.open-xchange.com/8/middleware/push_notifications/webhooks.html Webhooks]&lt;br /&gt;
Example&lt;br /&gt;
  packages:&lt;br /&gt;
    status:&lt;br /&gt;
      open-xchange-pns-impl: enabled&lt;br /&gt;
&lt;br /&gt;
  properties:&lt;br /&gt;
    com.openexchange.pns.transport.webhooks.enabled: &amp;quot;true&amp;quot;&lt;br /&gt;
    com.openexchange.pns.transport.webhooks.allowLocalWebhooks: &amp;quot;true&amp;quot;&lt;br /&gt;
    com.openexchange.pns.transport.webhooks.httpsOnly: &amp;quot;false&amp;quot;&lt;br /&gt;
    com.openexchange.pns.transport.webhooks.allowTrustAll: &amp;quot;true&amp;quot;&lt;br /&gt;
    com.openexchange.webhooks.enabledIds: switchboard&lt;br /&gt;
    com.openexchange.push.credstorage.enabled: &amp;quot;true&amp;quot;&lt;br /&gt;
&lt;br /&gt;
* in the UI: &lt;br /&gt;
  io.ox/core//features/pns: &amp;quot;true&amp;quot;&lt;br /&gt;
&lt;br /&gt;
=== Switchboard ===&lt;br /&gt;
Websockets and webpush events in App Suite 8 are managed via the switchboard component instead of the Java middleware.&lt;br /&gt;
You can find the documentation how to setup websockets for switchboard here: https://documentation.open-xchange.com/appsuite/releases/8.39/helmdocs/switchboard.html#webhook-and-push-notifications&lt;br /&gt;
&lt;br /&gt;
Specifically it adds the requirement for a MySQL database for switchboard and the creation of vapids.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Enabling the webinterface to request mail push ===&lt;br /&gt;
The client &#039;&#039;&#039;open-xchange-appsuite&#039;&#039;&#039; needs to be added to the property &#039;&#039;&#039;com.openexchange.push.allowedClients&#039;&#039;&#039; (typically in the file /opt/open-xchange/etc/mail-push.properties).&lt;br /&gt;
&lt;br /&gt;
e.g.&lt;br /&gt;
 com.openexchange.push.allowedClients=&amp;quot;USM-EAS*&amp;quot;, &amp;quot;open-xchange-appsuite&amp;quot;&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:PushToUI_8&amp;diff=28935</id>
		<title>AppSuite:PushToUI 8</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:PushToUI_8&amp;diff=28935"/>
		<updated>2025-07-09T10:42:54Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: Created page with &amp;quot;= Howto configure push into the App Suite Web UI and PWA for App Suite 8 =  __TOC__  == Introduction == This HOWTO should provide a guideline to configure a push mechanism into the App Suite UI based on websockets and webpush. The push implementation in the current version of App Suite can provide push methods for email and calendar events.  == Setup == The general method to transport push to the UI is based on [https://en.wikipedia.org/wiki/WebSocket websockets] which i...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Howto configure push into the App Suite Web UI and PWA for App Suite 8 =&lt;br /&gt;
&lt;br /&gt;
__TOC__&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
This HOWTO should provide a guideline to configure a push mechanism into the App Suite UI based on websockets and webpush. The push implementation in the current version of App Suite can provide push methods for email and calendar events.&lt;br /&gt;
&lt;br /&gt;
== Setup ==&lt;br /&gt;
The general method to transport push to the UI is based on [https://en.wikipedia.org/wiki/WebSocket websockets] which is a web-technology to allow a web page to communicate with the web server full duplex.&lt;br /&gt;
&lt;br /&gt;
This also means that any loadbalancers or reverse proxies in front of the kubernetes environment used for App Suite need to support websockets transparently.&lt;br /&gt;
&lt;br /&gt;
Implementing this part already allows the system to push appointment updates via push to the webinterface.&lt;br /&gt;
&lt;br /&gt;
In addition to websocket based push App Suite 8 also supports [https://developer.mozilla.org/en-US/docs/Web/API/Push_API WebPush] alternatively. Especially for the PWA this is a requirement.&lt;br /&gt;
&lt;br /&gt;
In order to support new mail notifications and direct appearance of new mails in the mailbox there are the following components to be configured:&lt;br /&gt;
&lt;br /&gt;
=== Mail push implementation ===&lt;br /&gt;
There needs to be a suitable [https://documentation.open-xchange.com/8/middleware/mail/mail_push.html push implementation]. It is highly recommended to use the Dovecot push integration described here: https://documentation.open-xchange.com/8/middleware/mail/dovecot/dovecot_push.html&lt;br /&gt;
&lt;br /&gt;
=== Push Notification Service ===&lt;br /&gt;
In addition it is required to install and configure the generic push notifications and webhook support&lt;br /&gt;
* in the middleware: [https://documentation.open-xchange.com/8/middleware/push_notifications/push_notification_service.html PNS] and [https://documentation.open-xchange.com/8/middleware/push_notifications/webhooks.html Webhooks]&lt;br /&gt;
Example&lt;br /&gt;
  packages:&lt;br /&gt;
    status:&lt;br /&gt;
      open-xchange-pns-impl: enabled&lt;br /&gt;
&lt;br /&gt;
  properties:&lt;br /&gt;
    com.openexchange.pns.transport.webhooks.enabled: &amp;quot;true&amp;quot;&lt;br /&gt;
    com.openexchange.pns.transport.webhooks.allowLocalWebhooks: &amp;quot;true&amp;quot;&lt;br /&gt;
    com.openexchange.pns.transport.webhooks.httpsOnly: &amp;quot;false&amp;quot;&lt;br /&gt;
    com.openexchange.pns.transport.webhooks.allowTrustAll: &amp;quot;true&amp;quot;&lt;br /&gt;
    com.openexchange.webhooks.enabledIds: switchboard&lt;br /&gt;
    com.openexchange.push.allowedClients: &#039;&amp;quot;USM-EAS*&amp;quot;, &amp;quot;open-xchange-appsuite&amp;quot;&#039;&lt;br /&gt;
    com.openexchange.push.credstorage.enabled: &amp;quot;true&amp;quot;&lt;br /&gt;
&lt;br /&gt;
* in the UI: &lt;br /&gt;
  io.ox/core//features/pns: &amp;quot;true&amp;quot;&lt;br /&gt;
&lt;br /&gt;
=== Switchboard ===&lt;br /&gt;
Websockets and webpush events in App Suite 8 are managed via the switchboard component instead of the Java middleware.&lt;br /&gt;
You can find the documentation how to setup websockets for switchboard here: https://documentation.open-xchange.com/appsuite/releases/8.39/helmdocs/switchboard.html#webhook-and-push-notifications&lt;br /&gt;
&lt;br /&gt;
Specifically it adds the requirement for a MySQL database for switchboard and the creation of vapids.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Enabling the webinterface to request mail push ===&lt;br /&gt;
The client &#039;&#039;&#039;open-xchange-appsuite&#039;&#039;&#039; needs to be added to the property &#039;&#039;&#039;com.openexchange.push.allowedClients&#039;&#039;&#039; (typically in the file /opt/open-xchange/etc/mail-push.properties).&lt;br /&gt;
&lt;br /&gt;
e.g.&lt;br /&gt;
 com.openexchange.push.allowedClients=&amp;quot;USM-EAS*&amp;quot;, &amp;quot;open-xchange-appsuite&amp;quot;&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:OX_System_Requirements&amp;diff=26870</id>
		<title>AppSuite:OX System Requirements</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:OX_System_Requirements&amp;diff=26870"/>
		<updated>2022-04-11T12:03:55Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: /* Java */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= OX App Suite Requirements - Open-Xchange supported components overview =&lt;br /&gt;
&lt;br /&gt;
The following table provides an overview about the supported components of OX App Suite and further products. This overview makes no claim to be complete.&lt;br /&gt;
&lt;br /&gt;
Information about Maintenance expiries of components, versions and browser support, can be found in the [[AppSuite:Versioning_and_Numbering#Maintenance_expires|Maintenance Expires Table]]&lt;br /&gt;
&lt;br /&gt;
== Hardware Requirements ==&lt;br /&gt;
&lt;br /&gt;
=== General Assumptions ===&lt;br /&gt;
&lt;br /&gt;
Open-Xchange App Suite Server (middleware services) is designed to run on physical servers or virtual machines of the same flavor. Cloud environments might be used in terms of Infrastructure as a Service (IaaS), meaning that all components need to be deployed in a classical manner on virtual machines.&lt;br /&gt;
&lt;br /&gt;
This means in particular, but not only:&lt;br /&gt;
&lt;br /&gt;
* Infrastructure is supposed to be &amp;quot;quasi-static&amp;quot;. Automatic replacement of broken nodes is fine as long as this is always an exceptional case. Scaling out or reducing number of nodes must always be a conscious task and closely monitored.&lt;br /&gt;
* The only supported &amp;quot;Database as a service&amp;quot; solution is AWS RDS for MariaDB as defined by belows compatibility table.&lt;br /&gt;
&lt;br /&gt;
Especially we expect the virtual hardware to be not over-provisioned. Each VM must have dedicated resources with respect to CPU cores, RAM, IOPS, storage, network bandwidth, network latency, etc.&lt;br /&gt;
&lt;br /&gt;
Network is expected to be flat, inside one datacenter, no multi-datacenter, no segments. No packet loss, low latency.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Disclaimer: All recommendations below are without guarantee and can differ for specific deployments. For mid- and large-scale setups a detailed deployment planning and sizing tests are mandatory and should be agreed on with OX Professional Services.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== High Level Design / OS setup ===&lt;br /&gt;
&lt;br /&gt;
Operate services separately (USM, Document/Image Converters) as described in [https://oxpedia.org/wiki/index.php?title=AppSuite:Running_a_cluster Cluster Setup].&lt;br /&gt;
&lt;br /&gt;
Clocks between all nodes must be synchronized (e.g. via NTP).&lt;br /&gt;
&lt;br /&gt;
Open file/max process limits need to be adjusted properly. Based on the used Linux distribution and init system configuration will differ, see Resource Limits for further explanation.&lt;br /&gt;
&lt;br /&gt;
Platform Architecture: 64 bit versions (x84_64) of the supported [[#Software Requirements | Linux distributions]]&lt;br /&gt;
&lt;br /&gt;
=== Node Sizing ===&lt;br /&gt;
&lt;br /&gt;
==== OX App Suite Middleware ====&lt;br /&gt;
&lt;br /&gt;
* Max. 8 GB heap per JVM + 4 GB system memory for other daemons and the OS (buffers, caches)&lt;br /&gt;
* 4 CPU cores (virtual, physical or hyperthreads) for plain HTTP connections. If TLS is terminated on application nodes this might need to be doubled.&lt;br /&gt;
* Disk space&lt;br /&gt;
** 8 GB for OS and software&lt;br /&gt;
** Some services like Document Converter need SWAP partitions (~1 * RAM)&lt;br /&gt;
** 2 * system memory of free disk space (i.e. 12 GB RAM =&amp;gt; 24 GB free disk space) for file spooling, log files, heap and core dumps&lt;br /&gt;
&lt;br /&gt;
=== Untested/Unsupported Deployments ===&lt;br /&gt;
&lt;br /&gt;
* Changes to Garbage Collector settings&lt;br /&gt;
* Running in containerized environments (Docker, rkt)&lt;br /&gt;
* Elasticity/High velocity of nodes going up and down: Services are sometimes stateful and demand static configuration&lt;br /&gt;
* Cloud platform services (PaaS) that promise to replacements for certain supported technologies but have not been verified by OX for these regards&lt;br /&gt;
* Multi-site active-active&lt;br /&gt;
&lt;br /&gt;
== Software Requirements ==&lt;br /&gt;
&lt;br /&gt;
=== Linux Distributions ===&lt;br /&gt;
&lt;br /&gt;
OX App Suite is available as Linux packages for the following distributions:&lt;br /&gt;
&lt;br /&gt;
{|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
 |&#039;&#039;&#039;Distribution&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;Versions&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;Remarks&#039;&#039;&#039;&lt;br /&gt;
|- &lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
 |Red Hat Enterprise Linux&lt;br /&gt;
 |7&lt;br /&gt;
 |&lt;br /&gt;
|-&lt;br /&gt;
 |CentOS&lt;br /&gt;
 |7&lt;br /&gt;
 |Install from RHEL package repositories&lt;br /&gt;
|-&lt;br /&gt;
 |Debian&lt;br /&gt;
 |9 (Stretch), 10 (Buster)&lt;br /&gt;
 |&lt;br /&gt;
|-&lt;br /&gt;
 |Univention Corporate Server&lt;br /&gt;
 |4.4, 5.0&lt;br /&gt;
 |&lt;br /&gt;
|-&lt;br /&gt;
 |Amazon Linux&lt;br /&gt;
 |2&lt;br /&gt;
 |Discontinued Support with end of life of OX App Suite v7.10.5&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Java ===&lt;br /&gt;
&lt;br /&gt;
OX App Suite Middleware requires OpenJDK headless JRE 8 or 9. Linux distributions might offer only packages for OpenJDK 11 JRE or higher, which are not suitable for OX App Suite. It is in those cases required to install Eclipse Temurin 8 JRE with HotSpot VM (successor of Adoptium). A comprehensive installation guide can be found at https://adoptium.net/de/installation/linux/. The correct JRE package is &#039;&#039;&#039;temurin-8-jdk&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== Databases ===&lt;br /&gt;
&lt;br /&gt;
OX App Suite uses MySQL/MariaDB with the InnoDB storage engine as its primary data store. The following vendors and products are supported.&lt;br /&gt;
&lt;br /&gt;
{|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
 |&#039;&#039;&#039;Vendor&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;Product&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;Versions&#039;&#039;&#039;&lt;br /&gt;
|- &lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
 |Oracle&lt;br /&gt;
 |MySQL Community Edition, Standard Edition, Enterprise Edition&lt;br /&gt;
 |v5.6.x, v5.7.x&lt;br /&gt;
|-&lt;br /&gt;
 |MariaDB&lt;br /&gt;
 |MariaDB Server, Galera Cluster&lt;br /&gt;
 |v10.1.x, v10.2.x, v10.4.x, v10.5.x.&lt;br /&gt;
|-&lt;br /&gt;
 |Amazon&lt;br /&gt;
 |AWS RDS for MariaDB&lt;br /&gt;
 |10.2.x&amp;lt;br&amp;gt;Discontinued Support with end of life of OX App Suite v7.10.5&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Important Notes ====&lt;br /&gt;
&lt;br /&gt;
* Open-Xchange does not plan to support &#039;&#039;&#039;MySQL 8 or higher&#039;&#039;&#039;. As MariaDB and MySQL are diverging and cannot be assumed drop-in replacements anymore, Open-Xchange will focus on MariaDB Server and MariaDB Galera Cluster. Future App Suite releases &#039;&#039;&#039;&amp;gt; 7.10.x&#039;&#039;&#039; might rely on features only available in &#039;&#039;&#039;MariaDB&#039;&#039;&#039;.&lt;br /&gt;
* Open-Xchange supports &#039;&#039;&#039;Percona XtraDB Cluster&#039;&#039;&#039; for existing customers with initial deployments done using &#039;&#039;&#039;App Suite 7.8.x or earlier&#039;&#039;&#039;. Those customers can continue to use Percona XtraDB Cluster throughout the 7.10.x release series. Like for MySQL, 7.10.x supports only versions 5.6 and 5.7. It is not planned to support Percona XtraDB Cluster beyond 7.10.x.&lt;br /&gt;
&lt;br /&gt;
* For some Linux distributions the included MySQL/MariaDB packages are too old to be used with App Suite. It is mandatory then to install a supported version from &#039;&#039;&#039;upstream package sources&#039;&#039;&#039;. Possible sources are the official vendor repositories of MySQL or MariaDB as well as for example Red Hat Software Collections.&lt;br /&gt;
* Required &#039;&#039;&#039;MySQL/MariaDB configuration&#039;&#039;&#039; configuration differs between &#039;&#039;&#039;App Suite 7.8.4 and 7.10.x&#039;&#039;&#039; and also between the different database systems in terms of SQL modes. See [[My.cnf]] for details.&lt;br /&gt;
* For upgrades from App Suite &amp;lt;= 7.8.2 to &amp;gt;= 7.10.0 a comprehensive &#039;&#039;&#039;database upgrade guide&#039;&#039;&#039; exists: [[AppSuite:7_10_Database_Migration]]&lt;br /&gt;
&lt;br /&gt;
== HTTP Reverse Proxy ==&lt;br /&gt;
&lt;br /&gt;
An HTTP server with reverse proxy and load balancing capabilities is required in front of App Suite application servers. TLS termination, virtual hosts, path-based routing, sticky sessions and X-Forwarded headers are typical required features. OX strongly recommends [https://httpd.apache.org/ Apache httpd 2.x] for that. Configuration examples can be found in the quickinstall guides.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Important:&#039;&#039;&#039; For websocket support Apache httpd 2.4.x is needed, 2.2.x does not support the required ws_tunnel module. Websockets are mandatory for OX Documents starting with v7.10.3. Like with JRE and MySQL/MariaDB it might be necessary to use 3rd party packages to get the needed Linux packages. Especially for RHEL6 we recommend using Red Hat Software Collections.&lt;br /&gt;
&lt;br /&gt;
== Webserver ==&lt;br /&gt;
&lt;br /&gt;
[https://httpd.apache.org/ Apache httpd 2.x] is required as webserver to serve static App Suite UI content. Configuration examples can be found in the quickinstall guides.&lt;br /&gt;
&lt;br /&gt;
== File Storage ==&lt;br /&gt;
&lt;br /&gt;
=== Temporary Data ===&lt;br /&gt;
&lt;br /&gt;
OX App Suite stores temporary files in the local file system, e.g. for spooling of uploaded data. Any file system supported by the installed JRE is suitable.&lt;br /&gt;
&lt;br /&gt;
=== Persistent Data ===&lt;br /&gt;
&lt;br /&gt;
Persistent data like OX Drive files, PIM attachments etc. and temporary attachment data need to be stored in a distributed file system as registered filestore that is available from all server nodes. For single-node setups a local file system mount point can be used, small to mid-scale setups can be powered by NFS. For large-scale setups object storages should be considered.&lt;br /&gt;
&lt;br /&gt;
==== Object Storages ====&lt;br /&gt;
&lt;br /&gt;
OX App Suite ships with different optional adapters to support object storages.&lt;br /&gt;
&lt;br /&gt;
{|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
 |&#039;&#039;&#039;Vendor&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;Product&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;API&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;Remarks&#039;&#039;&#039;&lt;br /&gt;
|- &lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
 |Amazon&lt;br /&gt;
 |AWS S3&lt;br /&gt;
 |S3 HTTP API&lt;br /&gt;
 |See also [[AppSuite:S3_File_Store]]&lt;br /&gt;
|-&lt;br /&gt;
 |CEPH&lt;br /&gt;
 |RadosGW&lt;br /&gt;
 |S3 HTTP API&lt;br /&gt;
 |See also [[AppSuite:S3_File_Store]]&lt;br /&gt;
|-&lt;br /&gt;
 |Scality&lt;br /&gt;
 |Scality RING&lt;br /&gt;
 |Sproxyd HTTP API&lt;br /&gt;
 |See also [[AppSuite:Scality_File_Store]]&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Desktop Browser (Minimum display resolution: 1024 x 768)==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Browser&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;OX App Suite User Front-End&#039;&#039;&#039;&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |Google Chrome (latest &amp;amp; previous version)&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
 |-&lt;br /&gt;
  |Mozilla Firefox (latest &amp;amp; current ESR-Version)&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
 |-&lt;br /&gt;
  |Apple Safari (latest &amp;amp; previous version; macOS only)&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
 |-&lt;br /&gt;
  |Microsoft Edge (Chromium-based)&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
 |-&lt;br /&gt;
  |Microsoft Internet Explorer 10/11&lt;br /&gt;
  |v7.6.3&lt;br /&gt;
 |-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Mobile Device Support==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Mobile Device&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;Supported Browser&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;OX App Suite User Front-End&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;Minimum Speed Requirements&#039;&#039;&#039;&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |iPhone on iOS 14 / iOS 15 / iPad OS&lt;br /&gt;
  |Safari&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
  |3G connections (512/256kBit/s, 350ms latency)&lt;br /&gt;
 |-&lt;br /&gt;
  |Smartphone on Android 4.1 or later&lt;br /&gt;
  |Chrome (latest &amp;amp; previous version)&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
  |3G connections (512/256kBit/s, 350ms latency)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Tablet Support==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Tablet&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;Supported Browser&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;OX App Suite User Front-End&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;Minimum Speed Requirements&#039;&#039;&#039;&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |Apple iPad (all devices) on iOS 14 / iOS 15 / iPad OS&lt;br /&gt;
  |Safari&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
  |3G connections (512/256kBit/s, 350ms latency)&lt;br /&gt;
 |-&lt;br /&gt;
  |Tablets on Android 4.1 or later&lt;br /&gt;
  |Chrome (latest &amp;amp; previous version)&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
  |3G connections (512/256kBit/s, 350ms latency)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Calendar/Contact synchronization Apple macOS ==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Requirement&#039;&#039;&#039;&lt;br /&gt;
  |Calendar synchronization with CalDAV&lt;br /&gt;
  |Contacts synchronization with CardDAV&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
  |macOS 11.0 (Big Sur)&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
|-&lt;br /&gt;
  |macOS 12.0 (Monterey)&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Calendar/Contact synchronization Apple iOS ==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Requirement&#039;&#039;&#039;&lt;br /&gt;
  |Calendar synchronization with CalDAV&lt;br /&gt;
  |Contacts synchronization with CardDAV&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
  |Apple iOS 14 / iOS 15 / iPad OS&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Mobility Solution - Supported-  Platforms, Features and Devices ==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Feature/Technology/Device&#039;&#039;&#039;&lt;br /&gt;
  |[http://oxpedia.org/wiki/index.php?title=OXtender_for_Business_Mobility &#039;&#039;&#039;OXtender for Business Mobility&#039;&#039;&#039;] (availalble for App Suite, OXHE, OXSE)&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |Exchange Active Sync 2.5&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
 |-&lt;br /&gt;
  |Exchange Active Sync 12.1&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |Access and creation of emails&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
|-&lt;br /&gt;
  |Personal PIM folder&lt;br /&gt;
  |[[File:check.gif]] &lt;br /&gt;
|-&lt;br /&gt;
  |Public and Shared PIM folder&lt;br /&gt;
  |[[File:cross.gif]]&lt;br /&gt;
|-&lt;br /&gt;
  |Global address book&lt;br /&gt;
  |[[File:check.gif]] &lt;br /&gt;
|-&lt;br /&gt;
  |Push E-Mail&lt;br /&gt;
  |[[File:check.gif]] &lt;br /&gt;
|-&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |Apple iOS 14 / iOS 15 / iPad OS&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
 |-&lt;br /&gt;
  |Android 8 (Oreo) or later with latest Gmail app.&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
 |-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== OX Drive Clients ==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Requirement&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;System / Platform&#039;&#039;&#039;&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |OX Drive for Windows&lt;br /&gt;
  |OX App Suite 7.10.5, OX App Suite 7.10.6&amp;lt;br&amp;gt;Latest versions of Windows 10 (no support of macOS clients with emulators and Windows RT)&lt;br /&gt;
 |-&lt;br /&gt;
  |OX Drive for Apple macOS&lt;br /&gt;
  |OX App Suite 7.10.5, OX App Suite 7.10.6&amp;lt;br&amp;gt;macOS Big Sur 11, macOS Monterey 12, Intel- and Apple Silicon-based devices are both supported&lt;br /&gt;
 |-&lt;br /&gt;
  |OX Drive v2 for Apple iOS&lt;br /&gt;
  |OX App Suite 7.10.5, OX App Suite 7.10.6&amp;lt;br&amp;gt;iOS / iPadOS 14 and above&lt;br /&gt;
 |-&lt;br /&gt;
  |OX Drive v3 for Apple iOS&lt;br /&gt;
  |OX App Suite 7.10.6&amp;lt;br&amp;gt;iOS / iPadOS 14 and above&lt;br /&gt;
 |-&lt;br /&gt;
  |OX Drive for Android&lt;br /&gt;
  |OX App Suite 7.10.5, OX App Suite 7.10.6&amp;lt;br&amp;gt;Smartphones and tablets running Android 7.0 (API level 24) and above.&lt;br /&gt;
 |-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== OX Sync App ==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Requirement&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;System / Platform / User Interface&#039;&#039;&#039;&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |OX App Suite&lt;br /&gt;
  |OX App Suite 7.10.5, OX App Suite 7.10.6&lt;br /&gt;
 |-&lt;br /&gt;
  |OX Sync App for Android&lt;br /&gt;
  |Smartphone on Android 5.0 or later&lt;br /&gt;
 |-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== OX Guard ==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Requirement&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;System / Platform / User Interface&#039;&#039;&#039;&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |OX App Suite&lt;br /&gt;
  |OX Guard since v2.10.5: OX App Suite v7.10.5&amp;lt;br&amp;gt;OX Guard since v2.10.6: OX App Suite v7.10.6&lt;br /&gt;
 |-&lt;br /&gt;
  |Mobile Device and Tablet Support&lt;br /&gt;
  |Apple iPhone on iOS 14 / iOS 15 / iPad OS: Safari (latest version &amp;amp; previous version)&amp;lt;br&amp;gt;Smartphone on Android 4.1 or later: Chrome (latest &amp;amp; previous version)&amp;lt;br&amp;gt;Apple iPad (all devices) on iOS 14 / iOS 15 / iPad OS: Safari Safari (latest version &amp;amp; previous version)&amp;lt;br&amp;gt;Tablets on Android 4.1 or later: Chrome (latest &amp;amp; previous version)&lt;br /&gt;
 |-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: OX7]]&lt;br /&gt;
[[Category: AppSuite]]&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:OX_System_Requirements&amp;diff=26867</id>
		<title>AppSuite:OX System Requirements</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:OX_System_Requirements&amp;diff=26867"/>
		<updated>2022-04-11T12:02:14Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= OX App Suite Requirements - Open-Xchange supported components overview =&lt;br /&gt;
&lt;br /&gt;
The following table provides an overview about the supported components of OX App Suite and further products. This overview makes no claim to be complete.&lt;br /&gt;
&lt;br /&gt;
Information about Maintenance expiries of components, versions and browser support, can be found in the [[AppSuite:Versioning_and_Numbering#Maintenance_expires|Maintenance Expires Table]]&lt;br /&gt;
&lt;br /&gt;
== Hardware Requirements ==&lt;br /&gt;
&lt;br /&gt;
=== General Assumptions ===&lt;br /&gt;
&lt;br /&gt;
Open-Xchange App Suite Server (middleware services) is designed to run on physical servers or virtual machines of the same flavor. Cloud environments might be used in terms of Infrastructure as a Service (IaaS), meaning that all components need to be deployed in a classical manner on virtual machines.&lt;br /&gt;
&lt;br /&gt;
This means in particular, but not only:&lt;br /&gt;
&lt;br /&gt;
* Infrastructure is supposed to be &amp;quot;quasi-static&amp;quot;. Automatic replacement of broken nodes is fine as long as this is always an exceptional case. Scaling out or reducing number of nodes must always be a conscious task and closely monitored.&lt;br /&gt;
* The only supported &amp;quot;Database as a service&amp;quot; solution is AWS RDS for MariaDB as defined by belows compatibility table.&lt;br /&gt;
&lt;br /&gt;
Especially we expect the virtual hardware to be not over-provisioned. Each VM must have dedicated resources with respect to CPU cores, RAM, IOPS, storage, network bandwidth, network latency, etc.&lt;br /&gt;
&lt;br /&gt;
Network is expected to be flat, inside one datacenter, no multi-datacenter, no segments. No packet loss, low latency.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Disclaimer: All recommendations below are without guarantee and can differ for specific deployments. For mid- and large-scale setups a detailed deployment planning and sizing tests are mandatory and should be agreed on with OX Professional Services.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== High Level Design / OS setup ===&lt;br /&gt;
&lt;br /&gt;
Operate services separately (USM, Document/Image Converters) as described in [https://oxpedia.org/wiki/index.php?title=AppSuite:Running_a_cluster Cluster Setup].&lt;br /&gt;
&lt;br /&gt;
Clocks between all nodes must be synchronized (e.g. via NTP).&lt;br /&gt;
&lt;br /&gt;
Open file/max process limits need to be adjusted properly. Based on the used Linux distribution and init system configuration will differ, see Resource Limits for further explanation.&lt;br /&gt;
&lt;br /&gt;
Platform Architecture: 64 bit versions (x84_64) of the supported [[#Software Requirements | Linux distributions]]&lt;br /&gt;
&lt;br /&gt;
=== Node Sizing ===&lt;br /&gt;
&lt;br /&gt;
==== OX App Suite Middleware ====&lt;br /&gt;
&lt;br /&gt;
* Max. 8 GB heap per JVM + 4 GB system memory for other daemons and the OS (buffers, caches)&lt;br /&gt;
* 4 CPU cores (virtual, physical or hyperthreads) for plain HTTP connections. If TLS is terminated on application nodes this might need to be doubled.&lt;br /&gt;
* Disk space&lt;br /&gt;
** 8 GB for OS and software&lt;br /&gt;
** Some services like Document Converter need SWAP partitions (~1 * RAM)&lt;br /&gt;
** 2 * system memory of free disk space (i.e. 12 GB RAM =&amp;gt; 24 GB free disk space) for file spooling, log files, heap and core dumps&lt;br /&gt;
&lt;br /&gt;
=== Untested/Unsupported Deployments ===&lt;br /&gt;
&lt;br /&gt;
* Changes to Garbage Collector settings&lt;br /&gt;
* Running in containerized environments (Docker, rkt)&lt;br /&gt;
* Elasticity/High velocity of nodes going up and down: Services are sometimes stateful and demand static configuration&lt;br /&gt;
* Cloud platform services (PaaS) that promise to replacements for certain supported technologies but have not been verified by OX for these regards&lt;br /&gt;
* Multi-site active-active&lt;br /&gt;
&lt;br /&gt;
== Software Requirements ==&lt;br /&gt;
&lt;br /&gt;
=== Linux Distributions ===&lt;br /&gt;
&lt;br /&gt;
OX App Suite is available as Linux packages for the following distributions:&lt;br /&gt;
&lt;br /&gt;
{|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
 |&#039;&#039;&#039;Distribution&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;Versions&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;Remarks&#039;&#039;&#039;&lt;br /&gt;
|- &lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
 |Red Hat Enterprise Linux&lt;br /&gt;
 |7&lt;br /&gt;
 |&lt;br /&gt;
|-&lt;br /&gt;
 |CentOS&lt;br /&gt;
 |7&lt;br /&gt;
 |Install from RHEL package repositories&lt;br /&gt;
|-&lt;br /&gt;
 |Debian&lt;br /&gt;
 |9 (Stretch), 10 (Buster)&lt;br /&gt;
 |&lt;br /&gt;
|-&lt;br /&gt;
 |Univention Corporate Server&lt;br /&gt;
 |4.4, 5.0&lt;br /&gt;
 |&lt;br /&gt;
|-&lt;br /&gt;
 |Amazon Linux&lt;br /&gt;
 |2&lt;br /&gt;
 |Discontinued Support with end of life of OX App Suite v7.10.5&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Java ===&lt;br /&gt;
&lt;br /&gt;
OX App Suite Middleware requires OpenJDK headless JRE 8 or 9. Linux distributions might offer only packages for OpenJDK 11 JRE or higher, which are not suitable for OX App Suite. It is in those cases required to install Eclipse Temurin 8 JRE with HotSpot VM (successor of Adoptium). A comprehensive installation guide can be found at https://adoptium.net/de/installation/linux/. The correct JRE package is *temurin-8-jdk*.&lt;br /&gt;
&lt;br /&gt;
=== Databases ===&lt;br /&gt;
&lt;br /&gt;
OX App Suite uses MySQL/MariaDB with the InnoDB storage engine as its primary data store. The following vendors and products are supported.&lt;br /&gt;
&lt;br /&gt;
{|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
 |&#039;&#039;&#039;Vendor&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;Product&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;Versions&#039;&#039;&#039;&lt;br /&gt;
|- &lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
 |Oracle&lt;br /&gt;
 |MySQL Community Edition, Standard Edition, Enterprise Edition&lt;br /&gt;
 |v5.6.x, v5.7.x&lt;br /&gt;
|-&lt;br /&gt;
 |MariaDB&lt;br /&gt;
 |MariaDB Server, Galera Cluster&lt;br /&gt;
 |v10.1.x, v10.2.x, v10.4.x, v10.5.x.&lt;br /&gt;
|-&lt;br /&gt;
 |Amazon&lt;br /&gt;
 |AWS RDS for MariaDB&lt;br /&gt;
 |10.2.x&amp;lt;br&amp;gt;Discontinued Support with end of life of OX App Suite v7.10.5&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Important Notes ====&lt;br /&gt;
&lt;br /&gt;
* Open-Xchange does not plan to support &#039;&#039;&#039;MySQL 8 or higher&#039;&#039;&#039;. As MariaDB and MySQL are diverging and cannot be assumed drop-in replacements anymore, Open-Xchange will focus on MariaDB Server and MariaDB Galera Cluster. Future App Suite releases &#039;&#039;&#039;&amp;gt; 7.10.x&#039;&#039;&#039; might rely on features only available in &#039;&#039;&#039;MariaDB&#039;&#039;&#039;.&lt;br /&gt;
* Open-Xchange supports &#039;&#039;&#039;Percona XtraDB Cluster&#039;&#039;&#039; for existing customers with initial deployments done using &#039;&#039;&#039;App Suite 7.8.x or earlier&#039;&#039;&#039;. Those customers can continue to use Percona XtraDB Cluster throughout the 7.10.x release series. Like for MySQL, 7.10.x supports only versions 5.6 and 5.7. It is not planned to support Percona XtraDB Cluster beyond 7.10.x.&lt;br /&gt;
&lt;br /&gt;
* For some Linux distributions the included MySQL/MariaDB packages are too old to be used with App Suite. It is mandatory then to install a supported version from &#039;&#039;&#039;upstream package sources&#039;&#039;&#039;. Possible sources are the official vendor repositories of MySQL or MariaDB as well as for example Red Hat Software Collections.&lt;br /&gt;
* Required &#039;&#039;&#039;MySQL/MariaDB configuration&#039;&#039;&#039; configuration differs between &#039;&#039;&#039;App Suite 7.8.4 and 7.10.x&#039;&#039;&#039; and also between the different database systems in terms of SQL modes. See [[My.cnf]] for details.&lt;br /&gt;
* For upgrades from App Suite &amp;lt;= 7.8.2 to &amp;gt;= 7.10.0 a comprehensive &#039;&#039;&#039;database upgrade guide&#039;&#039;&#039; exists: [[AppSuite:7_10_Database_Migration]]&lt;br /&gt;
&lt;br /&gt;
== HTTP Reverse Proxy ==&lt;br /&gt;
&lt;br /&gt;
An HTTP server with reverse proxy and load balancing capabilities is required in front of App Suite application servers. TLS termination, virtual hosts, path-based routing, sticky sessions and X-Forwarded headers are typical required features. OX strongly recommends [https://httpd.apache.org/ Apache httpd 2.x] for that. Configuration examples can be found in the quickinstall guides.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Important:&#039;&#039;&#039; For websocket support Apache httpd 2.4.x is needed, 2.2.x does not support the required ws_tunnel module. Websockets are mandatory for OX Documents starting with v7.10.3. Like with JRE and MySQL/MariaDB it might be necessary to use 3rd party packages to get the needed Linux packages. Especially for RHEL6 we recommend using Red Hat Software Collections.&lt;br /&gt;
&lt;br /&gt;
== Webserver ==&lt;br /&gt;
&lt;br /&gt;
[https://httpd.apache.org/ Apache httpd 2.x] is required as webserver to serve static App Suite UI content. Configuration examples can be found in the quickinstall guides.&lt;br /&gt;
&lt;br /&gt;
== File Storage ==&lt;br /&gt;
&lt;br /&gt;
=== Temporary Data ===&lt;br /&gt;
&lt;br /&gt;
OX App Suite stores temporary files in the local file system, e.g. for spooling of uploaded data. Any file system supported by the installed JRE is suitable.&lt;br /&gt;
&lt;br /&gt;
=== Persistent Data ===&lt;br /&gt;
&lt;br /&gt;
Persistent data like OX Drive files, PIM attachments etc. and temporary attachment data need to be stored in a distributed file system as registered filestore that is available from all server nodes. For single-node setups a local file system mount point can be used, small to mid-scale setups can be powered by NFS. For large-scale setups object storages should be considered.&lt;br /&gt;
&lt;br /&gt;
==== Object Storages ====&lt;br /&gt;
&lt;br /&gt;
OX App Suite ships with different optional adapters to support object storages.&lt;br /&gt;
&lt;br /&gt;
{|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
 |&#039;&#039;&#039;Vendor&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;Product&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;API&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;Remarks&#039;&#039;&#039;&lt;br /&gt;
|- &lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
 |Amazon&lt;br /&gt;
 |AWS S3&lt;br /&gt;
 |S3 HTTP API&lt;br /&gt;
 |See also [[AppSuite:S3_File_Store]]&lt;br /&gt;
|-&lt;br /&gt;
 |CEPH&lt;br /&gt;
 |RadosGW&lt;br /&gt;
 |S3 HTTP API&lt;br /&gt;
 |See also [[AppSuite:S3_File_Store]]&lt;br /&gt;
|-&lt;br /&gt;
 |Scality&lt;br /&gt;
 |Scality RING&lt;br /&gt;
 |Sproxyd HTTP API&lt;br /&gt;
 |See also [[AppSuite:Scality_File_Store]]&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Desktop Browser (Minimum display resolution: 1024 x 768)==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Browser&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;OX App Suite User Front-End&#039;&#039;&#039;&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |Google Chrome (latest &amp;amp; previous version)&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
 |-&lt;br /&gt;
  |Mozilla Firefox (latest &amp;amp; current ESR-Version)&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
 |-&lt;br /&gt;
  |Apple Safari (latest &amp;amp; previous version; macOS only)&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
 |-&lt;br /&gt;
  |Microsoft Edge (Chromium-based)&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
 |-&lt;br /&gt;
  |Microsoft Internet Explorer 10/11&lt;br /&gt;
  |v7.6.3&lt;br /&gt;
 |-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Mobile Device Support==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Mobile Device&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;Supported Browser&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;OX App Suite User Front-End&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;Minimum Speed Requirements&#039;&#039;&#039;&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |iPhone on iOS 14 / iOS 15 / iPad OS&lt;br /&gt;
  |Safari&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
  |3G connections (512/256kBit/s, 350ms latency)&lt;br /&gt;
 |-&lt;br /&gt;
  |Smartphone on Android 4.1 or later&lt;br /&gt;
  |Chrome (latest &amp;amp; previous version)&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
  |3G connections (512/256kBit/s, 350ms latency)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Tablet Support==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Tablet&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;Supported Browser&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;OX App Suite User Front-End&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;Minimum Speed Requirements&#039;&#039;&#039;&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |Apple iPad (all devices) on iOS 14 / iOS 15 / iPad OS&lt;br /&gt;
  |Safari&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
  |3G connections (512/256kBit/s, 350ms latency)&lt;br /&gt;
 |-&lt;br /&gt;
  |Tablets on Android 4.1 or later&lt;br /&gt;
  |Chrome (latest &amp;amp; previous version)&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
  |3G connections (512/256kBit/s, 350ms latency)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Calendar/Contact synchronization Apple macOS ==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Requirement&#039;&#039;&#039;&lt;br /&gt;
  |Calendar synchronization with CalDAV&lt;br /&gt;
  |Contacts synchronization with CardDAV&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
  |macOS 11.0 (Big Sur)&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
|-&lt;br /&gt;
  |macOS 12.0 (Monterey)&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Calendar/Contact synchronization Apple iOS ==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Requirement&#039;&#039;&#039;&lt;br /&gt;
  |Calendar synchronization with CalDAV&lt;br /&gt;
  |Contacts synchronization with CardDAV&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
  |Apple iOS 14 / iOS 15 / iPad OS&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Mobility Solution - Supported-  Platforms, Features and Devices ==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Feature/Technology/Device&#039;&#039;&#039;&lt;br /&gt;
  |[http://oxpedia.org/wiki/index.php?title=OXtender_for_Business_Mobility &#039;&#039;&#039;OXtender for Business Mobility&#039;&#039;&#039;] (availalble for App Suite, OXHE, OXSE)&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |Exchange Active Sync 2.5&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
 |-&lt;br /&gt;
  |Exchange Active Sync 12.1&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |Access and creation of emails&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
|-&lt;br /&gt;
  |Personal PIM folder&lt;br /&gt;
  |[[File:check.gif]] &lt;br /&gt;
|-&lt;br /&gt;
  |Public and Shared PIM folder&lt;br /&gt;
  |[[File:cross.gif]]&lt;br /&gt;
|-&lt;br /&gt;
  |Global address book&lt;br /&gt;
  |[[File:check.gif]] &lt;br /&gt;
|-&lt;br /&gt;
  |Push E-Mail&lt;br /&gt;
  |[[File:check.gif]] &lt;br /&gt;
|-&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |Apple iOS 14 / iOS 15 / iPad OS&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
 |-&lt;br /&gt;
  |Android 8 (Oreo) or later with latest Gmail app.&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
 |-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== OX Drive Clients ==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Requirement&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;System / Platform&#039;&#039;&#039;&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |OX Drive for Windows&lt;br /&gt;
  |OX App Suite 7.10.5, OX App Suite 7.10.6&amp;lt;br&amp;gt;Latest versions of Windows 10 (no support of macOS clients with emulators and Windows RT)&lt;br /&gt;
 |-&lt;br /&gt;
  |OX Drive for Apple macOS&lt;br /&gt;
  |OX App Suite 7.10.5, OX App Suite 7.10.6&amp;lt;br&amp;gt;macOS Big Sur 11, macOS Monterey 12, Intel- and Apple Silicon-based devices are both supported&lt;br /&gt;
 |-&lt;br /&gt;
  |OX Drive v2 for Apple iOS&lt;br /&gt;
  |OX App Suite 7.10.5, OX App Suite 7.10.6&amp;lt;br&amp;gt;iOS / iPadOS 14 and above&lt;br /&gt;
 |-&lt;br /&gt;
  |OX Drive v3 for Apple iOS&lt;br /&gt;
  |OX App Suite 7.10.6&amp;lt;br&amp;gt;iOS / iPadOS 14 and above&lt;br /&gt;
 |-&lt;br /&gt;
  |OX Drive for Android&lt;br /&gt;
  |OX App Suite 7.10.5, OX App Suite 7.10.6&amp;lt;br&amp;gt;Smartphones and tablets running Android 7.0 (API level 24) and above.&lt;br /&gt;
 |-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== OX Sync App ==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Requirement&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;System / Platform / User Interface&#039;&#039;&#039;&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |OX App Suite&lt;br /&gt;
  |OX App Suite 7.10.5, OX App Suite 7.10.6&lt;br /&gt;
 |-&lt;br /&gt;
  |OX Sync App for Android&lt;br /&gt;
  |Smartphone on Android 5.0 or later&lt;br /&gt;
 |-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== OX Guard ==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Requirement&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;System / Platform / User Interface&#039;&#039;&#039;&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |OX App Suite&lt;br /&gt;
  |OX Guard since v2.10.5: OX App Suite v7.10.5&amp;lt;br&amp;gt;OX Guard since v2.10.6: OX App Suite v7.10.6&lt;br /&gt;
 |-&lt;br /&gt;
  |Mobile Device and Tablet Support&lt;br /&gt;
  |Apple iPhone on iOS 14 / iOS 15 / iPad OS: Safari (latest version &amp;amp; previous version)&amp;lt;br&amp;gt;Smartphone on Android 4.1 or later: Chrome (latest &amp;amp; previous version)&amp;lt;br&amp;gt;Apple iPad (all devices) on iOS 14 / iOS 15 / iPad OS: Safari Safari (latest version &amp;amp; previous version)&amp;lt;br&amp;gt;Tablets on Android 4.1 or later: Chrome (latest &amp;amp; previous version)&lt;br /&gt;
 |-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: OX7]]&lt;br /&gt;
[[Category: AppSuite]]&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:OX_System_Requirements&amp;diff=26864</id>
		<title>AppSuite:OX System Requirements</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:OX_System_Requirements&amp;diff=26864"/>
		<updated>2022-04-11T12:01:42Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= OX App Suite Requirements - Open-Xchange supported components overview =&lt;br /&gt;
&lt;br /&gt;
The following table provides an overview about the supported components of OX App Suite and further products. This overview makes no claim to be complete.&lt;br /&gt;
&lt;br /&gt;
Information about Maintenance expiries of components, versions and browser support, can be found in the [[AppSuite:Versioning_and_Numbering#Maintenance_expires|Maintenance Expires Table]]&lt;br /&gt;
&lt;br /&gt;
== Hardware Requirements ==&lt;br /&gt;
&lt;br /&gt;
=== General Assumptions ===&lt;br /&gt;
&lt;br /&gt;
Open-Xchange App Suite Server (middleware services) is designed to run on physical servers or virtual machines of the same flavor. Cloud environments might be used in terms of Infrastructure as a Service (IaaS), meaning that all components need to be deployed in a classical manner on virtual machines.&lt;br /&gt;
&lt;br /&gt;
This means in particular, but not only:&lt;br /&gt;
&lt;br /&gt;
* Infrastructure is supposed to be &amp;quot;quasi-static&amp;quot;. Automatic replacement of broken nodes is fine as long as this is always an exceptional case. Scaling out or reducing number of nodes must always be a conscious task and closely monitored.&lt;br /&gt;
* The only supported &amp;quot;Database as a service&amp;quot; solution is AWS RDS for MariaDB as defined by belows compatibility table.&lt;br /&gt;
&lt;br /&gt;
Especially we expect the virtual hardware to be not over-provisioned. Each VM must have dedicated resources with respect to CPU cores, RAM, IOPS, storage, network bandwidth, network latency, etc.&lt;br /&gt;
&lt;br /&gt;
Network is expected to be flat, inside one datacenter, no multi-datacenter, no segments. No packet loss, low latency.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Disclaimer: All recommendations below are without guarantee and can differ for specific deployments. For mid- and large-scale setups a detailed deployment planning and sizing tests are mandatory and should be agreed on with OX Professional Services.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== High Level Design / OS setup ===&lt;br /&gt;
&lt;br /&gt;
Operate services separately (USM, Document/Image Converters) as described in [https://oxpedia.org/wiki/index.php?title=AppSuite:Running_a_cluster Cluster Setup].&lt;br /&gt;
&lt;br /&gt;
Clocks between all nodes must be synchronized (e.g. via NTP).&lt;br /&gt;
&lt;br /&gt;
Open file/max process limits need to be adjusted properly. Based on the used Linux distribution and init system configuration will differ, see Resource Limits for further explanation.&lt;br /&gt;
&lt;br /&gt;
Platform Architecture: 64 bit versions (x84_64) of the supported [[#Software Requirements | Linux distributions]]&lt;br /&gt;
&lt;br /&gt;
=== Node Sizing ===&lt;br /&gt;
&lt;br /&gt;
==== OX App Suite Middleware ====&lt;br /&gt;
&lt;br /&gt;
* Max. 8 GB heap per JVM + 4 GB system memory for other daemons and the OS (buffers, caches)&lt;br /&gt;
* 4 CPU cores (virtual, physical or hyperthreads) for plain HTTP connections. If TLS is terminated on application nodes this might need to be doubled.&lt;br /&gt;
* Disk space&lt;br /&gt;
** 8 GB for OS and software&lt;br /&gt;
** Some services like Document Converter need SWAP partitions (~1 * RAM)&lt;br /&gt;
** 2 * system memory of free disk space (i.e. 12 GB RAM =&amp;gt; 24 GB free disk space) for file spooling, log files, heap and core dumps&lt;br /&gt;
&lt;br /&gt;
=== Untested/Unsupported Deployments ===&lt;br /&gt;
&lt;br /&gt;
* Changes to Garbage Collector settings&lt;br /&gt;
* Running in containerized environments (Docker, rkt)&lt;br /&gt;
* Elasticity/High velocity of nodes going up and down: Services are sometimes stateful and demand static configuration&lt;br /&gt;
* Cloud platform services (PaaS) that promise to replacements for certain supported technologies but have not been verified by OX for these regards&lt;br /&gt;
* Multi-site active-active&lt;br /&gt;
&lt;br /&gt;
== Software Requirements ==&lt;br /&gt;
&lt;br /&gt;
=== Linux Distributions ===&lt;br /&gt;
&lt;br /&gt;
OX App Suite is available as Linux packages for the following distributions:&lt;br /&gt;
&lt;br /&gt;
{|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
 |&#039;&#039;&#039;Distribution&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;Versions&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;Remarks&#039;&#039;&#039;&lt;br /&gt;
|- &lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
 |Red Hat Enterprise Linux&lt;br /&gt;
 |7&lt;br /&gt;
 |&lt;br /&gt;
|-&lt;br /&gt;
 |CentOS&lt;br /&gt;
 |7&lt;br /&gt;
 |Install from RHEL package repositories&lt;br /&gt;
|-&lt;br /&gt;
 |Debian&lt;br /&gt;
 |9 (Stretch), 10 (Buster)&lt;br /&gt;
 |&lt;br /&gt;
|-&lt;br /&gt;
 |Univention Corporate Server&lt;br /&gt;
 |4.4, 5.0&lt;br /&gt;
 |&lt;br /&gt;
|-&lt;br /&gt;
 |Amazon Linux&lt;br /&gt;
 |2&lt;br /&gt;
 |Discontinued Support with end of life of OX App Suite v7.10.5&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Java ===&lt;br /&gt;
&lt;br /&gt;
OX App Suite Middleware requires OpenJDK headless JRE 8 or 9. Linux distributions might offer only packages for OpenJDK 11 JRE, which is not suitable for OX App Suite. It is in those cases required to install Eclipse Temurin 8 JRE with HotSpot VM (successor of Adoptium). A comprehensive installation guide can be found at https://adoptium.net/de/installation/linux/. The correct JRE package is *temurin-8-jdk*.&lt;br /&gt;
&lt;br /&gt;
=== Databases ===&lt;br /&gt;
&lt;br /&gt;
OX App Suite uses MySQL/MariaDB with the InnoDB storage engine as its primary data store. The following vendors and products are supported.&lt;br /&gt;
&lt;br /&gt;
{|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
 |&#039;&#039;&#039;Vendor&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;Product&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;Versions&#039;&#039;&#039;&lt;br /&gt;
|- &lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
 |Oracle&lt;br /&gt;
 |MySQL Community Edition, Standard Edition, Enterprise Edition&lt;br /&gt;
 |v5.6.x, v5.7.x&lt;br /&gt;
|-&lt;br /&gt;
 |MariaDB&lt;br /&gt;
 |MariaDB Server, Galera Cluster&lt;br /&gt;
 |v10.1.x, v10.2.x, v10.4.x, v10.5.x.&lt;br /&gt;
|-&lt;br /&gt;
 |Amazon&lt;br /&gt;
 |AWS RDS for MariaDB&lt;br /&gt;
 |10.2.x&amp;lt;br&amp;gt;Discontinued Support with end of life of OX App Suite v7.10.5&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Important Notes ====&lt;br /&gt;
&lt;br /&gt;
* Open-Xchange does not plan to support &#039;&#039;&#039;MySQL 8 or higher&#039;&#039;&#039;. As MariaDB and MySQL are diverging and cannot be assumed drop-in replacements anymore, Open-Xchange will focus on MariaDB Server and MariaDB Galera Cluster. Future App Suite releases &#039;&#039;&#039;&amp;gt; 7.10.x&#039;&#039;&#039; might rely on features only available in &#039;&#039;&#039;MariaDB&#039;&#039;&#039;.&lt;br /&gt;
* Open-Xchange supports &#039;&#039;&#039;Percona XtraDB Cluster&#039;&#039;&#039; for existing customers with initial deployments done using &#039;&#039;&#039;App Suite 7.8.x or earlier&#039;&#039;&#039;. Those customers can continue to use Percona XtraDB Cluster throughout the 7.10.x release series. Like for MySQL, 7.10.x supports only versions 5.6 and 5.7. It is not planned to support Percona XtraDB Cluster beyond 7.10.x.&lt;br /&gt;
&lt;br /&gt;
* For some Linux distributions the included MySQL/MariaDB packages are too old to be used with App Suite. It is mandatory then to install a supported version from &#039;&#039;&#039;upstream package sources&#039;&#039;&#039;. Possible sources are the official vendor repositories of MySQL or MariaDB as well as for example Red Hat Software Collections.&lt;br /&gt;
* Required &#039;&#039;&#039;MySQL/MariaDB configuration&#039;&#039;&#039; configuration differs between &#039;&#039;&#039;App Suite 7.8.4 and 7.10.x&#039;&#039;&#039; and also between the different database systems in terms of SQL modes. See [[My.cnf]] for details.&lt;br /&gt;
* For upgrades from App Suite &amp;lt;= 7.8.2 to &amp;gt;= 7.10.0 a comprehensive &#039;&#039;&#039;database upgrade guide&#039;&#039;&#039; exists: [[AppSuite:7_10_Database_Migration]]&lt;br /&gt;
&lt;br /&gt;
== HTTP Reverse Proxy ==&lt;br /&gt;
&lt;br /&gt;
An HTTP server with reverse proxy and load balancing capabilities is required in front of App Suite application servers. TLS termination, virtual hosts, path-based routing, sticky sessions and X-Forwarded headers are typical required features. OX strongly recommends [https://httpd.apache.org/ Apache httpd 2.x] for that. Configuration examples can be found in the quickinstall guides.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Important:&#039;&#039;&#039; For websocket support Apache httpd 2.4.x is needed, 2.2.x does not support the required ws_tunnel module. Websockets are mandatory for OX Documents starting with v7.10.3. Like with JRE and MySQL/MariaDB it might be necessary to use 3rd party packages to get the needed Linux packages. Especially for RHEL6 we recommend using Red Hat Software Collections.&lt;br /&gt;
&lt;br /&gt;
== Webserver ==&lt;br /&gt;
&lt;br /&gt;
[https://httpd.apache.org/ Apache httpd 2.x] is required as webserver to serve static App Suite UI content. Configuration examples can be found in the quickinstall guides.&lt;br /&gt;
&lt;br /&gt;
== File Storage ==&lt;br /&gt;
&lt;br /&gt;
=== Temporary Data ===&lt;br /&gt;
&lt;br /&gt;
OX App Suite stores temporary files in the local file system, e.g. for spooling of uploaded data. Any file system supported by the installed JRE is suitable.&lt;br /&gt;
&lt;br /&gt;
=== Persistent Data ===&lt;br /&gt;
&lt;br /&gt;
Persistent data like OX Drive files, PIM attachments etc. and temporary attachment data need to be stored in a distributed file system as registered filestore that is available from all server nodes. For single-node setups a local file system mount point can be used, small to mid-scale setups can be powered by NFS. For large-scale setups object storages should be considered.&lt;br /&gt;
&lt;br /&gt;
==== Object Storages ====&lt;br /&gt;
&lt;br /&gt;
OX App Suite ships with different optional adapters to support object storages.&lt;br /&gt;
&lt;br /&gt;
{|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
 |&#039;&#039;&#039;Vendor&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;Product&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;API&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;Remarks&#039;&#039;&#039;&lt;br /&gt;
|- &lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
 |Amazon&lt;br /&gt;
 |AWS S3&lt;br /&gt;
 |S3 HTTP API&lt;br /&gt;
 |See also [[AppSuite:S3_File_Store]]&lt;br /&gt;
|-&lt;br /&gt;
 |CEPH&lt;br /&gt;
 |RadosGW&lt;br /&gt;
 |S3 HTTP API&lt;br /&gt;
 |See also [[AppSuite:S3_File_Store]]&lt;br /&gt;
|-&lt;br /&gt;
 |Scality&lt;br /&gt;
 |Scality RING&lt;br /&gt;
 |Sproxyd HTTP API&lt;br /&gt;
 |See also [[AppSuite:Scality_File_Store]]&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Desktop Browser (Minimum display resolution: 1024 x 768)==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Browser&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;OX App Suite User Front-End&#039;&#039;&#039;&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |Google Chrome (latest &amp;amp; previous version)&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
 |-&lt;br /&gt;
  |Mozilla Firefox (latest &amp;amp; current ESR-Version)&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
 |-&lt;br /&gt;
  |Apple Safari (latest &amp;amp; previous version; macOS only)&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
 |-&lt;br /&gt;
  |Microsoft Edge (Chromium-based)&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
 |-&lt;br /&gt;
  |Microsoft Internet Explorer 10/11&lt;br /&gt;
  |v7.6.3&lt;br /&gt;
 |-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Mobile Device Support==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Mobile Device&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;Supported Browser&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;OX App Suite User Front-End&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;Minimum Speed Requirements&#039;&#039;&#039;&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |iPhone on iOS 14 / iOS 15 / iPad OS&lt;br /&gt;
  |Safari&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
  |3G connections (512/256kBit/s, 350ms latency)&lt;br /&gt;
 |-&lt;br /&gt;
  |Smartphone on Android 4.1 or later&lt;br /&gt;
  |Chrome (latest &amp;amp; previous version)&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
  |3G connections (512/256kBit/s, 350ms latency)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Tablet Support==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Tablet&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;Supported Browser&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;OX App Suite User Front-End&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;Minimum Speed Requirements&#039;&#039;&#039;&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |Apple iPad (all devices) on iOS 14 / iOS 15 / iPad OS&lt;br /&gt;
  |Safari&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
  |3G connections (512/256kBit/s, 350ms latency)&lt;br /&gt;
 |-&lt;br /&gt;
  |Tablets on Android 4.1 or later&lt;br /&gt;
  |Chrome (latest &amp;amp; previous version)&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
  |3G connections (512/256kBit/s, 350ms latency)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Calendar/Contact synchronization Apple macOS ==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Requirement&#039;&#039;&#039;&lt;br /&gt;
  |Calendar synchronization with CalDAV&lt;br /&gt;
  |Contacts synchronization with CardDAV&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
  |macOS 11.0 (Big Sur)&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
|-&lt;br /&gt;
  |macOS 12.0 (Monterey)&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Calendar/Contact synchronization Apple iOS ==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Requirement&#039;&#039;&#039;&lt;br /&gt;
  |Calendar synchronization with CalDAV&lt;br /&gt;
  |Contacts synchronization with CardDAV&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
  |Apple iOS 14 / iOS 15 / iPad OS&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Mobility Solution - Supported-  Platforms, Features and Devices ==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Feature/Technology/Device&#039;&#039;&#039;&lt;br /&gt;
  |[http://oxpedia.org/wiki/index.php?title=OXtender_for_Business_Mobility &#039;&#039;&#039;OXtender for Business Mobility&#039;&#039;&#039;] (availalble for App Suite, OXHE, OXSE)&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |Exchange Active Sync 2.5&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
 |-&lt;br /&gt;
  |Exchange Active Sync 12.1&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |Access and creation of emails&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
|-&lt;br /&gt;
  |Personal PIM folder&lt;br /&gt;
  |[[File:check.gif]] &lt;br /&gt;
|-&lt;br /&gt;
  |Public and Shared PIM folder&lt;br /&gt;
  |[[File:cross.gif]]&lt;br /&gt;
|-&lt;br /&gt;
  |Global address book&lt;br /&gt;
  |[[File:check.gif]] &lt;br /&gt;
|-&lt;br /&gt;
  |Push E-Mail&lt;br /&gt;
  |[[File:check.gif]] &lt;br /&gt;
|-&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |Apple iOS 14 / iOS 15 / iPad OS&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
 |-&lt;br /&gt;
  |Android 8 (Oreo) or later with latest Gmail app.&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
 |-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== OX Drive Clients ==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Requirement&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;System / Platform&#039;&#039;&#039;&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |OX Drive for Windows&lt;br /&gt;
  |OX App Suite 7.10.5, OX App Suite 7.10.6&amp;lt;br&amp;gt;Latest versions of Windows 10 (no support of macOS clients with emulators and Windows RT)&lt;br /&gt;
 |-&lt;br /&gt;
  |OX Drive for Apple macOS&lt;br /&gt;
  |OX App Suite 7.10.5, OX App Suite 7.10.6&amp;lt;br&amp;gt;macOS Big Sur 11, macOS Monterey 12, Intel- and Apple Silicon-based devices are both supported&lt;br /&gt;
 |-&lt;br /&gt;
  |OX Drive v2 for Apple iOS&lt;br /&gt;
  |OX App Suite 7.10.5, OX App Suite 7.10.6&amp;lt;br&amp;gt;iOS / iPadOS 14 and above&lt;br /&gt;
 |-&lt;br /&gt;
  |OX Drive v3 for Apple iOS&lt;br /&gt;
  |OX App Suite 7.10.6&amp;lt;br&amp;gt;iOS / iPadOS 14 and above&lt;br /&gt;
 |-&lt;br /&gt;
  |OX Drive for Android&lt;br /&gt;
  |OX App Suite 7.10.5, OX App Suite 7.10.6&amp;lt;br&amp;gt;Smartphones and tablets running Android 7.0 (API level 24) and above.&lt;br /&gt;
 |-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== OX Sync App ==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Requirement&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;System / Platform / User Interface&#039;&#039;&#039;&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |OX App Suite&lt;br /&gt;
  |OX App Suite 7.10.5, OX App Suite 7.10.6&lt;br /&gt;
 |-&lt;br /&gt;
  |OX Sync App for Android&lt;br /&gt;
  |Smartphone on Android 5.0 or later&lt;br /&gt;
 |-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== OX Guard ==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Requirement&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;System / Platform / User Interface&#039;&#039;&#039;&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |OX App Suite&lt;br /&gt;
  |OX Guard since v2.10.5: OX App Suite v7.10.5&amp;lt;br&amp;gt;OX Guard since v2.10.6: OX App Suite v7.10.6&lt;br /&gt;
 |-&lt;br /&gt;
  |Mobile Device and Tablet Support&lt;br /&gt;
  |Apple iPhone on iOS 14 / iOS 15 / iPad OS: Safari (latest version &amp;amp; previous version)&amp;lt;br&amp;gt;Smartphone on Android 4.1 or later: Chrome (latest &amp;amp; previous version)&amp;lt;br&amp;gt;Apple iPad (all devices) on iOS 14 / iOS 15 / iPad OS: Safari Safari (latest version &amp;amp; previous version)&amp;lt;br&amp;gt;Tablets on Android 4.1 or later: Chrome (latest &amp;amp; previous version)&lt;br /&gt;
 |-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: OX7]]&lt;br /&gt;
[[Category: AppSuite]]&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:ClientIdentifiers&amp;diff=26782</id>
		<title>AppSuite:ClientIdentifiers</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:ClientIdentifiers&amp;diff=26782"/>
		<updated>2022-02-11T10:51:15Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= List of App Suite client identifiers =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The tables contain the existing client identifiers (user agents) which are also collected in the OX database as &amp;quot;last used&amp;quot; entries.&lt;br /&gt;
&lt;br /&gt;
== Actively used ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|CALDAV&lt;br /&gt;
|CalDAV client access&lt;br /&gt;
|-&lt;br /&gt;
|CARDDAV&lt;br /&gt;
|CardDAV client access&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-appsuite&lt;br /&gt;
|OX App Suite web frontend&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-mobile-api-facade&lt;br /&gt;
|[[AppSuite:OX_Mail_App|OX Mail App]]&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.Android.OXDrive&lt;br /&gt;
|OX Drive for Android&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXDrive&lt;br /&gt;
|OX Drive for Microsoft Windows&lt;br /&gt;
|-&lt;br /&gt;
|OXDrive&lt;br /&gt;
|OX Drive for Microsoft Windows (faulty recording)&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.iosClient.OXDrive&lt;br /&gt;
|OX Drive for iOS (legacy)&lt;br /&gt;
|-&lt;br /&gt;
|iOS.Drive&lt;br /&gt;
|OX Drive for iOS (v3)&lt;br /&gt;
|-&lt;br /&gt;
|OSX.OXDrive&lt;br /&gt;
|OX Drive for MacOS&lt;br /&gt;
|-&lt;br /&gt;
|USM-EAS&lt;br /&gt;
|[[AppSuite:Connector_for_Business_Mobility_Installation_Guide|Connector for Business Mobility]]&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_INFOSTORE&lt;br /&gt;
|WebDAV access to Drive&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Obsolete ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|com.openexchange.ox.gui.dhtml&lt;br /&gt;
|Open-Xchange Server 6 web frontend&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXUploader&lt;br /&gt;
|[[AppSuite:OX_Outlook_Uploader|OX Uploader for Outlook]]&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.olox1&lt;br /&gt;
|OX Connector for Outlook&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.olox2&lt;br /&gt;
|OX Connector 2 for Outlook&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-mailapp&lt;br /&gt;
|Legacy OX Mail App (v1)&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXNotifier&lt;br /&gt;
|OX Notifier for Microsoft Windows&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.OXNotifier&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|USM-JSON&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OUTLOOK_UPDATER&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|com.openexchange.mobileapp&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|ox.mobileapp&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|DRIVE_UPDATER&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_XML&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXAddIn&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_VCARD&lt;br /&gt;
|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:OX_System_Requirements&amp;diff=26770</id>
		<title>AppSuite:OX System Requirements</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:OX_System_Requirements&amp;diff=26770"/>
		<updated>2022-02-09T12:10:40Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: /* Databases */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= OX App Suite Requirements - Open-Xchange supported components overview =&lt;br /&gt;
&lt;br /&gt;
The following table provides an overview about the supported components of OX App Suite and further products. This overview makes no claim to be complete.&lt;br /&gt;
&lt;br /&gt;
Information about Maintenance expiries of components, versions and browser support, can be found in the [[AppSuite:Versioning_and_Numbering#Maintenance_expires|Maintenance Expires Table]]&lt;br /&gt;
&lt;br /&gt;
== Hardware Requirements ==&lt;br /&gt;
&lt;br /&gt;
=== General Assumptions ===&lt;br /&gt;
&lt;br /&gt;
Open-Xchange App Suite Server (middleware services) is designed to run on physical servers or virtual machines of the same flavor. Cloud environments might be used in terms of Infrastructure as a Service (IaaS), meaning that all components need to be deployed in a classical manner on virtual machines.&lt;br /&gt;
&lt;br /&gt;
This means in particular, but not only:&lt;br /&gt;
&lt;br /&gt;
* Infrastructure is supposed to be &amp;quot;quasi-static&amp;quot;. Automatic replacement of broken nodes is fine as long as this is always an exceptional case. Scaling out or reducing number of nodes must always be a conscious task and closely monitored.&lt;br /&gt;
* The only supported &amp;quot;Database as a service&amp;quot; solution is AWS RDS for MariaDB as defined by belows compatibility table.&lt;br /&gt;
&lt;br /&gt;
Especially we expect the virtual hardware to be not over-provisioned. Each VM must have dedicated resources with respect to CPU cores, RAM, IOPS, storage, network bandwidth, network latency, etc.&lt;br /&gt;
&lt;br /&gt;
Network is expected to be flat, inside one datacenter, no multi-datacenter, no segments. No packet loss, low latency.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Disclaimer: All recommendations below are without guarantee and can differ for specific deployments. For mid- and large-scale setups a detailed deployment planning and sizing tests are mandatory and should be agreed on with OX Professional Services.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== High Level Design / OS setup ===&lt;br /&gt;
&lt;br /&gt;
Operate services separately (USM, Document/Image Converters) as described in [https://oxpedia.org/wiki/index.php?title=AppSuite:Running_a_cluster Cluster Setup].&lt;br /&gt;
&lt;br /&gt;
Clocks between all nodes must be synchronized (e.g. via NTP).&lt;br /&gt;
&lt;br /&gt;
Open file/max process limits need to be adjusted properly. Based on the used Linux distribution and init system configuration will differ, see Resource Limits for further explanation.&lt;br /&gt;
&lt;br /&gt;
Platform Architecture: 64 bit versions (x84_64) of the supported [[#Software Requirements | Linux distributions]]&lt;br /&gt;
&lt;br /&gt;
=== Node Sizing ===&lt;br /&gt;
&lt;br /&gt;
==== OX App Suite Middleware ====&lt;br /&gt;
&lt;br /&gt;
* Max. 8 GB heap per JVM + 4 GB system memory for other daemons and the OS (buffers, caches)&lt;br /&gt;
* 4 CPU cores (virtual, physical or hyperthreads) for plain HTTP connections. If TLS is terminated on application nodes this might need to be doubled.&lt;br /&gt;
* Disk space&lt;br /&gt;
** 8 GB for OS and software&lt;br /&gt;
** Some services like Document Converter need SWAP partitions (~1 * RAM)&lt;br /&gt;
** 2 * system memory of free disk space (i.e. 12 GB RAM =&amp;gt; 24 GB free disk space) for file spooling, log files, heap and core dumps&lt;br /&gt;
&lt;br /&gt;
=== Untested/Unsupported Deployments ===&lt;br /&gt;
&lt;br /&gt;
* Changes to Garbage Collector settings&lt;br /&gt;
* Running in containerized environments (Docker, rkt)&lt;br /&gt;
* Elasticity/High velocity of nodes going up and down: Services are sometimes stateful and demand static configuration&lt;br /&gt;
* Cloud platform services (PaaS) that promise to replacements for certain supported technologies but have not been verified by OX for these regards&lt;br /&gt;
* Multi-site active-active&lt;br /&gt;
&lt;br /&gt;
== Software Requirements ==&lt;br /&gt;
&lt;br /&gt;
=== Linux Distributions ===&lt;br /&gt;
&lt;br /&gt;
OX App Suite is available as Linux packages for the following distributions:&lt;br /&gt;
&lt;br /&gt;
{|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
 |&#039;&#039;&#039;Distribution&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;Versions&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;Remarks&#039;&#039;&#039;&lt;br /&gt;
|- &lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
 |Red Hat Enterprise Linux&lt;br /&gt;
 |7&lt;br /&gt;
 |&lt;br /&gt;
|-&lt;br /&gt;
 |CentOS&lt;br /&gt;
 |7&lt;br /&gt;
 |Install from RHEL package repositories&lt;br /&gt;
|-&lt;br /&gt;
 |Debian&lt;br /&gt;
 |9 (Stretch), 10 (Buster)&lt;br /&gt;
 |&lt;br /&gt;
|-&lt;br /&gt;
 |Univention Corporate Server&lt;br /&gt;
 |4.4, 5.0&lt;br /&gt;
 |&lt;br /&gt;
|-&lt;br /&gt;
 |Amazon Linux&lt;br /&gt;
 |2&lt;br /&gt;
 |Discontinued Support with end of life of OX App Suite v7.10.5&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Java ===&lt;br /&gt;
&lt;br /&gt;
OX App Suite Middleware requires OpenJDK headless JRE 8 or 9. Linux distributions might offer only packages for OpenJDK 11 JRE, which is not suitable for OX App Suite. It is in those cases required to install AdoptOpenJDK 8 JRE with HotSpot VM. A comprehensive installation guide can be found at https://adoptopenjdk.net/installation.html#linux-pkg. The correct JRE package is adoptopenjdk-8-hotspot-jre.&lt;br /&gt;
&lt;br /&gt;
=== Databases ===&lt;br /&gt;
&lt;br /&gt;
OX App Suite uses MySQL/MariaDB with the InnoDB storage engine as its primary data store. The following vendors and products are supported.&lt;br /&gt;
&lt;br /&gt;
{|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
 |&#039;&#039;&#039;Vendor&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;Product&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;Versions&#039;&#039;&#039;&lt;br /&gt;
|- &lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
 |Oracle&lt;br /&gt;
 |MySQL Community Edition, Standard Edition, Enterprise Edition&lt;br /&gt;
 |v5.6.x, v5.7.x&lt;br /&gt;
|-&lt;br /&gt;
 |MariaDB&lt;br /&gt;
 |MariaDB Server, Galera Cluster&lt;br /&gt;
 |v10.1.x, v10.2.x, v10.4.x, v10.5.x.&lt;br /&gt;
|-&lt;br /&gt;
 |Amazon&lt;br /&gt;
 |AWS RDS for MariaDB&lt;br /&gt;
 |10.2.x&amp;lt;br&amp;gt;Discontinued Support with end of life of OX App Suite v7.10.5&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Important Notes ====&lt;br /&gt;
&lt;br /&gt;
* Open-Xchange does not plan to support &#039;&#039;&#039;MySQL 8 or higher&#039;&#039;&#039;. As MariaDB and MySQL are diverging and cannot be assumed drop-in replacements anymore, Open-Xchange will focus on MariaDB Server and MariaDB Galera Cluster. Future App Suite releases &#039;&#039;&#039;&amp;gt; 7.10.x&#039;&#039;&#039; might rely on features only available in &#039;&#039;&#039;MariaDB&#039;&#039;&#039;.&lt;br /&gt;
* Open-Xchange supports &#039;&#039;&#039;Percona XtraDB Cluster&#039;&#039;&#039; for existing customers with initial deployments done using &#039;&#039;&#039;App Suite 7.8.x or earlier&#039;&#039;&#039;. Those customers can continue to use Percona XtraDB Cluster throughout the 7.10.x release series. Like for MySQL, 7.10.x supports only versions 5.6 and 5.7. It is not planned to support Percona XtraDB Cluster beyond 7.10.x.&lt;br /&gt;
&lt;br /&gt;
* For some Linux distributions the included MySQL/MariaDB packages are too old to be used with App Suite. It is mandatory then to install a supported version from &#039;&#039;&#039;upstream package sources&#039;&#039;&#039;. Possible sources are the official vendor repositories of MySQL or MariaDB as well as for example Red Hat Software Collections.&lt;br /&gt;
* Required &#039;&#039;&#039;MySQL/MariaDB configuration&#039;&#039;&#039; configuration differs between &#039;&#039;&#039;App Suite 7.8.4 and 7.10.x&#039;&#039;&#039; and also between the different database systems in terms of SQL modes. See [[My.cnf]] for details.&lt;br /&gt;
* For upgrades from App Suite &amp;lt;= 7.8.2 to &amp;gt;= 7.10.0 a comprehensive &#039;&#039;&#039;database upgrade guide&#039;&#039;&#039; exists: [[AppSuite:7_10_Database_Migration]]&lt;br /&gt;
&lt;br /&gt;
== HTTP Reverse Proxy ==&lt;br /&gt;
&lt;br /&gt;
An HTTP server with reverse proxy and load balancing capabilities is required in front of App Suite application servers. TLS termination, virtual hosts, path-based routing, sticky sessions and X-Forwarded headers are typical required features. OX strongly recommends [https://httpd.apache.org/ Apache httpd 2.x] for that. Configuration examples can be found in the quickinstall guides.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Important:&#039;&#039;&#039; For websocket support Apache httpd 2.4.x is needed, 2.2.x does not support the required ws_tunnel module. Websockets are mandatory for OX Documents starting with v7.10.3. Like with JRE and MySQL/MariaDB it might be necessary to use 3rd party packages to get the needed Linux packages. Especially for RHEL6 we recommend using Red Hat Software Collections.&lt;br /&gt;
&lt;br /&gt;
== Webserver ==&lt;br /&gt;
&lt;br /&gt;
[https://httpd.apache.org/ Apache httpd 2.x] is required as webserver to serve static App Suite UI content. Configuration examples can be found in the quickinstall guides.&lt;br /&gt;
&lt;br /&gt;
== File Storage ==&lt;br /&gt;
&lt;br /&gt;
=== Temporary Data ===&lt;br /&gt;
&lt;br /&gt;
OX App Suite stores temporary files in the local file system, e.g. for spooling of uploaded data. Any file system supported by the installed JRE is suitable.&lt;br /&gt;
&lt;br /&gt;
=== Persistent Data ===&lt;br /&gt;
&lt;br /&gt;
Persistent data like OX Drive files, PIM attachments etc. and temporary attachment data need to be stored in a distributed file system as registered filestore that is available from all server nodes. For single-node setups a local file system mount point can be used, small to mid-scale setups can be powered by NFS. For large-scale setups object storages should be considered.&lt;br /&gt;
&lt;br /&gt;
==== Object Storages ====&lt;br /&gt;
&lt;br /&gt;
OX App Suite ships with different optional adapters to support object storages.&lt;br /&gt;
&lt;br /&gt;
{|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
 |&#039;&#039;&#039;Vendor&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;Product&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;API&#039;&#039;&#039;&lt;br /&gt;
 |&#039;&#039;&#039;Remarks&#039;&#039;&#039;&lt;br /&gt;
|- &lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
 |&amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
 |Amazon&lt;br /&gt;
 |AWS S3&lt;br /&gt;
 |S3 HTTP API&lt;br /&gt;
 |See also [[AppSuite:S3_File_Store]]&lt;br /&gt;
|-&lt;br /&gt;
 |CEPH&lt;br /&gt;
 |RadosGW&lt;br /&gt;
 |S3 HTTP API&lt;br /&gt;
 |See also [[AppSuite:S3_File_Store]]&lt;br /&gt;
|-&lt;br /&gt;
 |Scality&lt;br /&gt;
 |Scality RING&lt;br /&gt;
 |Sproxyd HTTP API&lt;br /&gt;
 |See also [[AppSuite:Scality_File_Store]]&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Desktop Browser (Minimum display resolution: 1024 x 768)==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Browser&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;OX App Suite User Front-End&#039;&#039;&#039;&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |Google Chrome (latest &amp;amp; previous version)&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
 |-&lt;br /&gt;
  |Mozilla Firefox (latest &amp;amp; current ESR-Version)&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
 |-&lt;br /&gt;
  |Apple Safari (latest &amp;amp; previous version; macOS only)&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
 |-&lt;br /&gt;
  |Microsoft Edge (Chromium-based)&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
 |-&lt;br /&gt;
  |Microsoft Internet Explorer 10/11&lt;br /&gt;
  |v7.6.3&lt;br /&gt;
 |-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Mobile Device Support==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Mobile Device&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;Supported Browser&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;OX App Suite User Front-End&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;Minimum Speed Requirements&#039;&#039;&#039;&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |iPhone on iOS 14 / iOS 15 / iPad OS&lt;br /&gt;
  |Safari&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
  |3G connections (512/256kBit/s, 350ms latency)&lt;br /&gt;
 |-&lt;br /&gt;
  |Smartphone on Android 4.1 or later&lt;br /&gt;
  |Chrome (latest &amp;amp; previous version)&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
  |3G connections (512/256kBit/s, 350ms latency)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Tablet Support==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Tablet&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;Supported Browser&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;OX App Suite User Front-End&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;Minimum Speed Requirements&#039;&#039;&#039;&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |Apple iPad (all devices) on iOS 14 / iOS 15 / iPad OS&lt;br /&gt;
  |Safari&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
  |3G connections (512/256kBit/s, 350ms latency)&lt;br /&gt;
 |-&lt;br /&gt;
  |Tablets on Android 4.1 or later&lt;br /&gt;
  |Chrome (latest &amp;amp; previous version)&lt;br /&gt;
  |v7.10.5, v7.10.6&lt;br /&gt;
  |3G connections (512/256kBit/s, 350ms latency)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Calendar/Contact synchronization Apple macOS ==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Requirement&#039;&#039;&#039;&lt;br /&gt;
  |Calendar synchronization with CalDAV&lt;br /&gt;
  |Contacts synchronization with CardDAV&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
  |macOS 11.0 (Big Sur)&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
|-&lt;br /&gt;
  |macOS 12.0 (Monterey)&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Calendar/Contact synchronization Apple iOS ==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Requirement&#039;&#039;&#039;&lt;br /&gt;
  |Calendar synchronization with CalDAV&lt;br /&gt;
  |Contacts synchronization with CardDAV&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
  |Apple iOS 14 / iOS 15 / iPad OS&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Mobility Solution - Supported-  Platforms, Features and Devices ==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Feature/Technology/Device&#039;&#039;&#039;&lt;br /&gt;
  |[http://oxpedia.org/wiki/index.php?title=OXtender_for_Business_Mobility &#039;&#039;&#039;OXtender for Business Mobility&#039;&#039;&#039;] (availalble for App Suite, OXHE, OXSE)&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |Exchange Active Sync 2.5&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
 |-&lt;br /&gt;
  |Exchange Active Sync 12.1&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |Access and creation of emails&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
|-&lt;br /&gt;
  |Personal PIM folder&lt;br /&gt;
  |[[File:check.gif]] &lt;br /&gt;
|-&lt;br /&gt;
  |Public and Shared PIM folder&lt;br /&gt;
  |[[File:cross.gif]]&lt;br /&gt;
|-&lt;br /&gt;
  |Global address book&lt;br /&gt;
  |[[File:check.gif]] &lt;br /&gt;
|-&lt;br /&gt;
  |Push E-Mail&lt;br /&gt;
  |[[File:check.gif]] &lt;br /&gt;
|-&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |Apple iOS 14 / iOS 15 / iPad OS&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
 |-&lt;br /&gt;
  |Android 8 (Oreo) or later with latest Gmail app.&lt;br /&gt;
  |[[File:check.gif]]&lt;br /&gt;
 |-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== OX Drive Clients ==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Requirement&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;System / Platform&#039;&#039;&#039;&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |OX Drive for Windows&lt;br /&gt;
  |OX App Suite 7.10.5, OX App Suite 7.10.6&amp;lt;br&amp;gt;Latest versions of Windows 10 (no support of macOS clients with emulators and Windows RT)&lt;br /&gt;
 |-&lt;br /&gt;
  |OX Drive for Apple macOS&lt;br /&gt;
  |OX App Suite 7.10.5, OX App Suite 7.10.6&amp;lt;br&amp;gt;macOS Big Sur 11, macOS Monterey 12, Intel- and Apple Silicon-based devices are both supported&lt;br /&gt;
 |-&lt;br /&gt;
  |OX Drive v2 for Apple iOS&lt;br /&gt;
  |OX App Suite 7.10.5, OX App Suite 7.10.6&amp;lt;br&amp;gt;iOS / iPadOS 14 and above&lt;br /&gt;
 |-&lt;br /&gt;
  |OX Drive v3 for Apple iOS&lt;br /&gt;
  |OX App Suite 7.10.6&amp;lt;br&amp;gt;iOS / iPadOS 14 and above&lt;br /&gt;
 |-&lt;br /&gt;
  |OX Drive for Android&lt;br /&gt;
  |OX App Suite 7.10.5, OX App Suite 7.10.6&amp;lt;br&amp;gt;Smartphones and tablets running Android 7.0 (API level 24) and above.&lt;br /&gt;
 |-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== OX Sync App ==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Requirement&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;System / Platform / User Interface&#039;&#039;&#039;&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |OX App Suite&lt;br /&gt;
  |OX App Suite 7.10.5, OX App Suite 7.10.6&lt;br /&gt;
 |-&lt;br /&gt;
  |OX Sync App for Android&lt;br /&gt;
  |Smartphone on Android 5.0 or later&lt;br /&gt;
 |-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== OX Guard ==&lt;br /&gt;
&lt;br /&gt;
 {|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
  |&#039;&#039;&#039;Requirement&#039;&#039;&#039;&lt;br /&gt;
  |&#039;&#039;&#039;System / Platform / User Interface&#039;&#039;&#039;&lt;br /&gt;
 |- &lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
  |&amp;amp;nbsp;&lt;br /&gt;
 |-&lt;br /&gt;
  |OX App Suite&lt;br /&gt;
  |OX Guard since v2.10.5: OX App Suite v7.10.5&amp;lt;br&amp;gt;OX Guard since v2.10.6: OX App Suite v7.10.6&lt;br /&gt;
 |-&lt;br /&gt;
  |Mobile Device and Tablet Support&lt;br /&gt;
  |Apple iPhone on iOS 14 / iOS 15 / iPad OS: Safari (latest version &amp;amp; previous version)&amp;lt;br&amp;gt;Smartphone on Android 4.1 or later: Chrome (latest &amp;amp; previous version)&amp;lt;br&amp;gt;Apple iPad (all devices) on iOS 14 / iOS 15 / iPad OS: Safari Safari (latest version &amp;amp; previous version)&amp;lt;br&amp;gt;Tablets on Android 4.1 or later: Chrome (latest &amp;amp; previous version)&lt;br /&gt;
 |-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: OX7]]&lt;br /&gt;
[[Category: AppSuite]]&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:ClientIdentifiers&amp;diff=26764</id>
		<title>AppSuite:ClientIdentifiers</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:ClientIdentifiers&amp;diff=26764"/>
		<updated>2022-02-08T14:53:05Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= List of App Suite client identifiers =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The tables contain the existing client identifiers (user agents) which are also collected in the OX database as &amp;quot;last used&amp;quot; entries.&lt;br /&gt;
&lt;br /&gt;
== Actively used ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|CALDAV&lt;br /&gt;
|CalDAV client access&lt;br /&gt;
|-&lt;br /&gt;
|CARDDAV&lt;br /&gt;
|CardDAV client access&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-appsuite&lt;br /&gt;
|OX App Suite web frontend&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-mobile-api-facade&lt;br /&gt;
|[[AppSuite:OX_Mail_App|OX Mail App]]&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.Android.OXDrive&lt;br /&gt;
|OX Drive for Android&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXDrive&lt;br /&gt;
|OX Drive for Microsoft Windows&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.iosClient.OXDrive&lt;br /&gt;
|OX Drive for iOS (legacy)&lt;br /&gt;
|-&lt;br /&gt;
|iOS.Drive&lt;br /&gt;
|OX Drive for iOS (v3)&lt;br /&gt;
|-&lt;br /&gt;
|OSX.OXDrive&lt;br /&gt;
|OX Drive for MacOS&lt;br /&gt;
|-&lt;br /&gt;
|OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|USM-EAS&lt;br /&gt;
|[[AppSuite:Connector_for_Business_Mobility_Installation_Guide|Connector for Business Mobility]]&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_INFOSTORE&lt;br /&gt;
|WebDAV access to Drive&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Obsolete ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|com.openexchange.ox.gui.dhtml&lt;br /&gt;
|Open-Xchange Server 6 web frontend&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXUploader&lt;br /&gt;
|[[AppSuite:OX_Outlook_Uploader|OX Uploader for Outlook]]&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.olox1&lt;br /&gt;
|OX Connector for Outlook&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.olox2&lt;br /&gt;
|OX Connector 2 for Outlook&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-mailapp&lt;br /&gt;
|Legacy OX Mail App (v1)&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXNotifier&lt;br /&gt;
|OX Notifier for Microsoft Windows&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.OXNotifier&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|USM-JSON&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OUTLOOK_UPDATER&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|com.openexchange.mobileapp&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|ox.mobileapp&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|DRIVE_UPDATER&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_XML&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXAddIn&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_VCARD&lt;br /&gt;
|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:ClientIdentifiers&amp;diff=26761</id>
		<title>AppSuite:ClientIdentifiers</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:ClientIdentifiers&amp;diff=26761"/>
		<updated>2022-02-08T14:52:48Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= List of App Suite client identifiers =&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;pre style=&amp;quot;color: red&amp;quot;&amp;gt;This page is under construction!&amp;lt;/pre&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
The tables contain the existing client identifiers (user agents) which are also collected in the OX database as &amp;quot;last used&amp;quot; entries.&lt;br /&gt;
&lt;br /&gt;
== Actively used ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|CALDAV&lt;br /&gt;
|CalDAV client access&lt;br /&gt;
|-&lt;br /&gt;
|CARDDAV&lt;br /&gt;
|CardDAV client access&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-appsuite&lt;br /&gt;
|OX App Suite web frontend&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-mobile-api-facade&lt;br /&gt;
|[[AppSuite:OX_Mail_App|OX Mail App]]&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.Android.OXDrive&lt;br /&gt;
|OX Drive for Android&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXDrive&lt;br /&gt;
|OX Drive for Microsoft Windows&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.iosClient.OXDrive&lt;br /&gt;
|OX Drive for iOS (legacy)&lt;br /&gt;
|-&lt;br /&gt;
|iOS.Drive&lt;br /&gt;
|OX Drive for iOS (v3)&lt;br /&gt;
|-&lt;br /&gt;
|OSX.OXDrive&lt;br /&gt;
|OX Drive for MacOS&lt;br /&gt;
|-&lt;br /&gt;
|OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|USM-EAS&lt;br /&gt;
|[[AppSuite:Connector_for_Business_Mobility_Installation_Guide|Connector for Business Mobility]]&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_INFOSTORE&lt;br /&gt;
|WebDAV access to Drive&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Obsolete ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|com.openexchange.ox.gui.dhtml&lt;br /&gt;
|Open-Xchange Server 6 web frontend&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXUploader&lt;br /&gt;
|[[AppSuite:OX_Outlook_Uploader|OX Uploader for Outlook]]&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.olox1&lt;br /&gt;
|OX Connector for Outlook&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.olox2&lt;br /&gt;
|OX Connector 2 for Outlook&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-mailapp&lt;br /&gt;
|Legacy OX Mail App (v1)&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXNotifier&lt;br /&gt;
|OX Notifier for Microsoft Windows&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.OXNotifier&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|USM-JSON&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OUTLOOK_UPDATER&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|com.openexchange.mobileapp&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|ox.mobileapp&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|DRIVE_UPDATER&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_XML&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXAddIn&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_VCARD&lt;br /&gt;
|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:ClientIdentifiers&amp;diff=26758</id>
		<title>AppSuite:ClientIdentifiers</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:ClientIdentifiers&amp;diff=26758"/>
		<updated>2022-02-08T14:52:16Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= List of App Suite client identifiers =&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;pre style=&amp;quot;color: red&amp;quot;&amp;gt;This page is under construction!&amp;lt;/pre&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
The tables contain the existing client identifiers (user agents) which are also collected in the OX database as &amp;quot;last used&amp;quot; entries.&lt;br /&gt;
&lt;br /&gt;
== Actively used ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|CALDAV&lt;br /&gt;
|CalDAV client access&lt;br /&gt;
|-&lt;br /&gt;
|CARDDAV&lt;br /&gt;
|CardDAV client access&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-appsuite&lt;br /&gt;
|OX App Suite web frontend&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-mobile-api-facade&lt;br /&gt;
|[[AppSuite:OX_Mail_App|OX Mail App]]&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.Android.OXDrive&lt;br /&gt;
|OX Drive for Android&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXDrive&lt;br /&gt;
|OX Drive for Microsoft Windows&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.iosClient.OXDrive&lt;br /&gt;
|OX Drive for iOS (legacy)&lt;br /&gt;
|-&lt;br /&gt;
|iOS.Drive&lt;br /&gt;
|OX Drive for iOS (v3)&lt;br /&gt;
|-&lt;br /&gt;
|OSX.OXDrive&lt;br /&gt;
|OX Drive for MacOS&lt;br /&gt;
|-&lt;br /&gt;
|OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|USM-EAS&lt;br /&gt;
|[[AppSuite:Connector_for_Business_Mobility_Installation_Guide|Connector for Business Mobility]]&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_INFOSTORE&lt;br /&gt;
|WebDAV access to Drive&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXUploader&lt;br /&gt;
|[[AppSuite:OX_Outlook_Uploader|OX Uploader for Outlook]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Obsolete ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|com.openexchange.ox.gui.dhtml&lt;br /&gt;
|Open-Xchange Server 6 web frontend&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.olox1&lt;br /&gt;
|OX Connector for Outlook&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.olox2&lt;br /&gt;
|OX Connector 2 for Outlook&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-mailapp&lt;br /&gt;
|Legacy OX Mail App (v1)&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXNotifier&lt;br /&gt;
|OX Notifier for Microsoft Windows&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.OXNotifier&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|USM-JSON&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OUTLOOK_UPDATER&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|com.openexchange.mobileapp&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|ox.mobileapp&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|DRIVE_UPDATER&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_XML&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXAddIn&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_VCARD&lt;br /&gt;
|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:ClientIdentifiers&amp;diff=26707</id>
		<title>AppSuite:ClientIdentifiers</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:ClientIdentifiers&amp;diff=26707"/>
		<updated>2022-01-25T15:49:15Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= List of App Suite client identifiers =&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;pre style=&amp;quot;color: red&amp;quot;&amp;gt;This page is under construction!&amp;lt;/pre&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
The tables contain the existing client identifiers (user agents) which are also collected in the OX database as &amp;quot;last used&amp;quot; entries.&lt;br /&gt;
&lt;br /&gt;
== Actively used ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|CALDAV&lt;br /&gt;
|CalDAV client access&lt;br /&gt;
|-&lt;br /&gt;
|CARDDAV&lt;br /&gt;
|CardDAV client access&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-appsuite&lt;br /&gt;
|OX App Suite web frontend&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-mobile-api-facade&lt;br /&gt;
|[[AppSuite:OX_Mail_App|OX Mail App]]&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.Android.OXDrive&lt;br /&gt;
|OX Drive for Android&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXDrive&lt;br /&gt;
|OX Drive for Microsoft Windows&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.iosClient.OXDrive&lt;br /&gt;
|OX Drive for iOS (legacy)&lt;br /&gt;
|-&lt;br /&gt;
|iOS.Drive&lt;br /&gt;
|OX Drive for iOS (v3)&lt;br /&gt;
|-&lt;br /&gt;
|OSX.OXDrive&lt;br /&gt;
|OX Drive for MacOS&lt;br /&gt;
|-&lt;br /&gt;
|OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|USM-EAS&lt;br /&gt;
|[[AppSuite:Connector_for_Business_Mobility_Installation_Guide|Connector for Business Mobility]]&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_INFOSTORE&lt;br /&gt;
|WebDAV access to Drive&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_VCARD&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXUploader&lt;br /&gt;
|[[AppSuite:OX_Outlook_Uploader|OX Uploader for Outlook]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Obsolete ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|com.openexchange.ox.gui.dhtml&lt;br /&gt;
|Open-Xchange Server 6 web frontend&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.olox1&lt;br /&gt;
|OX Connector for Outlook&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.olox2&lt;br /&gt;
|OX Connector 2 for Outlook&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-mailapp&lt;br /&gt;
|Legacy OX Mail App (v1)&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXNotifier&lt;br /&gt;
|OX Notifier for Microsoft Windows&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.OXNotifier&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|USM-JSON&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OUTLOOK_UPDATER&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|com.openexchange.mobileapp&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|ox.mobileapp&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|DRIVE_UPDATER&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_XML&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXAddIn&lt;br /&gt;
|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:ClientIdentifiers&amp;diff=26704</id>
		<title>AppSuite:ClientIdentifiers</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:ClientIdentifiers&amp;diff=26704"/>
		<updated>2022-01-25T15:48:02Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= List of App Suite client identifiers =&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;pre style=&amp;quot;color: red&amp;quot;&amp;gt;This page is under construction!&amp;lt;/pre&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
The tables contain the existing client identifiers (user agents) which are also collected in the OX database as &amp;quot;last used&amp;quot; entries.&lt;br /&gt;
&lt;br /&gt;
== Actively used ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|CALDAV&lt;br /&gt;
|CalDAV client access&lt;br /&gt;
|-&lt;br /&gt;
|CARDDAV&lt;br /&gt;
|CardDAV client access&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-appsuite&lt;br /&gt;
|OX App Suite web frontend&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-mobile-api-facade&lt;br /&gt;
|[[AppSuite:OX_Mail_App|OX Mail App]]&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.Android.OXDrive&lt;br /&gt;
|OX Drive for Android&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXDrive&lt;br /&gt;
|OX Drive for Microsoft Windows&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXUploader&lt;br /&gt;
|[[AppSuite:OX_Outlook_Uploader|OX Uploader for Outlook]]&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.iosClient.OXDrive&lt;br /&gt;
|OX Drive for iOS (legacy)&lt;br /&gt;
|-&lt;br /&gt;
|iOS.Drive&lt;br /&gt;
|OX Drive for iOS (v3)&lt;br /&gt;
|-&lt;br /&gt;
|OSX.OXDrive&lt;br /&gt;
|OX Drive for MacOS&lt;br /&gt;
|-&lt;br /&gt;
|OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|USM-EAS&lt;br /&gt;
|[[AppSuite:Connector_for_Business_Mobility_Installation_Guide|Connector for Business Mobility]]&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_INFOSTORE&lt;br /&gt;
|WebDAV access to Drive&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_VCARD&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Obsolete ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|com.openexchange.ox.gui.dhtml&lt;br /&gt;
|Open-Xchange Server 6 web frontend&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.olox1&lt;br /&gt;
|OX Connector for Outlook&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.olox2&lt;br /&gt;
|OX Connector 2 for Outlook&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-mailapp&lt;br /&gt;
|Legacy OX Mail App (v1)&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXNotifier&lt;br /&gt;
|OX Notifier for Microsoft Windows&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.OXNotifier&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|USM-JSON&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OUTLOOK_UPDATER&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|com.openexchange.mobileapp&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|ox.mobileapp&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|DRIVE_UPDATER&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_XML&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXAddIn&lt;br /&gt;
|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:ClientIdentifiers&amp;diff=26701</id>
		<title>AppSuite:ClientIdentifiers</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:ClientIdentifiers&amp;diff=26701"/>
		<updated>2022-01-25T15:36:04Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= List of App Suite client identifiers =&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;pre style=&amp;quot;color: red&amp;quot;&amp;gt;This page is under construction!&amp;lt;/pre&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
The tables contain the existing client identifiers (user agents) which are also collected in the OX database as &amp;quot;last used&amp;quot; entries.&lt;br /&gt;
&lt;br /&gt;
== Actively used ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|CALDAV&lt;br /&gt;
|CalDAV client access&lt;br /&gt;
|-&lt;br /&gt;
|CARDDAV&lt;br /&gt;
|CardDAV client access&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-appsuite&lt;br /&gt;
|OX App Suite web frontend&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-mobile-api-facade&lt;br /&gt;
|[[AppSuite:OX_Mail_App|OX Mail App]]&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.Android.OXDrive&lt;br /&gt;
|OX Drive for Android&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXAddIn&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXUploader&lt;br /&gt;
|[[AppSuite:OX_Outlook_Uploader|OX Uploader for Outlook]]&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.iosClient.OXDrive&lt;br /&gt;
|OX Drive for iOS&lt;br /&gt;
|-&lt;br /&gt;
|OSX.OXDrive&lt;br /&gt;
|OX Drive for MacOS&lt;br /&gt;
|-&lt;br /&gt;
|OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|USM-EAS&lt;br /&gt;
|[[AppSuite:Connector_for_Business_Mobility_Installation_Guide|Connector for Business Mobility]]&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_INFOSTORE&lt;br /&gt;
|WebDAV access to Drive&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_VCARD&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Obsolete ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|com.openexchange.ox.gui.dhtml&lt;br /&gt;
|Open-Xchange Server 6 web frontend&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.olox1&lt;br /&gt;
|OX Connector for Outlook&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.olox2&lt;br /&gt;
|OX Connector 2 for Outlook&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-mailapp&lt;br /&gt;
|Legacy OX Mail App (v1)&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXNotifier&lt;br /&gt;
|OX Notifier for Microsoft Windows&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.OXNotifier&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|USM-JSON&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OUTLOOK_UPDATER&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|com.openexchange.mobileapp&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|ox.mobileapp&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|DRIVE_UPDATER&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_XML&lt;br /&gt;
|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:ClientIdentifiers&amp;diff=26698</id>
		<title>AppSuite:ClientIdentifiers</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:ClientIdentifiers&amp;diff=26698"/>
		<updated>2022-01-25T13:46:08Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= List of App Suite client identifiers =&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;pre style=&amp;quot;color: red&amp;quot;&amp;gt;This page is under construction!&amp;lt;/pre&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
The tables contain the existing client identifiers (user agents) which are also collected in the OX database as &amp;quot;last used&amp;quot; entries.&lt;br /&gt;
&lt;br /&gt;
== Actively used ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|CALDAV&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|CARDDAV&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|DRIVE_UPDATER&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-appsuite&lt;br /&gt;
|OX App Suite web frontend&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-mobile-api-facade&lt;br /&gt;
|[[AppSuite:OX_Mail_App|OX Mail App]]&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.Android.OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXAddIn&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXUploader&lt;br /&gt;
|[[AppSuite:OX_Outlook_Uploader|OX Uploader for Outlook]]&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.iosClient.OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OSX.OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|USM-EAS&lt;br /&gt;
|[[AppSuite:Connector_for_Business_Mobility_Installation_Guide|Connector for Business Mobility]]&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_INFOSTORE&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_VCARD&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_XML&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Obsolete ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|com.openexchange.ox.gui.dhtml&lt;br /&gt;
|Open-Xchange Server 6 web frontend&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.olox1&lt;br /&gt;
|OX Connector for Outlook&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.olox2&lt;br /&gt;
|OX Connector 2 for Outlook&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-mailapp&lt;br /&gt;
|Legacy OX Mail App (v1)&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXNotifier&lt;br /&gt;
|OX Notifier for Microsoft Windows&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.OXNotifier&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|USM-JSON&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OUTLOOK_UPDATER&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|com.openexchange.mobileapp&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|ox.mobileapp&lt;br /&gt;
|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:ClientIdentifiers&amp;diff=26683</id>
		<title>AppSuite:ClientIdentifiers</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:ClientIdentifiers&amp;diff=26683"/>
		<updated>2022-01-25T08:31:11Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= List of App Suite client identifiers =&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;pre style=&amp;quot;color: red&amp;quot;&amp;gt;This page is under construction!&amp;lt;/pre&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
The tables contain the existing client identifiers (user agents) which are also collected in the OX database as &amp;quot;last used&amp;quot; entries.&lt;br /&gt;
&lt;br /&gt;
== Actively used ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|CALDAV&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|CARDDAV&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|DRIVE_UPDATER&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-appsuite&lt;br /&gt;
|OX App Suite web frontend&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-mobile-api-facade&lt;br /&gt;
|[[AppSuite:OX_Mail_App|OX Mail App]]&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.Android.OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXAddIn&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXUploader&lt;br /&gt;
|[[AppSuite:OX_Outlook_Uploader|OX Uploader for Outlook]]&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.iosClient.OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OSX.OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|USM-EAS&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_INFOSTORE&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_VCARD&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_XML&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Obsolete ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|com.openexchange.ox.gui.dhtml&lt;br /&gt;
|Open-Xchange Server 6 web frontend&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.olox1&lt;br /&gt;
|OX Connector for Outlook&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.olox2&lt;br /&gt;
|OX Connector 2 for Outlook&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-mailapp&lt;br /&gt;
|Legacy OX Mail App (v1)&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXNotifier&lt;br /&gt;
|OX Notifier for Microsoft Windows&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.OXNotifier&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|USM-JSON&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OUTLOOK_UPDATER&lt;br /&gt;
|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:ClientIdentifiers&amp;diff=26680</id>
		<title>AppSuite:ClientIdentifiers</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:ClientIdentifiers&amp;diff=26680"/>
		<updated>2022-01-25T08:30:01Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= List of App Suite client identifiers =&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;pre style=&amp;quot;color: red&amp;quot;&amp;gt;This page is under construction!&amp;lt;/pre&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Actively used ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|CALDAV&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|CARDDAV&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|DRIVE_UPDATER&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-appsuite&lt;br /&gt;
|OX App Suite web frontend&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-mobile-api-facade&lt;br /&gt;
|[[AppSuite:OX_Mail_App|OX Mail App]]&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.Android.OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXAddIn&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXUploader&lt;br /&gt;
|[[AppSuite:OX_Outlook_Uploader|OX Uploader for Outlook]]&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.iosClient.OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OSX.OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|USM-EAS&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_INFOSTORE&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_VCARD&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_XML&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Obsolete ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|com.openexchange.ox.gui.dhtml&lt;br /&gt;
|Open-Xchange Server 6 web frontend&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.olox1&lt;br /&gt;
|OX Connector for Outlook&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.olox2&lt;br /&gt;
|OX Connector 2 for Outlook&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-mailapp&lt;br /&gt;
|Legacy OX Mail App (v1)&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXNotifier&lt;br /&gt;
|OX Notifier for Microsoft Windows&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.OXNotifier&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|USM-JSON&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OUTLOOK_UPDATER&lt;br /&gt;
|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:ClientIdentifiers&amp;diff=26677</id>
		<title>AppSuite:ClientIdentifiers</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:ClientIdentifiers&amp;diff=26677"/>
		<updated>2022-01-25T08:28:38Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: Created page with &amp;quot;= List of App Suite client identifiers =  ---- &amp;lt;pre style=&amp;quot;color: red&amp;quot;&amp;gt;This page is under construction!&amp;lt;/pre&amp;gt; ----  == Actively used ==  {| |CALDAV | |- |CARDDAV | |- |DRIVE_U...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= List of App Suite client identifiers =&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;pre style=&amp;quot;color: red&amp;quot;&amp;gt;This page is under construction!&amp;lt;/pre&amp;gt;&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Actively used ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|CALDAV&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|CARDDAV&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|DRIVE_UPDATER&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-appsuite&lt;br /&gt;
|OX App Suite web frontend&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-mobile-api-facade&lt;br /&gt;
|[[AppSuite:OX_Mail_App|OX Mail App]]&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.Android.OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXAddIn&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXUploader&lt;br /&gt;
|[[AppSuite:OX_Outlook_Uploader|OX Uploader for Outlook]]&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.iosClient.OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OSX.OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OUTLOOK_UPDATER&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|OXDrive&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|USM-EAS&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_INFOSTORE&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_VCARD&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|WEBDAV_XML&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Obsolete ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|com.openexchange.ox.gui.dhtml&lt;br /&gt;
|Open-Xchange Server 6 web frontend&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.olox1&lt;br /&gt;
|OX Connector for Outlook&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.olox2&lt;br /&gt;
|OX Connector 2 for Outlook&lt;br /&gt;
|-&lt;br /&gt;
|open-xchange-mailapp&lt;br /&gt;
|Legacy OX Mail App (v1)&lt;br /&gt;
|-&lt;br /&gt;
|OpenXchange.HTTPClient.OXNotifier&lt;br /&gt;
|OX Notifier for Microsoft Windows&lt;br /&gt;
|-&lt;br /&gt;
|com.open-xchange.updater.OXNotifier&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|USM-JSON&lt;br /&gt;
|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:S3_File_Store&amp;diff=26023</id>
		<title>AppSuite:S3 File Store</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:S3_File_Store&amp;diff=26023"/>
		<updated>2021-06-09T08:03:46Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: /* Overview */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
= Overview =&lt;br /&gt;
&lt;br /&gt;
Besides ordinary local- or NFS-filesystem-based filestores, OX may also be used with a cloud storage solution offering an S3 interface. The required functionality is added with the package &#039;&#039;open-xchange-filestore-s3&#039;&#039;. The filestore integration was tested against the regular Amazon Simple Storage Service (S3), however, other object storage implementation offering an S3-compatible API should work, too. The list of officially supported S3 storages can be found on the [https://oxpedia.org/wiki/index.php?title=AppSuite:OX_System_Requirements#File_Storage system requirements page].&lt;br /&gt;
&lt;br /&gt;
= Installation &amp;amp; Configuration =&lt;br /&gt;
&lt;br /&gt;
This chapter shows which components need to be installed and where configuration is done.&lt;br /&gt;
&lt;br /&gt;
{{InstallPlugin | pluginname=open-xchange-filestore-s3 | toplevel=products | sopath=appsuite/stable/backend | version=App Suite}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Configuration ==&lt;br /&gt;
&lt;br /&gt;
S3 filestores can be configured in the configuration file &#039;&#039;filestore-s3.properties&#039;&#039; once they have been registered on the server with the &#039;&#039;registerfilestore&#039;&#039; command. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Register an S3 filestore ===&lt;br /&gt;
&lt;br /&gt;
Similarly to local- or NFS-filesystem-based filestores, S3 filestore need to be registered using the commandline tool &#039;&#039;registerfilestore&#039;&#039; before they can be used. The &#039;&#039;scheme&#039;&#039;-part of the filestore URI must be set to &#039;&#039;s3&#039;&#039; in this case. Besides the common &#039;&#039;s3://&#039;&#039; prefix of such filestore URIs, the remaining authority component of the URI specifies an identifier of the filestore that will be used to refer to this filestore registration in the configuration file. It&#039;s recommended to use the bucket name here, for example:&lt;br /&gt;
&lt;br /&gt;
 root@ox01:/opt/open-xchange/sbin# ./registerfilestore -A oxadminmaster -P secret -t s3://ox-filestore-s3 -s 1048576000 -x 5000&lt;br /&gt;
 filestore 7433 registered&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Configure the filestore ===&lt;br /&gt;
&lt;br /&gt;
Additional configuration for each registered filestore is done in the configuration file &#039;&#039;filestore-s3.properties&#039;&#039;. To map configuration properties to specific filestore registrations, the filestore identifier corresponding to the defined authority part of the filestore URI is used in the property names. Please refer to the inline documentation or the examples below for details.&lt;br /&gt;
&lt;br /&gt;
Note: In most cases, you want to use the same configuration throughout the whole ox cluster, so you should make sure to use the same &#039;&#039;filestore-s3.properties&#039;&#039; configuration file on all nodes.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Step-by-step guide to setup an AWS S3 storage =&lt;br /&gt;
&lt;br /&gt;
The following walktrhorugh outlines all steps necessary to complete the setup of a S3 filestore running on the regular Amazon Simple Storage Service (S3). &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Prerequisites ==&lt;br /&gt;
* Installed &#039;&#039;open-xchange-filestore-s3&#039;&#039; package&lt;br /&gt;
* A valid account for Amazon S3&lt;br /&gt;
* AWS access key, e.g. &#039;&#039;AKIAIOSFODNN7EXAMPLE&#039;&#039;&lt;br /&gt;
* AWS secret key, e.g. &#039;&#039;wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Create a bucket ==&lt;br /&gt;
* Login to the S3 Management Console at https://console.aws.amazon.com/s3/&lt;br /&gt;
* Click the &#039;&#039;Create Bucket&#039;&#039; button&lt;br /&gt;
* Select a bucket name of your choice, e.g. &#039;&#039;ox-filestore-s3&#039;&#039;&lt;br /&gt;
* Select the region according to your needs, e.g. &#039;&#039;EU (Ireland)&#039;&#039;&lt;br /&gt;
* Click &#039;&#039;Create&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Register the filestore ==&lt;br /&gt;
* Open a terminal on a running backend server of your OX cluster&lt;br /&gt;
* Navigate to the directory where the commandline utilities are installed, usually at &#039;&#039;/opt/open-xchange/sbin&#039;&#039;&lt;br /&gt;
* Run the &#039;&#039;registerfilestore&#039;&#039; tool using a storepath URL starting with the &#039;&#039;s3&#039;&#039; scheme (use &#039;&#039;s3://&#039;&#039; as prefix literally) followed by the filestore ID (the bucket name seems most appropriate here, however, you can still use a different name), e.g.:&lt;br /&gt;
 ./registerfilestore -A oxadminmaster -P secret -t s3://ox-filestore-s3 -s 1048576000 -x 5000&#039;&#039;&lt;br /&gt;
(execute &amp;quot;./registerfilestore -h&amp;quot; for more information regarding possible commandline arguments)&lt;br /&gt;
* The internal ID of the new filestore is printed out &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Configure the filestore ==&lt;br /&gt;
* Open the configuration file &#039;&#039;filestore-s3.properties&#039;&#039; in your favourite editor&lt;br /&gt;
* Insert a new set of properties using the filestore ID assigned during registration of the filestore in the previous step, e.g. &#039;&#039;ox-filestore-s3&#039;&#039;:&lt;br /&gt;
 com.openexchange.filestore.s3.ox-filestore-s3.endpoint=&lt;br /&gt;
 com.openexchange.filestore.s3.ox-filestore-s3.bucketName=&lt;br /&gt;
 com.openexchange.filestore.s3.ox-filestore-s3.region=&lt;br /&gt;
 com.openexchange.filestore.s3.ox-filestore-s3.pathStyleAccess=&lt;br /&gt;
 com.openexchange.filestore.s3.ox-filestore-s3.accessKey=&lt;br /&gt;
 com.openexchange.filestore.s3.ox-filestore-s3.secretKey=&lt;br /&gt;
 com.openexchange.filestore.s3.ox-filestore-s3.encryption=&lt;br /&gt;
 com.openexchange.filestore.s3.ox-filestore-s3.signerOverride=&lt;br /&gt;
 com.openexchange.filestore.s3.ox-filestore-s3.chunkSize=&lt;br /&gt;
* Specify the endpoint to use depending on the chosen region (see http://docs.aws.amazon.com/general/latest/gr/rande.html#s3_region for a list of endpoints), e.g.:&lt;br /&gt;
 com.openexchange.filestore.s3.ox-filestore-s3.endpoint=https://s3-eu-west-1.amazonaws.com&lt;br /&gt;
* Set the bucket name for the filestore, e.g.:&lt;br /&gt;
 com.openexchange.filestore.s3.ox-filestore-s3.bucketName=ox-filestore-s3&lt;br /&gt;
* Define the location constraint according to the chosen region - valid values are listed in the comments of the properties file - e.g.:&lt;br /&gt;
 com.openexchange.filestore.s3.ox-filestore-s3.region=eu-west-1&lt;br /&gt;
* Configure path style / virtual host access (recommended to set to &#039;&#039;false&#039;&#039; for Amazon S3, must be &#039;&#039;false&#039;&#039; when using the default endpoint &#039;&#039;s3.amazonaws.com&#039;&#039; and a different region than US), see http://docs.aws.amazon.com/AmazonS3/latest/dev/VirtualHosting.html for details):&lt;br /&gt;
 com.openexchange.filestore.s3.ox-filestore-s3.pathStyleAccess=false&lt;br /&gt;
* Specify your API access and secret keys, e.g.:&lt;br /&gt;
 com.openexchange.filestore.s3.ox-filestore-s3.accessKey=AKIAIOSFODNN7EXAMPLE&lt;br /&gt;
 com.openexchange.filestore.s3.ox-filestore-s3.secretKey=wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY&lt;br /&gt;
* Configure encryption as needed (&#039;&#039;none&#039;&#039; in this example):&lt;br /&gt;
 com.openexchange.filestore.s3.ox-filestore-s3.encryption=none&lt;br /&gt;
* Specify the signing algorithm if applicable. Please mind that this setting needs to be adjusted to &amp;quot;AWSS3V4SignerType&amp;quot; when targeting the newer &amp;quot;v4-only&amp;quot; regions like Frankfurt or Beijing.&lt;br /&gt;
 com.openexchange.filestore.s3.ox-filestore-s3.encryption=S3SignerType&lt;br /&gt;
* Optionally override the default minimum chunk size to use when doing multipart uploads.&lt;br /&gt;
 com.openexchange.filestore.s3.ox-filestore-s3.chunkSize=5MB&lt;br /&gt;
&lt;br /&gt;
== Create contexts using the filestore ==&lt;br /&gt;
* New contexts that should use the configured filestore can be created by suppliying the ID of the registered filestore in the &#039;&#039;createcontext&#039;&#039; commandline tool. Use the internal ID returned by the previously used &#039;&#039;registerfilestore&#039;&#039; command executed above, e.g., assuming the ID returned from the &#039;&#039;registerfilestore&#039;&#039; command was &#039;&#039;6&#039;&#039;:&lt;br /&gt;
 ./createcontext -A oxadminmaster -P secret -u oxadmin -d &amp;quot;Context Admin&amp;quot; -g Admin -s User -p secret -e oxadmin@example.com -q 1000 -L example.com --access-combination-name=all -F 6&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Check the configuration ==&lt;br /&gt;
* Login to the App Suite webinterface with a user from a context using the S3 filestore&lt;br /&gt;
* Upload a new file in the &#039;&#039;Drive&#039;&#039; module and download it again to verify basic functionality&lt;br /&gt;
* Check the S3 management console to verify the creation of the new file; here, the file should show up under a virtual prefix based on the parent context&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: AppSuite]] [[Category: Administration]] [[Category: Cluster]]&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=Caldav_carddav_Bundles&amp;diff=25822</id>
		<title>Caldav carddav Bundles</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=Caldav_carddav_Bundles&amp;diff=25822"/>
		<updated>2021-03-10T16:49:10Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: /* Alternative 2: Apache useragent detection */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This article is valid until the version 7.10.2 of the Open Xchange Server. For newer versions please visit https://documentation.open-xchange.com/latest/middleware/miscellaneous/caldav_carddav.html&lt;br /&gt;
&lt;br /&gt;
= Installation and Configuration of the CalDAV- and CardDAV-bundles =&lt;br /&gt;
&lt;br /&gt;
The Open-Xchange server can be accessed via it&#039;s CalDAV- and CardDAV-interfaces to allow the synchronization of Calendar- and Contact-data with external applications like the Mac OS Calendar and Address Book clients.&lt;br /&gt;
&lt;br /&gt;
CalDAV and CardDAV are standard protocols for the exchange of calendar data and address data respectively. The CalDAV interface publishes all the user&#039;s calendar folders via CalDAV so the user can subscribe to them in a client application. Similarly, the CardDAV interface publishes the user&#039;s contact folders. Depending on the used client, the user can either subscribe one or more folders, or access all available data in an aggregated way. &lt;br /&gt;
&lt;br /&gt;
== User Guide and Client Configuration ==&lt;br /&gt;
Please find further information regarding the client configuration at [[CalDAVClients]] and [[CardDAVClients]].&lt;br /&gt;
&lt;br /&gt;
== Webserver Configuration ==&lt;br /&gt;
In order to redirect DAV requests to the appropiate servlets, the webserver&#039;s configuration may need to be adjusted using one of the following alternatives. Please be aware that for a working Mavericks auto configuration setup you need to have SSL enabled on the server. The non-SSL variant described below only works if you use the advanced CalDAV configuration in Mac OS X Mavericks and enter the path by hand. If you just want to enter the hostname, SSL is required. The same applies to iOS7 where SSL is always required.&lt;br /&gt;
&lt;br /&gt;
=== Alternative 1: Apache vhost (recommended) ===&lt;br /&gt;
Please edit your site configuration file for OX so that &#039;&#039;&#039; the existing OX configuration as well as the CalDAV/CardDAV configuration are placed inside their own virtual hosts sections.&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Please add the following entries before your existing &amp;lt;code&amp;gt;VirtualHost&amp;lt;/code&amp;gt; entry. This is an &amp;lt;b&amp;gt;example&amp;lt;/b&amp;gt; where &amp;lt;code&amp;gt;MYSERVER.TLD&amp;lt;/code&amp;gt; is the domain-name of the ox-server:&lt;br /&gt;
&lt;br /&gt;
 # NameVirtualHost directive no longer has any effect since Apache &amp;gt;=2.4&lt;br /&gt;
 # uncomment only for Apache Versions &amp;lt;2.4&lt;br /&gt;
 #NameVirtualHost *:80&lt;br /&gt;
 &amp;lt;VirtualHost *:80&amp;gt;&lt;br /&gt;
        ServerName dav.&amp;lt;MYSERVER.TLD&amp;gt;&lt;br /&gt;
        ErrorLog /tmp/dav.err.log&lt;br /&gt;
        TransferLog /tmp/dav.access.log&lt;br /&gt;
 &lt;br /&gt;
       &amp;lt;Proxy balancer://oxserver-sync&amp;gt;&lt;br /&gt;
         Order deny,allow&lt;br /&gt;
         Allow from all&lt;br /&gt;
 &lt;br /&gt;
         # for grizzly http service&lt;br /&gt;
         BalancerMember http://localhost:8009 timeout=100 smax=0 ttl=60 retry=60 loadfactor=50 route=OX1&lt;br /&gt;
         # uncomment this entry if you have a clustered setup and want to use the other nodes too&lt;br /&gt;
         #BalancerMember http://&amp;lt;ip-of-other-host&amp;gt;:8009 timeout=100 smax=0 ttl=60 retry=60 loadfactor=50 route=OX2&lt;br /&gt;
         SetEnv proxy-initial-not-pooled&lt;br /&gt;
         SetEnv proxy-sendchunked&lt;br /&gt;
       &amp;lt;/Proxy&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
       ProxyPass / balancer://oxserver-sync/servlet/dav/&lt;br /&gt;
 &lt;br /&gt;
 &amp;lt;/VirtualHost&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If you use this method, you have to make sure that &amp;lt;code&amp;gt;dav.&amp;lt;MYSERVER.TLD&amp;gt;&amp;lt;/code&amp;gt; is reachable, your DNS configuration needs an entry for this name. Take care of the the dav.* logfiles, the example writes them without logrotation to &amp;lt;code&amp;gt;/tmp&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Please note the &amp;lt;code&amp;gt;NameVirtualHost&amp;lt;/code&amp;gt; directive is needed to be able to specify multiple virtual hosts for the same IP. The differentiation is only done by the given &amp;lt;code&amp;gt;ServerName&amp;lt;/code&amp;gt;. This implies that you need two server names, so the virtual host entry for the existing ox site configuration needs to be also enriched by a &amp;lt;code&amp;gt;ServerName&amp;lt;/code&amp;gt; if not already present. If you access the system without one of the given &amp;lt;code&amp;gt;ServerName&amp;lt;/code&amp;gt;s so e.g. via the IP the system will pick the corresponding one by order (in this case the DAV part first. If you want it to work differently please change the order accordingly.&lt;br /&gt;
&lt;br /&gt;
=== Alternative 2: Apache useragent detection ===&lt;br /&gt;
For environments where it is inconvenient to setup a vhost there is the possibility to redirect to relevant servlets another way: Via useragent detection. This is not recommended for the following reason: Per definition this is a whitelist-approach and any client sending a useragent-string not explicitly listed in the configuration will not be able to connect . Useragent-strings may also change between different versions of an application or may even be actively changed into something non-standard.&lt;br /&gt;
&lt;br /&gt;
   $ vi &amp;lt;your-ox-site-configuration-file&amp;gt;&lt;br /&gt;
&lt;br /&gt;
  RewriteEngine On&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      Calendar           [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      Reminders          [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      DataAccess         [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      DAVKit             [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      DAVx5              [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      OpenSync           [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      &amp;quot;DAVdroid&amp;quot;         [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      Lightning          [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      Thunderbird        [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      Adresboek          [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      dataaccessd        [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      Preferences        [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      Adressbuch         [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      AddressBook        [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      Address\ Book      [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      CalendarStore      [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      CalendarAgent      [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      CalDAV%20Sync%20Adapter [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      CalDavSynchronizer [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      accountsd          [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      &amp;quot;eM Client&amp;quot;        [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      &amp;quot;OX Sync&amp;quot;          [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      CalDav             [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      CoreDAV            [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      remindd&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      &amp;quot;!Open-Xchange Calendar Feed Client&amp;quot;&lt;br /&gt;
  RewriteRule (.*)                  http://localhost:8009/servlet/dav$1     [P] # for grizzly http service&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; The address book app on OSX 10.6 uses a localized user-agent string. If you&#039;re expecting clients with non-english language settings, you need to add the translated user-agent string to these rewrite rules. For example: &amp;quot;Adressbuch&amp;quot; for german OSX clients.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; Depending on the specific configuration, such a global definition of the rewrite rules might not be appropriate. However, the rules may also be defined inside a &amp;lt;code&amp;gt;Directory&amp;lt;/code&amp;gt; context. More details are available at http://httpd.apache.org/docs/current/mod/mod_rewrite.html#rewriterule.&lt;br /&gt;
&lt;br /&gt;
== Autodiscovery ==&lt;br /&gt;
&lt;br /&gt;
By providing some DNS service name registrations for your domain and adding an additional rewrite-rule to the webserver&#039;s configuration, it&#039;s possible for some clients to automatically discover the account settings by just providing the user&#039;s e-mail address and password. The procedure is specified in [http://tools.ietf.org/html/rfc6764 RFC 6764]. &lt;br /&gt;
&lt;br /&gt;
The following example illustrates the DNS entries where MYSERVER.TLD would be the domain name of the ox-server, both for CalDAV and CardDAV via HTTP and HTTPS on the virtual host dav.MYSERVER.TLD:&lt;br /&gt;
&lt;br /&gt;
 _caldavs._tcp.MYSERVER.TLD.      10800 IN SRV      10 1 443 dav.MYSERVER.TLD.&lt;br /&gt;
 _caldav._tcp.MYSERVER.TLD.       10800 IN SRV      10 1  80 dav.MYSERVER.TLD.&lt;br /&gt;
 _carddavs._tcp.MYSERVER.TLD.     10800 IN SRV      10 1 443 dav.MYSERVER.TLD.&lt;br /&gt;
 _carddav._tcp.MYSERVER.TLD.      10800 IN SRV      10 1  80 dav.MYSERVER.TLD.&lt;br /&gt;
&lt;br /&gt;
Additionally, a rewrite-rule similar to the following example should be added to the webserver configuration of the virtual host to enable the bootstrapping process. The rewrite target must be the root of your DAV server.&lt;br /&gt;
The well-known aliases should be added for your DAV vhost and on the vhost serving the host matching the mail domain:&lt;br /&gt;
&lt;br /&gt;
 RewriteEngine On&lt;br /&gt;
 RewriteCond %{REQUEST_URI} ^/\.well-known/caldav   [OR]&lt;br /&gt;
 RewriteCond %{REQUEST_URI} ^/\.well-known/carddav&lt;br /&gt;
 RewriteRule (.*) / [L,R]&lt;br /&gt;
&lt;br /&gt;
In the case of not serving the DAV service on the vhost root additionally some DNS TXT records are recommended:&lt;br /&gt;
&lt;br /&gt;
 _caldavs._tcp.MYSERVER.TLD.      10800 IN TXT   path=/servlet/dav&lt;br /&gt;
 _caldav._tcp.MYSERVER.TLD.       10800 IN TXT   path=/servlet/dav&lt;br /&gt;
 _carddavs._tcp.MYSERVER.TLD.     10800 IN TXT   path=/servlet/dav&lt;br /&gt;
 _carddav._tcp.MYSERVER.TLD.      10800 IN TXT   path=/servlet/dav&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Installation on OX App Suite ==&lt;br /&gt;
&lt;br /&gt;
=== Debian GNU/Linux 9.0 ===&lt;br /&gt;
&lt;br /&gt;
Add the following entry to /etc/apt/sources.list.d/open-xchange.list if not already present:&lt;br /&gt;
&lt;br /&gt;
 deb https://software.open-xchange.com/products/appsuite/stable/backend/DebianStretch/ /&lt;br /&gt;
&lt;br /&gt;
 # if you have a valid maintenance subscription, please uncomment the &lt;br /&gt;
 # following and add the ldb account data to the url so that the most recent&lt;br /&gt;
 # packages get installed&lt;br /&gt;
 # deb https://[CUSTOMERID:PASSWORD]@software.open-xchange.com/products/appsuite/stable/backend/updates/DebianStretch/ /&lt;br /&gt;
&lt;br /&gt;
and run&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-dav&lt;br /&gt;
&lt;br /&gt;
=== Debian GNU/Linux 10.0 ===&lt;br /&gt;
&lt;br /&gt;
Add the following entry to /etc/apt/sources.list.d/open-xchange.list if not already present:&lt;br /&gt;
&lt;br /&gt;
 deb https://software.open-xchange.com/products/appsuite/stable/backend/DebianBuster/ /&lt;br /&gt;
&lt;br /&gt;
 # if you have a valid maintenance subscription, please uncomment the &lt;br /&gt;
 # following and add the ldb account data to the url so that the most recent&lt;br /&gt;
 # packages get installed&lt;br /&gt;
 # deb https://[CUSTOMERID:PASSWORD]@software.open-xchange.com/products/appsuite/stable/backend/updates/DebianBuster/ /&lt;br /&gt;
&lt;br /&gt;
and run&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-dav&lt;br /&gt;
&lt;br /&gt;
=== SUSE Linux Enterprise Server 12 (valid until 7.10.3)===&lt;br /&gt;
&lt;br /&gt;
Add the package repository using zypper if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ar https://software.open-xchange.com/products/appsuite/7.10.3/backend/SLE_12 ox&lt;br /&gt;
&lt;br /&gt;
If you have a valid maintenance subscription, please run the following command and add the ldb account data to the url so that the most recent packages get installed:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ar https://[CUSTOMERID:PASSWORD]@software.open-xchange.com/products/appsuite/7.10.3/backend/updates/SLES11 ox-updates&lt;br /&gt;
&lt;br /&gt;
and run&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&lt;br /&gt;
 $ zypper in open-xchange-dav&lt;br /&gt;
&lt;br /&gt;
=== RedHat Enterprise Linux 6 (valid until 7.10.3)===&lt;br /&gt;
&lt;br /&gt;
Start a console and create a software repository file if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ vim /etc/yum.repos.d/ox.repo&lt;br /&gt;
&lt;br /&gt;
 [ox]&lt;br /&gt;
 name=Open-Xchange&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/7.10.3/backend/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 # if you have a valid maintenance subscription, please uncomment the &lt;br /&gt;
 # following and add the ldb account data to the url so that the most recent&lt;br /&gt;
 # packages get installed&lt;br /&gt;
 # [ox-updates]&lt;br /&gt;
 # name=Open-Xchange Updates&lt;br /&gt;
 # baseurl=https://[CUSTOMERID:PASSWORD]@software.open-xchange.com/products/appsuite/7.10.3/backend/updates/RHEL6/&lt;br /&gt;
 # gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 # enabled=1&lt;br /&gt;
 # gpgcheck=1&lt;br /&gt;
 # metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and run&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-dav&lt;br /&gt;
&lt;br /&gt;
===RedHat Enterprise Linux 7 ===&lt;br /&gt;
&lt;br /&gt;
Start a console and create a software repository file if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ vim /etc/yum.repos.d/ox.repo&lt;br /&gt;
&lt;br /&gt;
 [ox]&lt;br /&gt;
 name=Open-Xchange&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/stable/backend/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 # if you have a valid maintenance subscription, please uncomment the &lt;br /&gt;
 # following and add the ldb account data to the url so that the most recent&lt;br /&gt;
 # packages get installed&lt;br /&gt;
 # [ox-updates]&lt;br /&gt;
 # name=Open-Xchange Updates&lt;br /&gt;
 # baseurl=https://[CUSTOMERID:PASSWORD]@software.open-xchange.com/products/appsuite/stable/backend/updates/RHEL7/&lt;br /&gt;
 # gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 # enabled=1&lt;br /&gt;
 # gpgcheck=1&lt;br /&gt;
 # metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and run&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-dav&lt;br /&gt;
&lt;br /&gt;
===CentOS 6 (valid until 7.10.3)===&lt;br /&gt;
&lt;br /&gt;
Start a console and create a software repository file if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ vim /etc/yum.repos.d/ox.repo&lt;br /&gt;
&lt;br /&gt;
 [ox]&lt;br /&gt;
 name=Open-Xchange&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/7.10.3/backend/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 # if you have a valid maintenance subscription, please uncomment the &lt;br /&gt;
 # following and add the ldb account data to the url so that the most recent&lt;br /&gt;
 # packages get installed&lt;br /&gt;
 # [ox-updates]&lt;br /&gt;
 # name=Open-Xchange Updates&lt;br /&gt;
 # baseurl=https://[CUSTOMERID:PASSWORD]@software.open-xchange.com/products/appsuite/7.10.3/backend/updates/RHEL6/&lt;br /&gt;
 # gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 # enabled=1&lt;br /&gt;
 # gpgcheck=1&lt;br /&gt;
 # metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and run&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-dav&lt;br /&gt;
&lt;br /&gt;
===CentOS 7===&lt;br /&gt;
&lt;br /&gt;
Start a console and create a software repository file if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ vim /etc/yum.repos.d/ox.repo&lt;br /&gt;
&lt;br /&gt;
 [ox]&lt;br /&gt;
 name=Open-Xchange&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/stable/backend/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 # if you have a valid maintenance subscription, please uncomment the &lt;br /&gt;
 # following and add the ldb account data to the url so that the most recent&lt;br /&gt;
 # packages get installed&lt;br /&gt;
 # [ox-updates]&lt;br /&gt;
 # name=Open-Xchange Updates&lt;br /&gt;
 # baseurl=https://[CUSTOMERID:PASSWORD]@software.open-xchange.com/products/appsuite/stable/backend/updates/RHEL7/&lt;br /&gt;
 # gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 # enabled=1&lt;br /&gt;
 # gpgcheck=1&lt;br /&gt;
 # metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and run&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-dav&lt;br /&gt;
&lt;br /&gt;
== CalDAV Configuration ==&lt;br /&gt;
&lt;br /&gt;
The following configuration options are available in the configuration files &amp;lt;code&amp;gt;caldav.properties&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;caldav.yml&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
===com.openexchange.caldav.enabled===&lt;br /&gt;
The property &#039;&#039;&#039;com.openexchange.caldav.enabled&#039;&#039;&#039; governs whether a user has access to the CalDAV interface. This can be configured along the config cascade, in the default setting, everyone that has access to the infostore also has access to caldav. This is achieved in the following way:&lt;br /&gt;
&lt;br /&gt;
/opt/open-xchange/etc/caldav.properties:&lt;br /&gt;
  com.openexchange.caldav.enabled=false&lt;br /&gt;
&lt;br /&gt;
/opt/open-xchange/etc/contextSets/caldav.yml&lt;br /&gt;
  premium:&lt;br /&gt;
      com.openexchange.caldav.enabled: true&lt;br /&gt;
      withTags: ucInfostore&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This means: In general CalDAV is turned off, but using the &amp;lt;code&amp;gt;contextSets&amp;lt;/code&amp;gt; feature of the config cascade it is turned on for everyone that has infostore access.&lt;br /&gt;
&lt;br /&gt;
===com.openexchange.caldav.tree===&lt;br /&gt;
Configures the ID of the folder tree used by the CalDAV interface. Currently, this should be set to the default value of &#039;0&#039;.&lt;br /&gt;
&lt;br /&gt;
===com.openexchange.caldav.interval.start===&lt;br /&gt;
Defines the minimum end time of appointments to be synchronized via the CalDAV interface, relative to the current date. Possible values are &amp;quot;one_month&amp;quot; (default), &amp;quot;one_year&amp;quot; and &amp;quot;six_months&amp;quot;.  &lt;br /&gt;
&lt;br /&gt;
===com.openexchange.caldav.interval.end===&lt;br /&gt;
Defines the maximum start time of appointments to be synchronized via the CalDAV interface, relative to the current date. Possible values are &amp;quot;one_year&amp;quot; (default) and &amp;quot;two_years&amp;quot;.  &lt;br /&gt;
&lt;br /&gt;
===com.openexchange.caldav.url===&lt;br /&gt;
Tells users where to find a caldav folder. This can be displayed in frontends. You can use the variables [hostname] and [folderId]. If you chose to deploy caldav as a virtual host (say &#039;dav.open-xchange.com&#039;) use https://dav.open-xchange.com/caldav/[folderId] as the value. If you are using user-agent sniffing use https://[hostname]/caldav/[folderId].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== CardDAV Configuration ==&lt;br /&gt;
&lt;br /&gt;
The following configuration options are available in the configuration files carddav.properties and carddav.yml:&lt;br /&gt;
&lt;br /&gt;
===com.openexchange.carddav.enabled===&lt;br /&gt;
Similarly to CalDAV, the property &#039;&#039;&#039;com.openexchange.carddav.enabled&#039;&#039;&#039; governs whether CardDAV is available for a certain user. This is configured exactly like CalDAV with the config cascade only enabling this for users that have access to the infostore:&lt;br /&gt;
&lt;br /&gt;
/opt/open-xchange/etc/carddav.properties:&lt;br /&gt;
  com.openexchange.carddav.enabled=false&lt;br /&gt;
&lt;br /&gt;
/opt/open-xchange/etc/contextSets/carddav.yml&lt;br /&gt;
  premium:&lt;br /&gt;
      com.openexchange.carddav.enabled: true&lt;br /&gt;
      withTags: ucInfostore&lt;br /&gt;
&lt;br /&gt;
===com.openexchange.carddav.ignoreFolders===&lt;br /&gt;
A comma-separated list of folder IDs to exclude from the synchronization. Use this to disable syncing of very large folders (e.g. the global address list in large contexts, which always has ID 6). By default, no folders are excluded.&lt;br /&gt;
&lt;br /&gt;
===com.openexchange.carddav.tree===&lt;br /&gt;
Configures the ID of the folder tree used by the CardDAV interface. Currently, this should be set to the default value of &#039;0&#039;.&lt;br /&gt;
&lt;br /&gt;
===com.openexchange.carddav.exposedCollections===&lt;br /&gt;
Controls which collections are exposed via the CardDAV interface. Possible values are &#039;0&#039;, &#039;1&#039; and &#039;2&#039;. A value of &#039;1&#039; makes each visible folder available as a resource collection, while &#039;2&#039; only exposes an aggregated collection containing  all contact resources from all visible folders. The default value &#039;0&#039; exposes either an aggregated collection or individual collections for each folder, depending on the client&#039;s user-agent that is matched against the pattern in &#039;userAgentForAggregatedCollection&#039;. &lt;br /&gt;
&lt;br /&gt;
===com.openexchange.carddav.userAgentForAggregatedCollection===&lt;br /&gt;
Regular expression to match against the client&#039;s user-agent to decide whether the aggregated collection is exposed or not. The default pattern matches all known varieties of the Mac OS Addressbook client, that doesn&#039;t support multiple collections. Only used if &#039;exposedCollections&#039; is set to &#039;0&#039;. The pattern is used case insensitive. &lt;br /&gt;
&lt;br /&gt;
===com.openexchange.carddav.reducedAggregatedCollection===&lt;br /&gt;
Specifies if all visible folders are used to create the aggregated collection, or if a reduced set of folders only containing the global addressbook and the personal contacts folders should be used. This setting only influences the aggregated collection that is used for clients that don&#039;t support multiple collections. Possible values are &#039;true&#039; and &#039;false.&lt;br /&gt;
&lt;br /&gt;
[[Category: Clients]]&lt;br /&gt;
[[Category: Administrator]]&lt;br /&gt;
[[Category: AppSuite]]&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=Caldav_carddav_Bundles&amp;diff=25821</id>
		<title>Caldav carddav Bundles</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=Caldav_carddav_Bundles&amp;diff=25821"/>
		<updated>2021-03-10T16:34:02Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: /* Alternative 2: Apache useragent detection */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This article is valid until the version 7.10.2 of the Open Xchange Server. For newer versions please visit https://documentation.open-xchange.com/latest/middleware/miscellaneous/caldav_carddav.html&lt;br /&gt;
&lt;br /&gt;
= Installation and Configuration of the CalDAV- and CardDAV-bundles =&lt;br /&gt;
&lt;br /&gt;
The Open-Xchange server can be accessed via it&#039;s CalDAV- and CardDAV-interfaces to allow the synchronization of Calendar- and Contact-data with external applications like the Mac OS Calendar and Address Book clients.&lt;br /&gt;
&lt;br /&gt;
CalDAV and CardDAV are standard protocols for the exchange of calendar data and address data respectively. The CalDAV interface publishes all the user&#039;s calendar folders via CalDAV so the user can subscribe to them in a client application. Similarly, the CardDAV interface publishes the user&#039;s contact folders. Depending on the used client, the user can either subscribe one or more folders, or access all available data in an aggregated way. &lt;br /&gt;
&lt;br /&gt;
== User Guide and Client Configuration ==&lt;br /&gt;
Please find further information regarding the client configuration at [[CalDAVClients]] and [[CardDAVClients]].&lt;br /&gt;
&lt;br /&gt;
== Webserver Configuration ==&lt;br /&gt;
In order to redirect DAV requests to the appropiate servlets, the webserver&#039;s configuration may need to be adjusted using one of the following alternatives. Please be aware that for a working Mavericks auto configuration setup you need to have SSL enabled on the server. The non-SSL variant described below only works if you use the advanced CalDAV configuration in Mac OS X Mavericks and enter the path by hand. If you just want to enter the hostname, SSL is required. The same applies to iOS7 where SSL is always required.&lt;br /&gt;
&lt;br /&gt;
=== Alternative 1: Apache vhost (recommended) ===&lt;br /&gt;
Please edit your site configuration file for OX so that &#039;&#039;&#039; the existing OX configuration as well as the CalDAV/CardDAV configuration are placed inside their own virtual hosts sections.&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Please add the following entries before your existing &amp;lt;code&amp;gt;VirtualHost&amp;lt;/code&amp;gt; entry. This is an &amp;lt;b&amp;gt;example&amp;lt;/b&amp;gt; where &amp;lt;code&amp;gt;MYSERVER.TLD&amp;lt;/code&amp;gt; is the domain-name of the ox-server:&lt;br /&gt;
&lt;br /&gt;
 # NameVirtualHost directive no longer has any effect since Apache &amp;gt;=2.4&lt;br /&gt;
 # uncomment only for Apache Versions &amp;lt;2.4&lt;br /&gt;
 #NameVirtualHost *:80&lt;br /&gt;
 &amp;lt;VirtualHost *:80&amp;gt;&lt;br /&gt;
        ServerName dav.&amp;lt;MYSERVER.TLD&amp;gt;&lt;br /&gt;
        ErrorLog /tmp/dav.err.log&lt;br /&gt;
        TransferLog /tmp/dav.access.log&lt;br /&gt;
 &lt;br /&gt;
       &amp;lt;Proxy balancer://oxserver-sync&amp;gt;&lt;br /&gt;
         Order deny,allow&lt;br /&gt;
         Allow from all&lt;br /&gt;
 &lt;br /&gt;
         # for grizzly http service&lt;br /&gt;
         BalancerMember http://localhost:8009 timeout=100 smax=0 ttl=60 retry=60 loadfactor=50 route=OX1&lt;br /&gt;
         # uncomment this entry if you have a clustered setup and want to use the other nodes too&lt;br /&gt;
         #BalancerMember http://&amp;lt;ip-of-other-host&amp;gt;:8009 timeout=100 smax=0 ttl=60 retry=60 loadfactor=50 route=OX2&lt;br /&gt;
         SetEnv proxy-initial-not-pooled&lt;br /&gt;
         SetEnv proxy-sendchunked&lt;br /&gt;
       &amp;lt;/Proxy&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
       ProxyPass / balancer://oxserver-sync/servlet/dav/&lt;br /&gt;
 &lt;br /&gt;
 &amp;lt;/VirtualHost&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If you use this method, you have to make sure that &amp;lt;code&amp;gt;dav.&amp;lt;MYSERVER.TLD&amp;gt;&amp;lt;/code&amp;gt; is reachable, your DNS configuration needs an entry for this name. Take care of the the dav.* logfiles, the example writes them without logrotation to &amp;lt;code&amp;gt;/tmp&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Please note the &amp;lt;code&amp;gt;NameVirtualHost&amp;lt;/code&amp;gt; directive is needed to be able to specify multiple virtual hosts for the same IP. The differentiation is only done by the given &amp;lt;code&amp;gt;ServerName&amp;lt;/code&amp;gt;. This implies that you need two server names, so the virtual host entry for the existing ox site configuration needs to be also enriched by a &amp;lt;code&amp;gt;ServerName&amp;lt;/code&amp;gt; if not already present. If you access the system without one of the given &amp;lt;code&amp;gt;ServerName&amp;lt;/code&amp;gt;s so e.g. via the IP the system will pick the corresponding one by order (in this case the DAV part first. If you want it to work differently please change the order accordingly.&lt;br /&gt;
&lt;br /&gt;
=== Alternative 2: Apache useragent detection ===&lt;br /&gt;
For environments where it is inconvenient to setup a vhost there is the possibility to redirect to relevant servlets another way: Via useragent detection. This is not recommended for the following reason: Per definition this is a whitelist-approach and any client sending a useragent-string not explicitly listed in the configuration will not be able to connect . Useragent-strings may also change between different versions of an application or may even be actively changed into something non-standard.&lt;br /&gt;
&lt;br /&gt;
   $ vi &amp;lt;your-ox-site-configuration-file&amp;gt;&lt;br /&gt;
&lt;br /&gt;
  RewriteEngine On&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      Calendar           [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      Reminders          [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      DataAccess         [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      DAVKit             [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      DAVx5              [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      OpenSync           [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      &amp;quot;DAVdroid&amp;quot;         [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      Lightning          [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      Adresboek          [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      dataaccessd        [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      Preferences        [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      Adressbuch         [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      AddressBook        [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      Address\ Book      [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      CalendarStore      [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      CalendarAgent      [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      CalDAV%20Sync%20Adapter [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      accountsd          [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      &amp;quot;eM Client&amp;quot;        [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      &amp;quot;OX Sync&amp;quot;          [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      CalDav             [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      CoreDAV            [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      remindd&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      &amp;quot;!Open-Xchange Calendar Feed Client&amp;quot;&lt;br /&gt;
  RewriteRule (.*)                  http://localhost:8009/servlet/dav$1     [P] # for grizzly http service&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; The address book app on OSX 10.6 uses a localized user-agent string. If you&#039;re expecting clients with non-english language settings, you need to add the translated user-agent string to these rewrite rules. For example: &amp;quot;Adressbuch&amp;quot; for german OSX clients.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; Depending on the specific configuration, such a global definition of the rewrite rules might not be appropriate. However, the rules may also be defined inside a &amp;lt;code&amp;gt;Directory&amp;lt;/code&amp;gt; context. More details are available at http://httpd.apache.org/docs/current/mod/mod_rewrite.html#rewriterule.&lt;br /&gt;
&lt;br /&gt;
== Autodiscovery ==&lt;br /&gt;
&lt;br /&gt;
By providing some DNS service name registrations for your domain and adding an additional rewrite-rule to the webserver&#039;s configuration, it&#039;s possible for some clients to automatically discover the account settings by just providing the user&#039;s e-mail address and password. The procedure is specified in [http://tools.ietf.org/html/rfc6764 RFC 6764]. &lt;br /&gt;
&lt;br /&gt;
The following example illustrates the DNS entries where MYSERVER.TLD would be the domain name of the ox-server, both for CalDAV and CardDAV via HTTP and HTTPS on the virtual host dav.MYSERVER.TLD:&lt;br /&gt;
&lt;br /&gt;
 _caldavs._tcp.MYSERVER.TLD.      10800 IN SRV      10 1 443 dav.MYSERVER.TLD.&lt;br /&gt;
 _caldav._tcp.MYSERVER.TLD.       10800 IN SRV      10 1  80 dav.MYSERVER.TLD.&lt;br /&gt;
 _carddavs._tcp.MYSERVER.TLD.     10800 IN SRV      10 1 443 dav.MYSERVER.TLD.&lt;br /&gt;
 _carddav._tcp.MYSERVER.TLD.      10800 IN SRV      10 1  80 dav.MYSERVER.TLD.&lt;br /&gt;
&lt;br /&gt;
Additionally, a rewrite-rule similar to the following example should be added to the webserver configuration of the virtual host to enable the bootstrapping process. The rewrite target must be the root of your DAV server.&lt;br /&gt;
The well-known aliases should be added for your DAV vhost and on the vhost serving the host matching the mail domain:&lt;br /&gt;
&lt;br /&gt;
 RewriteEngine On&lt;br /&gt;
 RewriteCond %{REQUEST_URI} ^/\.well-known/caldav   [OR]&lt;br /&gt;
 RewriteCond %{REQUEST_URI} ^/\.well-known/carddav&lt;br /&gt;
 RewriteRule (.*) / [L,R]&lt;br /&gt;
&lt;br /&gt;
In the case of not serving the DAV service on the vhost root additionally some DNS TXT records are recommended:&lt;br /&gt;
&lt;br /&gt;
 _caldavs._tcp.MYSERVER.TLD.      10800 IN TXT   path=/servlet/dav&lt;br /&gt;
 _caldav._tcp.MYSERVER.TLD.       10800 IN TXT   path=/servlet/dav&lt;br /&gt;
 _carddavs._tcp.MYSERVER.TLD.     10800 IN TXT   path=/servlet/dav&lt;br /&gt;
 _carddav._tcp.MYSERVER.TLD.      10800 IN TXT   path=/servlet/dav&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Installation on OX App Suite ==&lt;br /&gt;
&lt;br /&gt;
=== Debian GNU/Linux 9.0 ===&lt;br /&gt;
&lt;br /&gt;
Add the following entry to /etc/apt/sources.list.d/open-xchange.list if not already present:&lt;br /&gt;
&lt;br /&gt;
 deb https://software.open-xchange.com/products/appsuite/stable/backend/DebianStretch/ /&lt;br /&gt;
&lt;br /&gt;
 # if you have a valid maintenance subscription, please uncomment the &lt;br /&gt;
 # following and add the ldb account data to the url so that the most recent&lt;br /&gt;
 # packages get installed&lt;br /&gt;
 # deb https://[CUSTOMERID:PASSWORD]@software.open-xchange.com/products/appsuite/stable/backend/updates/DebianStretch/ /&lt;br /&gt;
&lt;br /&gt;
and run&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-dav&lt;br /&gt;
&lt;br /&gt;
=== Debian GNU/Linux 10.0 ===&lt;br /&gt;
&lt;br /&gt;
Add the following entry to /etc/apt/sources.list.d/open-xchange.list if not already present:&lt;br /&gt;
&lt;br /&gt;
 deb https://software.open-xchange.com/products/appsuite/stable/backend/DebianBuster/ /&lt;br /&gt;
&lt;br /&gt;
 # if you have a valid maintenance subscription, please uncomment the &lt;br /&gt;
 # following and add the ldb account data to the url so that the most recent&lt;br /&gt;
 # packages get installed&lt;br /&gt;
 # deb https://[CUSTOMERID:PASSWORD]@software.open-xchange.com/products/appsuite/stable/backend/updates/DebianBuster/ /&lt;br /&gt;
&lt;br /&gt;
and run&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-dav&lt;br /&gt;
&lt;br /&gt;
=== SUSE Linux Enterprise Server 12 (valid until 7.10.3)===&lt;br /&gt;
&lt;br /&gt;
Add the package repository using zypper if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ar https://software.open-xchange.com/products/appsuite/7.10.3/backend/SLE_12 ox&lt;br /&gt;
&lt;br /&gt;
If you have a valid maintenance subscription, please run the following command and add the ldb account data to the url so that the most recent packages get installed:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ar https://[CUSTOMERID:PASSWORD]@software.open-xchange.com/products/appsuite/7.10.3/backend/updates/SLES11 ox-updates&lt;br /&gt;
&lt;br /&gt;
and run&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&lt;br /&gt;
 $ zypper in open-xchange-dav&lt;br /&gt;
&lt;br /&gt;
=== RedHat Enterprise Linux 6 (valid until 7.10.3)===&lt;br /&gt;
&lt;br /&gt;
Start a console and create a software repository file if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ vim /etc/yum.repos.d/ox.repo&lt;br /&gt;
&lt;br /&gt;
 [ox]&lt;br /&gt;
 name=Open-Xchange&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/7.10.3/backend/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 # if you have a valid maintenance subscription, please uncomment the &lt;br /&gt;
 # following and add the ldb account data to the url so that the most recent&lt;br /&gt;
 # packages get installed&lt;br /&gt;
 # [ox-updates]&lt;br /&gt;
 # name=Open-Xchange Updates&lt;br /&gt;
 # baseurl=https://[CUSTOMERID:PASSWORD]@software.open-xchange.com/products/appsuite/7.10.3/backend/updates/RHEL6/&lt;br /&gt;
 # gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 # enabled=1&lt;br /&gt;
 # gpgcheck=1&lt;br /&gt;
 # metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and run&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-dav&lt;br /&gt;
&lt;br /&gt;
===RedHat Enterprise Linux 7 ===&lt;br /&gt;
&lt;br /&gt;
Start a console and create a software repository file if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ vim /etc/yum.repos.d/ox.repo&lt;br /&gt;
&lt;br /&gt;
 [ox]&lt;br /&gt;
 name=Open-Xchange&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/stable/backend/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 # if you have a valid maintenance subscription, please uncomment the &lt;br /&gt;
 # following and add the ldb account data to the url so that the most recent&lt;br /&gt;
 # packages get installed&lt;br /&gt;
 # [ox-updates]&lt;br /&gt;
 # name=Open-Xchange Updates&lt;br /&gt;
 # baseurl=https://[CUSTOMERID:PASSWORD]@software.open-xchange.com/products/appsuite/stable/backend/updates/RHEL7/&lt;br /&gt;
 # gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 # enabled=1&lt;br /&gt;
 # gpgcheck=1&lt;br /&gt;
 # metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and run&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-dav&lt;br /&gt;
&lt;br /&gt;
===CentOS 6 (valid until 7.10.3)===&lt;br /&gt;
&lt;br /&gt;
Start a console and create a software repository file if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ vim /etc/yum.repos.d/ox.repo&lt;br /&gt;
&lt;br /&gt;
 [ox]&lt;br /&gt;
 name=Open-Xchange&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/7.10.3/backend/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 # if you have a valid maintenance subscription, please uncomment the &lt;br /&gt;
 # following and add the ldb account data to the url so that the most recent&lt;br /&gt;
 # packages get installed&lt;br /&gt;
 # [ox-updates]&lt;br /&gt;
 # name=Open-Xchange Updates&lt;br /&gt;
 # baseurl=https://[CUSTOMERID:PASSWORD]@software.open-xchange.com/products/appsuite/7.10.3/backend/updates/RHEL6/&lt;br /&gt;
 # gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 # enabled=1&lt;br /&gt;
 # gpgcheck=1&lt;br /&gt;
 # metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and run&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-dav&lt;br /&gt;
&lt;br /&gt;
===CentOS 7===&lt;br /&gt;
&lt;br /&gt;
Start a console and create a software repository file if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ vim /etc/yum.repos.d/ox.repo&lt;br /&gt;
&lt;br /&gt;
 [ox]&lt;br /&gt;
 name=Open-Xchange&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/stable/backend/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 # if you have a valid maintenance subscription, please uncomment the &lt;br /&gt;
 # following and add the ldb account data to the url so that the most recent&lt;br /&gt;
 # packages get installed&lt;br /&gt;
 # [ox-updates]&lt;br /&gt;
 # name=Open-Xchange Updates&lt;br /&gt;
 # baseurl=https://[CUSTOMERID:PASSWORD]@software.open-xchange.com/products/appsuite/stable/backend/updates/RHEL7/&lt;br /&gt;
 # gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 # enabled=1&lt;br /&gt;
 # gpgcheck=1&lt;br /&gt;
 # metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and run&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-dav&lt;br /&gt;
&lt;br /&gt;
== CalDAV Configuration ==&lt;br /&gt;
&lt;br /&gt;
The following configuration options are available in the configuration files &amp;lt;code&amp;gt;caldav.properties&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;caldav.yml&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
===com.openexchange.caldav.enabled===&lt;br /&gt;
The property &#039;&#039;&#039;com.openexchange.caldav.enabled&#039;&#039;&#039; governs whether a user has access to the CalDAV interface. This can be configured along the config cascade, in the default setting, everyone that has access to the infostore also has access to caldav. This is achieved in the following way:&lt;br /&gt;
&lt;br /&gt;
/opt/open-xchange/etc/caldav.properties:&lt;br /&gt;
  com.openexchange.caldav.enabled=false&lt;br /&gt;
&lt;br /&gt;
/opt/open-xchange/etc/contextSets/caldav.yml&lt;br /&gt;
  premium:&lt;br /&gt;
      com.openexchange.caldav.enabled: true&lt;br /&gt;
      withTags: ucInfostore&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This means: In general CalDAV is turned off, but using the &amp;lt;code&amp;gt;contextSets&amp;lt;/code&amp;gt; feature of the config cascade it is turned on for everyone that has infostore access.&lt;br /&gt;
&lt;br /&gt;
===com.openexchange.caldav.tree===&lt;br /&gt;
Configures the ID of the folder tree used by the CalDAV interface. Currently, this should be set to the default value of &#039;0&#039;.&lt;br /&gt;
&lt;br /&gt;
===com.openexchange.caldav.interval.start===&lt;br /&gt;
Defines the minimum end time of appointments to be synchronized via the CalDAV interface, relative to the current date. Possible values are &amp;quot;one_month&amp;quot; (default), &amp;quot;one_year&amp;quot; and &amp;quot;six_months&amp;quot;.  &lt;br /&gt;
&lt;br /&gt;
===com.openexchange.caldav.interval.end===&lt;br /&gt;
Defines the maximum start time of appointments to be synchronized via the CalDAV interface, relative to the current date. Possible values are &amp;quot;one_year&amp;quot; (default) and &amp;quot;two_years&amp;quot;.  &lt;br /&gt;
&lt;br /&gt;
===com.openexchange.caldav.url===&lt;br /&gt;
Tells users where to find a caldav folder. This can be displayed in frontends. You can use the variables [hostname] and [folderId]. If you chose to deploy caldav as a virtual host (say &#039;dav.open-xchange.com&#039;) use https://dav.open-xchange.com/caldav/[folderId] as the value. If you are using user-agent sniffing use https://[hostname]/caldav/[folderId].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== CardDAV Configuration ==&lt;br /&gt;
&lt;br /&gt;
The following configuration options are available in the configuration files carddav.properties and carddav.yml:&lt;br /&gt;
&lt;br /&gt;
===com.openexchange.carddav.enabled===&lt;br /&gt;
Similarly to CalDAV, the property &#039;&#039;&#039;com.openexchange.carddav.enabled&#039;&#039;&#039; governs whether CardDAV is available for a certain user. This is configured exactly like CalDAV with the config cascade only enabling this for users that have access to the infostore:&lt;br /&gt;
&lt;br /&gt;
/opt/open-xchange/etc/carddav.properties:&lt;br /&gt;
  com.openexchange.carddav.enabled=false&lt;br /&gt;
&lt;br /&gt;
/opt/open-xchange/etc/contextSets/carddav.yml&lt;br /&gt;
  premium:&lt;br /&gt;
      com.openexchange.carddav.enabled: true&lt;br /&gt;
      withTags: ucInfostore&lt;br /&gt;
&lt;br /&gt;
===com.openexchange.carddav.ignoreFolders===&lt;br /&gt;
A comma-separated list of folder IDs to exclude from the synchronization. Use this to disable syncing of very large folders (e.g. the global address list in large contexts, which always has ID 6). By default, no folders are excluded.&lt;br /&gt;
&lt;br /&gt;
===com.openexchange.carddav.tree===&lt;br /&gt;
Configures the ID of the folder tree used by the CardDAV interface. Currently, this should be set to the default value of &#039;0&#039;.&lt;br /&gt;
&lt;br /&gt;
===com.openexchange.carddav.exposedCollections===&lt;br /&gt;
Controls which collections are exposed via the CardDAV interface. Possible values are &#039;0&#039;, &#039;1&#039; and &#039;2&#039;. A value of &#039;1&#039; makes each visible folder available as a resource collection, while &#039;2&#039; only exposes an aggregated collection containing  all contact resources from all visible folders. The default value &#039;0&#039; exposes either an aggregated collection or individual collections for each folder, depending on the client&#039;s user-agent that is matched against the pattern in &#039;userAgentForAggregatedCollection&#039;. &lt;br /&gt;
&lt;br /&gt;
===com.openexchange.carddav.userAgentForAggregatedCollection===&lt;br /&gt;
Regular expression to match against the client&#039;s user-agent to decide whether the aggregated collection is exposed or not. The default pattern matches all known varieties of the Mac OS Addressbook client, that doesn&#039;t support multiple collections. Only used if &#039;exposedCollections&#039; is set to &#039;0&#039;. The pattern is used case insensitive. &lt;br /&gt;
&lt;br /&gt;
===com.openexchange.carddav.reducedAggregatedCollection===&lt;br /&gt;
Specifies if all visible folders are used to create the aggregated collection, or if a reduced set of folders only containing the global addressbook and the personal contacts folders should be used. This setting only influences the aggregated collection that is used for clients that don&#039;t support multiple collections. Possible values are &#039;true&#039; and &#039;false.&lt;br /&gt;
&lt;br /&gt;
[[Category: Clients]]&lt;br /&gt;
[[Category: Administrator]]&lt;br /&gt;
[[Category: AppSuite]]&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:Mobile_API_Facade&amp;diff=25761</id>
		<title>AppSuite:Mobile API Facade</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:Mobile_API_Facade&amp;diff=25761"/>
		<updated>2021-02-11T16:17:47Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: /* Version Matrix */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Mobile API Facade =&lt;br /&gt;
&lt;br /&gt;
== General Information ==&lt;br /&gt;
&lt;br /&gt;
The Mobile API Facade is a server component that brings the new native mobile mail apps together with the OX App Suite. We’ve built the façade based on the technology used and proven in the OX App Suite middleware. The facade is developed in Java, utilizing the OSGI Framework.&lt;br /&gt;
&lt;br /&gt;
The Facade provides offline friendly HTTP interface by doing the work, the connections through the HTTP API, to the OX App Suite and providing only the data the offline capable clients need. In some cases multiple requests to the OX App Suite are combined into one for its clients.The facade also offers a method to tell the clients that information on the server haven’t changed since the last time the client asked for it. This reduces the amount of data to transmit to the clients under certain circumstances, especially important in mobile networks were bandwidth (and overall traffic) is limited. Thanks to facade some functionality can be shared among all clients and need only get implemented once. One example for this is the teaser text extraction, and HTML mail handling in general.The facade also provides a pluggable authentication system. In the default case, login request are just forwarded to the middleware. In more advanced use-cases, the login request is forwarded to IDM of the customer and an OX session is created from the access token from the IDM. For clients this is pretty straightforward.&lt;br /&gt;
&lt;br /&gt;
== License information ==&lt;br /&gt;
&lt;br /&gt;
=== Used 3rd party licenses ===&lt;br /&gt;
&lt;br /&gt;
In addition to the 3rd party software [https://www.open-xchange.com/legal/licenses-ox-app-suite/ used by AppSuite], the Mobile API Facade uses to following libraries:&lt;br /&gt;
&lt;br /&gt;
* [https://www.open-xchange.com/fileadmin/user_upload/images/portfolio/license/MIT_License_Generic.pdf Project Lombok (The MIT License]&lt;br /&gt;
* [https://www.open-xchange.com/fileadmin/user_upload/images/portfolio/license/MIT_License_Generic.pdf Semver4J (The MIT License)]&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
The Mobile API Facade has to be installed alongside an OX App Suite installation. It requires at least OX App Suite v7.8.4.&lt;br /&gt;
&lt;br /&gt;
== Version Matrix ==&lt;br /&gt;
{|border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&lt;br /&gt;
|- &lt;br /&gt;
|colspan=1|&#039;&#039;&#039;OX App Suite Core Version&#039;&#039;&#039;&lt;br /&gt;
|colspan=1|&#039;&#039;&#039;Mobile API Facade Version&#039;&#039;&#039;&lt;br /&gt;
|colspan=1|&#039;&#039;&#039;Version-Stream&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|v7.8.4&lt;br /&gt;
|v1.0.x&lt;br /&gt;
|stable-1.0&lt;br /&gt;
|-&lt;br /&gt;
|v7.10.1&lt;br /&gt;
|v1.4.x&lt;br /&gt;
|stable-1.4&lt;br /&gt;
|-&lt;br /&gt;
|v7.10.2&lt;br /&gt;
|v1.6.x&lt;br /&gt;
|stable-1.6&lt;br /&gt;
|-&lt;br /&gt;
|v7.10.3&lt;br /&gt;
|v1.8.x&lt;br /&gt;
|stable-1.8&lt;br /&gt;
|-&lt;br /&gt;
|v7.10.4&lt;br /&gt;
|v1.10.x&lt;br /&gt;
|stable-1.10&lt;br /&gt;
|-&lt;br /&gt;
|v7.10.5&lt;br /&gt;
|v1.12.x&lt;br /&gt;
|stable-1.12&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Mobile API Facade API ==&lt;br /&gt;
&lt;br /&gt;
Further information about the Mobile API Facade API can be found at:&lt;br /&gt;
https://documentation.open-xchange.com/components/facade/1.0.0/&lt;br /&gt;
&lt;br /&gt;
= OX Mail Server-side Installation and Configuration on OX App Suite v7.10.3 =&lt;br /&gt;
&lt;br /&gt;
This chapter describes how the backend components of OX Mail are installed and configured on the server.&lt;br /&gt;
&lt;br /&gt;
== Available packages ==&lt;br /&gt;
&lt;br /&gt;
Mobile API Facade is available with the following backend packages:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;open-xchange-mobile-api-facade&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Installation on the server varies depending on the underlying distribution, details are available in the following chapters.&lt;br /&gt;
&lt;br /&gt;
=== Redhat Enterprise Linux 6 or CentOS 6 ===&lt;br /&gt;
&lt;br /&gt;
Add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 {{for loop||call=YUMRepo|pv=reponame|pc1n=path|pc1v=products/mobile-api-facade/stable-1.8|pc2n=rhelname|pc2v=RHEL6|mobile-api-facade}}&lt;br /&gt;
&lt;br /&gt;
 $ yum install open-xchange-mobile-api-facade&lt;br /&gt;
 &lt;br /&gt;
=== Redhat Enterprise Linux 7 or CentOS 7 ===&lt;br /&gt;
&lt;br /&gt;
Add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 {{for loop||call=YUMRepo|pv=reponame|pc1n=path|pc1v=products/mobile-api-facade/stable-1.8|pc2n=rhelname|pc2v=RHEL7|mobile-api-facade}}&lt;br /&gt;
&lt;br /&gt;
 $ yum install open-xchange-mobile-api-facade&lt;br /&gt;
&lt;br /&gt;
=== Debian GNU/Linux 9.0 ===&lt;br /&gt;
&lt;br /&gt;
Add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 {{for loop||call=APTRepo|pv=reponame|pc1n=path|pc1v=products/mobile-api-facade/stable-1.8|pc2n=debianname|pc2v=DebianStretch|mobile-api-facade}}&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-mobile-api-facade&lt;br /&gt;
&lt;br /&gt;
=== Debian GNU/Linux 10.0 ===&lt;br /&gt;
&lt;br /&gt;
Add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 {{for loop||call=APTRepo|pv=reponame|pc1n=path|pc1v=products/mobile-api-facade/stable-1.8|pc2n=debianname|pc2v=DebianBuster|mobile-api-facade}}&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-mobile-api-facade&lt;br /&gt;
&lt;br /&gt;
=== SUSE Linux Enterprise Server 12 === &lt;br /&gt;
&lt;br /&gt;
 {{for loop||call=SUSERepo|pv=reponame|pc1n=path|pc1v=products/mobile-api-facade/stable-1.8|pc2n=susename|pc2v=SLE_12|mobile-api-facade}}&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&lt;br /&gt;
 $ zypper install open-xchange-mobile-api-facade&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= OX Mail Server-side Installation and Configuration on OX App Suite 7.8.x and 7.10.x =&lt;br /&gt;
&lt;br /&gt;
If you want to update an older version of OX Mobile API Facade to the latest maintenance release, add the following entry to &amp;lt;tt&amp;gt;/etc/apt/sources.list.d/open-xchange.list&amp;lt;/tt&amp;gt;. Replace VERSION with the link for the stream of versions as listed above in the version matrix (e.g. stable-1.8) or a specific version you are using (e.g. 1.8.3).&lt;br /&gt;
&lt;br /&gt;
This chapter describes how the backend components of OX Mail are installed and configured on the server.&lt;br /&gt;
&lt;br /&gt;
== Available packages ==&lt;br /&gt;
&lt;br /&gt;
Mobile API Facade is available with the following backend packages:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;open-xchange-mobile-api-facade&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Installation on the server varies depending on the underlying distribution, details are available in the following chapters.&lt;br /&gt;
&lt;br /&gt;
=== Redhat Enterprise Linux 6 or CentOS 6 ===&lt;br /&gt;
&lt;br /&gt;
Add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 {{for loop||call=YUMRepo|pv=reponame|pc1n=path|pc1v=products/mobile-api-facade/VERSION|pc2n=rhelname|pc2v=RHEL6|mobile-api-facade}}&lt;br /&gt;
&lt;br /&gt;
 $ yum install open-xchange-mobile-api-facade&lt;br /&gt;
 &lt;br /&gt;
=== Redhat Enterprise Linux 7 or CentOS 7 ===&lt;br /&gt;
&lt;br /&gt;
Add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 {{for loop||call=YUMRepo|pv=reponame|pc1n=path|pc1v=products/mobile-api-facade/VERSION|pc2n=rhelname|pc2v=RHEL7|mobile-api-facade}}&lt;br /&gt;
&lt;br /&gt;
 $ yum install open-xchange-mobile-api-facade&lt;br /&gt;
&lt;br /&gt;
=== Debian GNU/Linux 8.0 ===&lt;br /&gt;
&lt;br /&gt;
Add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 {{for loop||call=APTRepo|pv=reponame|pc1n=path|pc1v=products/mobile-api-facade/VERSION|pc2n=debianname|pc2v=DebianJessie|mobile-api-facade}}&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-mobile-api-facade&lt;br /&gt;
&lt;br /&gt;
=== Debian GNU/Linux 9.0 ===&lt;br /&gt;
&lt;br /&gt;
Add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 {{for loop||call=APTRepo|pv=reponame|pc1n=path|pc1v=products/mobile-api-facade/VERSION|pc2n=debianname|pc2v=DebianStretch|mobile-api-facade}}&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-mobile-api-facade&lt;br /&gt;
&lt;br /&gt;
=== Debian GNU/Linux 10.0 ===&lt;br /&gt;
&lt;br /&gt;
Add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 {{for loop||call=APTRepo|pv=reponame|pc1n=path|pc1v=products/mobile-api-facade/VERSION|pc2n=debianname|pc2v=DebianBuster|mobile-api-facade}}&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-mobile-api-facade&lt;br /&gt;
&lt;br /&gt;
=== SUSE Linux Enterprise Server 12 === &lt;br /&gt;
&lt;br /&gt;
 {{for loop||call=SUSERepo|pv=reponame|pc1n=path|pc1v=products/mobile-api-facade/VERSION|pc2n=susename|pc2v=SLE_12|mobile-api-facade}}&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&lt;br /&gt;
 $ zypper install open-xchange-mobile-api-facade&lt;br /&gt;
&lt;br /&gt;
= Configuration Mobile API Facade =&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
To be able to use the native mail apps the Mobile API Facade needs to be installed in front of the OX App Suite middleware. This document describes how to configure the Mobile API Facade.&lt;br /&gt;
&lt;br /&gt;
The Mobile API Facade stores its configuration in the files &amp;lt;code&amp;gt;/opt/open-xchange/mobile-api-facade/etc/facade.properties&amp;lt;/code&amp;gt; (the global configuration) and in &amp;lt;code&amp;gt;/opt/open-xchange/mobile-api-facade/etc/mobile-api-facade-config.yml&amp;lt;/code&amp;gt; (hostname specific configuration). Both files support the same configuration properties as can be seen on https://documentation.open-xchange.com/components/mobile-api-facade/config/1.8/.&lt;br /&gt;
&lt;br /&gt;
== Connection to the OX App Suite Middleware ==&lt;br /&gt;
&lt;br /&gt;
After installation of the facade package (&amp;quot;open-xchange-mobile-api-facade&amp;quot;) the property &amp;lt;code&amp;gt;com.openexchange.mobile.api.facade.MiddlewareBaseUrl&amp;lt;/code&amp;gt; needs to get set to the correct URL. This property needs to be explicitly configured by the administrator. It has no default value. Its possible to connect the Mobile API Facade directly to a middleware process, but this is highly discouraged. The Mobile API Facade should always connect to a middleware process through a load balancer.&lt;br /&gt;
&lt;br /&gt;
An example:&lt;br /&gt;
&lt;br /&gt;
 com.openexchange.mobile.api.facade.MiddlewareBaseUrl=https://appsuite.example.com/appsuite/api&lt;br /&gt;
&lt;br /&gt;
After this configuration the open-xchange-mobile-api-facade needs to get restarted.&lt;br /&gt;
&lt;br /&gt;
== Proxy configuration ==&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;Proxy balancer://oxcluster_facade&amp;gt;&lt;br /&gt;
         Order Allow,Deny&lt;br /&gt;
         Allow from all&lt;br /&gt;
         BalancerMember http://appsuite-middleware1.example.com:8007 timeout=100 smax=0 ttl=60 retry=60 loadfactor=50 keepalive=On route=FOX1&lt;br /&gt;
         BalancerMember http://appsuite-middleware2.example.com:8007 timeout=100 smax=0 ttl=60 retry=60 loadfactor=50 keepalive=On route=FOX2&lt;br /&gt;
 &lt;br /&gt;
         ProxySet stickysession=JSESSIONID|jsessionidscolonpathdelim=On&lt;br /&gt;
         SetEnv proxy-initial-not-pooled&lt;br /&gt;
         SetEnv proxy-sendchunked&lt;br /&gt;
 &amp;lt;/Proxy&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
 ProxyPass /services/api-facade balancer://oxcluster_facade/services/api-facade&lt;br /&gt;
&lt;br /&gt;
== Traffic compression ==&lt;br /&gt;
&lt;br /&gt;
The clients need to exchange a lot of data with the facade to accomplish the task of a mail client. This traffic can be compressed. Clients add the header &amp;quot;Accept-Encoding: gzip,deflate&amp;quot; by default. For this to work the Apache web server in front of the facade needs to handle this as the facade itself is not returning compressed response bodies.&lt;br /&gt;
&lt;br /&gt;
For Apache HTTPD &amp;lt;code&amp;gt;{mod_deflate}&amp;lt;/code&amp;gt; needs to be enabled and the following line needs to be added to your virtual host:&lt;br /&gt;
&lt;br /&gt;
 AddOutputFilterByType DEFLATE text/html text/plain text/javascript application/javascript text/css &lt;br /&gt;
 text/xml application/xml text/x-js application/x-javascript application/json&lt;br /&gt;
&lt;br /&gt;
== Starting/Stopping the Facade Service ==&lt;br /&gt;
&lt;br /&gt;
The facade runs as its own service independent of the normal OX App Suite middleware. For this on Debian-based system it can be started with&lt;br /&gt;
&lt;br /&gt;
 service open-xchange-mobile-api-facade start&lt;br /&gt;
&lt;br /&gt;
It can be stopped with&lt;br /&gt;
&lt;br /&gt;
 service open-xchange-mobile-api-facade stop&lt;br /&gt;
&lt;br /&gt;
== Rereading configuration from disk ==&lt;br /&gt;
&lt;br /&gt;
All configuration properties which are marked as reloadable can be configured without restarting the Mobile API Facade by using the &amp;lt;code&amp;gt;reloadconfiguration&amp;lt;/code&amp;gt; utility. As the Mobile API Facade runs in its own process you need to tell &amp;lt;code&amp;gt;reloadconfiguration&amp;lt;/code&amp;gt; to connect it instead of the Middleware. This can be done by:&lt;br /&gt;
&lt;br /&gt;
 reloadconfiguration -p 1100&lt;br /&gt;
&lt;br /&gt;
== Ports ==&lt;br /&gt;
&lt;br /&gt;
As the Mobile API Facade is its own process it also has its own JMX port and its own RMI port. The default JMX port is 9995 and the default RMI port is 1100. These ports needs to be explicitly specified to the command line tools using either JMX or RMI.&lt;br /&gt;
&lt;br /&gt;
== Configuration of Mobile API Facade behavior ==&lt;br /&gt;
&lt;br /&gt;
This can be configured in facade.properties and mobile-api-facade-config.yml.&lt;br /&gt;
&lt;br /&gt;
=== Multiple host names ===&lt;br /&gt;
&lt;br /&gt;
The Mobile API Facade supports multiple host names on one instance, that are configured differently. These can be configured in mobile-api-facade-config.yml. This file in YAML format. Beware that indentation is really important in YAML.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[ host name ]:&lt;br /&gt;
	[ properties, you want to configure ]&lt;br /&gt;
&lt;br /&gt;
[ host name ]:&lt;br /&gt;
	[ properties, you want to configure ]&lt;br /&gt;
&lt;br /&gt;
...&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The allowed properties are the same as allowed in facade.properties. You can find a complete list at https://documentation.open-xchange.com/components/mobile-api-facade/config/1.8/.&lt;br /&gt;
&lt;br /&gt;
=== Custom properties ===&lt;br /&gt;
&lt;br /&gt;
It&#039;s possible to configure custom properties to be returned to clients. This is usefull to return special configurations to your clients. Custom properties are key/attribute values under the &amp;quot;customProperties&amp;quot; key.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
appsuite.example.com:&lt;br /&gt;
    customProperties:&lt;br /&gt;
        custom.specific.property: true&lt;br /&gt;
        custom.specific.property.2: &amp;quot;value&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Client specific configuration ===&lt;br /&gt;
&lt;br /&gt;
By implementing the  client specific feature the above configuration possibilities got extended. We now have to use YAML lists for each host name. This allows to add multiple different configurations to one host configuration. You can add a list of matchers in the &amp;quot;matches&amp;quot; key to a host configuration. The first &amp;quot;matches&amp;quot; entry for a given host name that matches to the given User-Agent header sent by the client will be used. Further evaluation is not done at runtime. Configuration properties need to be on the same indentation level as the &amp;quot;matches&amp;quot; key. These host configurations inherit a default configuration from the configuration in facade.properties. Otherwise they need to be complete. They don&#039;t inherit configuration properties from other places.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[ host name ]:&lt;br /&gt;
	- matches:&lt;br /&gt;
		  [ matchers, you want to match against ]&lt;br /&gt;
		  [ properties, you want to configure ]&lt;br /&gt;
	- matches:&lt;br /&gt;
		  [ matchers, you want to match against ]&lt;br /&gt;
		  [ properties, you want to configure ]&lt;br /&gt;
	...&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
The iOS version supported in the beginning was iOS 9 and up. At some point in time due to technical reasons support for iOS 9 and 10 was dropped and the application supported iOS 11 and up. When you now want to update all installations on iOS 11 and up to the latest app version but leave old installations in intact you can use the force upgrade feature of the apps. Keep in mind that the matching process stops when the first match is found. If no match was found the default configuration is used.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
appsuite.example.com:&lt;br /&gt;
	- matches:&lt;br /&gt;
		  platform: &#039;iOS&#039;&lt;br /&gt;
		  osVersion: &#039;11.0-&#039;&lt;br /&gt;
          brand: &#039;OpenXchange&#039;&lt;br /&gt;
	  com.openexchange.mobile.api.facade.minimumClientVersion.ios: &#039;11.2&#039;&lt;br /&gt;
	  com.openexchange.mobile.api.facade.returnNonPrimaryAccounts: false&lt;br /&gt;
	- matches:&lt;br /&gt;
		  platform: &#039;iOS&#039;&lt;br /&gt;
		  osVersion: &#039;-10.99&#039;&lt;br /&gt;
		  brand: &#039;OpenXchange&#039;&lt;br /&gt;
	  com.openexchange.mobile.api.facade.returnNonPrimaryAccounts: false&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Matchers ===&lt;br /&gt;
&lt;br /&gt;
Several matchers are possible. All match against values in the User-Agent header.&lt;br /&gt;
&lt;br /&gt;
- platform: This matcher allows it to match only for &amp;quot;Android&amp;quot; or &amp;quot;iOS&amp;quot;&lt;br /&gt;
- version: This matcher checks against the application version. This is not the marketing version displayed in the About screen of the application.&lt;br /&gt;
- osVersion: The version of the operating system on the client device&lt;br /&gt;
- device: This matches against the exact device model.&lt;br /&gt;
    brand: This matches against the brand name of the app. By default this is &amp;quot;OpenXchange&amp;quot;. Versions specifically branded for customers have a unique brand name.&lt;br /&gt;
&lt;br /&gt;
=== Version matching ===&lt;br /&gt;
&lt;br /&gt;
For the matchers &#039;version&#039; and &#039;osVersion&#039; we allow to match concrete versions or version ranges. When adding a matcher with a concrete version, just put the version number as string attribute after the matcher name.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
appsuite.example.com:&lt;br /&gt;
	- matches:&lt;br /&gt;
		  platform: &#039;iOS&#039;&lt;br /&gt;
		  osVersion: &#039;11.0&#039;&lt;br /&gt;
	  com.openexchange.mobile.api.facade.returnNonPrimaryAccounts: false&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
When matching a range we are always matching inclusive. You can either use a closed range, a range with a given start value and an end value, or an open range with either a start value or an end value. Keep in mind that to match all versions lower then &#039;11.0&#039; you need use a probably non-existing version number like &#039;10.99&#039;.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
appsuite.example.com:&lt;br /&gt;
	- matches:&lt;br /&gt;
		  platform: &#039;iOS&#039;&lt;br /&gt;
		  osVersion: &#039;11.0-&#039;&lt;br /&gt;
	  com.openexchange.mobile.api.facade.returnNonPrimaryAccounts: true&lt;br /&gt;
	- matches:&lt;br /&gt;
		  platform: &#039;iOS&#039;&lt;br /&gt;
		  osVersion: &#039;-10.99&#039;&lt;br /&gt;
	  com.openexchange.mobile.api.facade.returnNonPrimaryAccounts: false&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Debugging ==&lt;br /&gt;
&lt;br /&gt;
In order to check whether installation went successful you may want to run&lt;br /&gt;
&lt;br /&gt;
   $ curl -v http://localhost:8007/services/api-facade/v1/version&lt;br /&gt;
&lt;br /&gt;
That should return a JSON string like this:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
{&amp;quot;version&amp;quot;:&amp;quot;1.6.8&amp;quot;,&amp;quot;commitHash&amp;quot;:&amp;quot;9e90d6072407b73c3e05b86ce724962af1a3de61&amp;quot;,&amp;quot;middlewareVersion&amp;quot;:&amp;quot;7.10.2-Rev15&amp;quot;}&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=Mailclient_autoconfiguration&amp;diff=25693</id>
		<title>Mailclient autoconfiguration</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=Mailclient_autoconfiguration&amp;diff=25693"/>
		<updated>2021-01-22T11:26:59Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: /* Installation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Providing autoconfiguration for mail clients =&lt;br /&gt;
&lt;br /&gt;
This article explains a solution for autoconfiguration for a set of mail clients which can be configured against a mail system automatically by just entering email address and password. There are three widely used approaches to do this via a self hosted lookup method, based on Microsoft&#039;s autodiscover, [https://developer.mozilla.org/en-US/docs/Mozilla/Thunderbird/Autoconfiguration Mozilla&#039;s autoconfig], and iOS/MacOS provisioning which are relevant to support detecting IMAP and SMTP server details for client configuration. Another option is solely based on DNS SRV discovery ([https://tools.ietf.org/html/rfc6186 RFC 6186]).&lt;br /&gt;
&lt;br /&gt;
Since [[AppSuite:EM_Client_for_OX_App_Suite|eMClient for OX App Suite]] is using the Microsoft based solution this service is especially important to have a smooth user experience for customer environments offering it to their users.&lt;br /&gt;
&lt;br /&gt;
autodiscover and autoconfig are based on XML schemas. Therefore for very simple deployments it might even be enough to serve some static XML files for both usecases. Please see the respective vendor standard documentation for more details.&lt;br /&gt;
&lt;br /&gt;
In this article we show how to deploy a simple autoconfiguration service based on the open source solution [https://automx.org/en/ automx].&lt;br /&gt;
&lt;br /&gt;
== Preparations ==&lt;br /&gt;
&lt;br /&gt;
The autoconfiguration protocols use several ways to find the XML provided later by automx. In the following section there is listed in which order the protocols are looking for the XML. Depending where you would like to serve the XML files you can choose from those options.&lt;br /&gt;
&lt;br /&gt;
The domain example.org as in those examples are the ones taken from the entered email address.&lt;br /&gt;
&lt;br /&gt;
=== autoconfig ===&lt;br /&gt;
&lt;br /&gt;
# http://autoconfig.example.org/mail/config-v1.1.xml&lt;br /&gt;
# http://example.org/.well-known/autoconfig/mail/config-v1.1.xml&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== autodiscover ===&lt;br /&gt;
&lt;br /&gt;
# https://example.org/autodiscover/autodiscover.xml&lt;br /&gt;
# https://autodiscover.example.org/autodiscover/autodiscover.xml&lt;br /&gt;
# DNS SRV lookup for autodiscover.tcp.example.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== DNS SRV ===&lt;br /&gt;
&lt;br /&gt;
A DNS SRV entry for autodiscover would look like this:&lt;br /&gt;
&lt;br /&gt;
  _autodiscover._tcp                      IN      SRV 0 0 443 $HOSTNAME.example.org.&lt;br /&gt;
&lt;br /&gt;
The following DNS SRV records can be used to provide configuration hints for mail clients supporting RFC 6186:&lt;br /&gt;
&lt;br /&gt;
  _submission._tcp     SRV 0 1 587 mail.example.org.&lt;br /&gt;
  _imap._tcp           SRV 2 1 143 imap.example.org.&lt;br /&gt;
  _imaps._tcp          SRV 1 1 993 imap.example.org.&lt;br /&gt;
  _pop3._tcp           SRV 4 1 110 pop3.example.org.&lt;br /&gt;
  _pop3s._tcp          SRV 3 1 995 pop3.example.org.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== automx ==&lt;br /&gt;
&lt;br /&gt;
=== Installation ===&lt;br /&gt;
&lt;br /&gt;
If you would like to support eMClient for OX App Suite please make sure that you are using a version after 1.1.1 or an earlier patched version which supports the DAV and OX services.&lt;br /&gt;
Also please note that the current versions of automx2 do neither support DAV nor the OX service extensions for autodiscover. It currently only supports IMAP and SMTP services.&lt;br /&gt;
&lt;br /&gt;
For manual installation please refer to the [https://automx.org/en/#download automx download instructions].&lt;br /&gt;
&lt;br /&gt;
RPM packages for SUSE and RHEL flavours are provided by the [https://software.opensuse.org/package/automx Open Build Service]. Those packages are currently version 0.10.2 with the above patches applied and are working with Python 2.&lt;br /&gt;
&lt;br /&gt;
=== Configuration ===&lt;br /&gt;
&lt;br /&gt;
==== automx ====&lt;br /&gt;
&lt;br /&gt;
Please find detailed documentation via &#039;&#039;&#039;man automx.conf&#039;&#039;&#039; and for more dynamic setups automx_script, automx_ldap and automx_sql.&lt;br /&gt;
&lt;br /&gt;
/etc/automx.conf:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
[automx]&lt;br /&gt;
provider = example.org&lt;br /&gt;
domains = example.org, example.com&lt;br /&gt;
debug = no&lt;br /&gt;
logfile = /var/log/automx/automx.log&lt;br /&gt;
&lt;br /&gt;
# Protect against DoS&lt;br /&gt;
memcache = 127.0.0.1:11211&lt;br /&gt;
memcache_ttl = 600&lt;br /&gt;
client_error_limit = 20&lt;br /&gt;
rate_limit_exception_networks = 127.0.0.0/8, ::1/128&lt;br /&gt;
&lt;br /&gt;
# The DEFAULT section is always merged into each other section. Each section&lt;br /&gt;
# can overwrite settings done here.&lt;br /&gt;
[DEFAULT]&lt;br /&gt;
account_type = email&lt;br /&gt;
account_name = example Mail&lt;br /&gt;
account_name_short = example Mail&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
# If a domain is listed in the automx section, it may have its own section. If&lt;br /&gt;
# none is found here, the global section is used.&lt;br /&gt;
[global]&lt;br /&gt;
backend = static&lt;br /&gt;
action = settings&lt;br /&gt;
&lt;br /&gt;
# EAS (mobilesync)&lt;br /&gt;
server_url = https://eas.example.org&lt;br /&gt;
server_name = example&lt;br /&gt;
&lt;br /&gt;
# If you want to sign mobileconfig profiles, enable these options. Make sure&lt;br /&gt;
# that your webserver has proper privileges to read the key. The cert file&lt;br /&gt;
# must contain the server certificate and all intermediate certificates. You&lt;br /&gt;
# can simply concatenate these certificates.&lt;br /&gt;
#sign_mobileconfig = yes&lt;br /&gt;
#sign_cert = /path/to/cert&lt;br /&gt;
#sign_key = /path/to/key&lt;br /&gt;
&lt;br /&gt;
smtp = yes&lt;br /&gt;
smtp_server = mail.example.org&lt;br /&gt;
smtp_port = 587&lt;br /&gt;
smtp_encryption = starttls&lt;br /&gt;
smtp_auth = plaintext&lt;br /&gt;
smtp_auth_identity = %s&lt;br /&gt;
smtp_refresh_ttl = 6&lt;br /&gt;
smtp_default = yes&lt;br /&gt;
&lt;br /&gt;
imap = yes&lt;br /&gt;
imap_server = mail.example.org&lt;br /&gt;
imap_port = 993&lt;br /&gt;
imap_encryption = ssl&lt;br /&gt;
imap_auth = plaintext&lt;br /&gt;
imap_auth_identity = %s&lt;br /&gt;
imap_refresh_ttl = 6&lt;br /&gt;
pop = yes&lt;br /&gt;
pop_server = mail.example.org&lt;br /&gt;
pop_port = 995&lt;br /&gt;
pop_encryption = ssl&lt;br /&gt;
pop_auth = plaintext&lt;br /&gt;
pop_auth_identity = %s&lt;br /&gt;
pop_refresh_ttl = 6&lt;br /&gt;
&lt;br /&gt;
carddav = yes&lt;br /&gt;
carddav_server = https://dav.example.org/&lt;br /&gt;
carddav_auth_identity = %s&lt;br /&gt;
&lt;br /&gt;
caldav = yes&lt;br /&gt;
caldav_server = https://dav.example.org/&lt;br /&gt;
caldav_auth_identity = %s&lt;br /&gt;
&lt;br /&gt;
ox = yes&lt;br /&gt;
ox_server = https://ox.example.org/&lt;br /&gt;
ox_auth_identity = %s&lt;br /&gt;
&lt;br /&gt;
follow = imap_starttls&lt;br /&gt;
&lt;br /&gt;
[imap_starttls]&lt;br /&gt;
backend = static_append&lt;br /&gt;
&lt;br /&gt;
imap = yes&lt;br /&gt;
imap_server = mail.example.org&lt;br /&gt;
imap_port = 143&lt;br /&gt;
imap_encryption = starttls&lt;br /&gt;
imap_auth = plaintext&lt;br /&gt;
imap_auth_identity = %s&lt;br /&gt;
imap_refresh_ttl = 6&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Apache ====&lt;br /&gt;
&lt;br /&gt;
e.g. /etc/{apache2,httpd}/conf.d/automx.conf:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
&amp;lt;IfModule mod_wsgi.c&amp;gt;&lt;br /&gt;
    WSGIChunkedRequest On&lt;br /&gt;
&lt;br /&gt;
    WSGIScriptAliasMatch \&lt;br /&gt;
      (?i)^/.+/(autodiscover|config-v1.1).xml \&lt;br /&gt;
      /usr/lib/automx/automx_wsgi.py&lt;br /&gt;
&lt;br /&gt;
    WSGIScriptAlias \&lt;br /&gt;
      /mobileconfig \&lt;br /&gt;
      /usr/lib/automx/automx_wsgi.py&lt;br /&gt;
&lt;br /&gt;
    &amp;lt;Directory &amp;quot;/usr/lib/automx&amp;quot;&amp;gt;&lt;br /&gt;
            Require all granted&lt;br /&gt;
    &amp;lt;/Directory&amp;gt;&lt;br /&gt;
&amp;lt;/IfModule&amp;gt;&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In case the iOS/MacOS web provisioning should be provided there should also be a /etc/{apache2,httpd}/conf.d/automx-web.conf:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
Alias /automx &amp;quot;/usr/share/automx/&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;Directory &amp;quot;/usr/share/automx&amp;quot;&amp;gt;&lt;br /&gt;
    Options Indexes MultiViews&lt;br /&gt;
    Require all granted&lt;br /&gt;
&amp;lt;/Directory&amp;gt;&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
eMClient for OX App Suite has a special requirement to make the autoconfiguration experience nice and straightforward. To make it ask directly for a password instead of later in the setup process (where it requires a restart of the application to be fully functional) it is required to protect the autodiscover.xml via basic auth. In our scenario there is nothing to protect really so in this example we allow any credentials for access but still ask for some.&lt;br /&gt;
&lt;br /&gt;
For this add the following section to /etc/{apache2,httpd}/conf.d/automx.conf:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
    &amp;lt;Location &amp;quot;/autodiscover/autodiscover.xml&amp;quot;&amp;gt;&lt;br /&gt;
            AuthType Basic&lt;br /&gt;
            AuthName &amp;quot;Restricted&amp;quot;&lt;br /&gt;
            AuthBasicProvider anon&lt;br /&gt;
            Anonymous_NoUserID off&lt;br /&gt;
            Anonymous_MustGiveEmail off&lt;br /&gt;
            Anonymous_VerifyEmail off&lt;br /&gt;
            Anonymous_LogEmail off&lt;br /&gt;
            Anonymous *&lt;br /&gt;
            Require valid-user&lt;br /&gt;
    &amp;lt;/Location&amp;gt;&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Related links ==&lt;br /&gt;
&lt;br /&gt;
[[Caldav_carddav_Bundles#Autodiscovery|DAV autodiscovery]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: Clients]]&lt;br /&gt;
[[Category: Administrator]]&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=Mailclient_autoconfiguration&amp;diff=25692</id>
		<title>Mailclient autoconfiguration</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=Mailclient_autoconfiguration&amp;diff=25692"/>
		<updated>2021-01-22T11:26:37Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: /* automx */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Providing autoconfiguration for mail clients =&lt;br /&gt;
&lt;br /&gt;
This article explains a solution for autoconfiguration for a set of mail clients which can be configured against a mail system automatically by just entering email address and password. There are three widely used approaches to do this via a self hosted lookup method, based on Microsoft&#039;s autodiscover, [https://developer.mozilla.org/en-US/docs/Mozilla/Thunderbird/Autoconfiguration Mozilla&#039;s autoconfig], and iOS/MacOS provisioning which are relevant to support detecting IMAP and SMTP server details for client configuration. Another option is solely based on DNS SRV discovery ([https://tools.ietf.org/html/rfc6186 RFC 6186]).&lt;br /&gt;
&lt;br /&gt;
Since [[AppSuite:EM_Client_for_OX_App_Suite|eMClient for OX App Suite]] is using the Microsoft based solution this service is especially important to have a smooth user experience for customer environments offering it to their users.&lt;br /&gt;
&lt;br /&gt;
autodiscover and autoconfig are based on XML schemas. Therefore for very simple deployments it might even be enough to serve some static XML files for both usecases. Please see the respective vendor standard documentation for more details.&lt;br /&gt;
&lt;br /&gt;
In this article we show how to deploy a simple autoconfiguration service based on the open source solution [https://automx.org/en/ automx].&lt;br /&gt;
&lt;br /&gt;
== Preparations ==&lt;br /&gt;
&lt;br /&gt;
The autoconfiguration protocols use several ways to find the XML provided later by automx. In the following section there is listed in which order the protocols are looking for the XML. Depending where you would like to serve the XML files you can choose from those options.&lt;br /&gt;
&lt;br /&gt;
The domain example.org as in those examples are the ones taken from the entered email address.&lt;br /&gt;
&lt;br /&gt;
=== autoconfig ===&lt;br /&gt;
&lt;br /&gt;
# http://autoconfig.example.org/mail/config-v1.1.xml&lt;br /&gt;
# http://example.org/.well-known/autoconfig/mail/config-v1.1.xml&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== autodiscover ===&lt;br /&gt;
&lt;br /&gt;
# https://example.org/autodiscover/autodiscover.xml&lt;br /&gt;
# https://autodiscover.example.org/autodiscover/autodiscover.xml&lt;br /&gt;
# DNS SRV lookup for autodiscover.tcp.example.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== DNS SRV ===&lt;br /&gt;
&lt;br /&gt;
A DNS SRV entry for autodiscover would look like this:&lt;br /&gt;
&lt;br /&gt;
  _autodiscover._tcp                      IN      SRV 0 0 443 $HOSTNAME.example.org.&lt;br /&gt;
&lt;br /&gt;
The following DNS SRV records can be used to provide configuration hints for mail clients supporting RFC 6186:&lt;br /&gt;
&lt;br /&gt;
  _submission._tcp     SRV 0 1 587 mail.example.org.&lt;br /&gt;
  _imap._tcp           SRV 2 1 143 imap.example.org.&lt;br /&gt;
  _imaps._tcp          SRV 1 1 993 imap.example.org.&lt;br /&gt;
  _pop3._tcp           SRV 4 1 110 pop3.example.org.&lt;br /&gt;
  _pop3s._tcp          SRV 3 1 995 pop3.example.org.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== automx ==&lt;br /&gt;
&lt;br /&gt;
=== Installation ===&lt;br /&gt;
&lt;br /&gt;
If you would like to support eMClient for OX App Suite please make sure that you are using a version after 1.1.1 or an earlier patched version which supports the DAV and OX services. automx2 does not have any support for anything but mail protocols yet and is not sufficient.&lt;br /&gt;
Also please note that the current versions of automx2 do neither support DAV nor the OX service extensions for autodiscover. It currently only supports IMAP and SMTP services.&lt;br /&gt;
&lt;br /&gt;
For manual installation please refer to the [https://automx.org/en/#download automx download instructions].&lt;br /&gt;
&lt;br /&gt;
RPM packages for SUSE and RHEL flavours are provided by the [https://software.opensuse.org/package/automx Open Build Service]. Those packages are currently version 0.10.2 with the above patches applied and are working with Python 2.&lt;br /&gt;
&lt;br /&gt;
=== Configuration ===&lt;br /&gt;
&lt;br /&gt;
==== automx ====&lt;br /&gt;
&lt;br /&gt;
Please find detailed documentation via &#039;&#039;&#039;man automx.conf&#039;&#039;&#039; and for more dynamic setups automx_script, automx_ldap and automx_sql.&lt;br /&gt;
&lt;br /&gt;
/etc/automx.conf:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
[automx]&lt;br /&gt;
provider = example.org&lt;br /&gt;
domains = example.org, example.com&lt;br /&gt;
debug = no&lt;br /&gt;
logfile = /var/log/automx/automx.log&lt;br /&gt;
&lt;br /&gt;
# Protect against DoS&lt;br /&gt;
memcache = 127.0.0.1:11211&lt;br /&gt;
memcache_ttl = 600&lt;br /&gt;
client_error_limit = 20&lt;br /&gt;
rate_limit_exception_networks = 127.0.0.0/8, ::1/128&lt;br /&gt;
&lt;br /&gt;
# The DEFAULT section is always merged into each other section. Each section&lt;br /&gt;
# can overwrite settings done here.&lt;br /&gt;
[DEFAULT]&lt;br /&gt;
account_type = email&lt;br /&gt;
account_name = example Mail&lt;br /&gt;
account_name_short = example Mail&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
# If a domain is listed in the automx section, it may have its own section. If&lt;br /&gt;
# none is found here, the global section is used.&lt;br /&gt;
[global]&lt;br /&gt;
backend = static&lt;br /&gt;
action = settings&lt;br /&gt;
&lt;br /&gt;
# EAS (mobilesync)&lt;br /&gt;
server_url = https://eas.example.org&lt;br /&gt;
server_name = example&lt;br /&gt;
&lt;br /&gt;
# If you want to sign mobileconfig profiles, enable these options. Make sure&lt;br /&gt;
# that your webserver has proper privileges to read the key. The cert file&lt;br /&gt;
# must contain the server certificate and all intermediate certificates. You&lt;br /&gt;
# can simply concatenate these certificates.&lt;br /&gt;
#sign_mobileconfig = yes&lt;br /&gt;
#sign_cert = /path/to/cert&lt;br /&gt;
#sign_key = /path/to/key&lt;br /&gt;
&lt;br /&gt;
smtp = yes&lt;br /&gt;
smtp_server = mail.example.org&lt;br /&gt;
smtp_port = 587&lt;br /&gt;
smtp_encryption = starttls&lt;br /&gt;
smtp_auth = plaintext&lt;br /&gt;
smtp_auth_identity = %s&lt;br /&gt;
smtp_refresh_ttl = 6&lt;br /&gt;
smtp_default = yes&lt;br /&gt;
&lt;br /&gt;
imap = yes&lt;br /&gt;
imap_server = mail.example.org&lt;br /&gt;
imap_port = 993&lt;br /&gt;
imap_encryption = ssl&lt;br /&gt;
imap_auth = plaintext&lt;br /&gt;
imap_auth_identity = %s&lt;br /&gt;
imap_refresh_ttl = 6&lt;br /&gt;
pop = yes&lt;br /&gt;
pop_server = mail.example.org&lt;br /&gt;
pop_port = 995&lt;br /&gt;
pop_encryption = ssl&lt;br /&gt;
pop_auth = plaintext&lt;br /&gt;
pop_auth_identity = %s&lt;br /&gt;
pop_refresh_ttl = 6&lt;br /&gt;
&lt;br /&gt;
carddav = yes&lt;br /&gt;
carddav_server = https://dav.example.org/&lt;br /&gt;
carddav_auth_identity = %s&lt;br /&gt;
&lt;br /&gt;
caldav = yes&lt;br /&gt;
caldav_server = https://dav.example.org/&lt;br /&gt;
caldav_auth_identity = %s&lt;br /&gt;
&lt;br /&gt;
ox = yes&lt;br /&gt;
ox_server = https://ox.example.org/&lt;br /&gt;
ox_auth_identity = %s&lt;br /&gt;
&lt;br /&gt;
follow = imap_starttls&lt;br /&gt;
&lt;br /&gt;
[imap_starttls]&lt;br /&gt;
backend = static_append&lt;br /&gt;
&lt;br /&gt;
imap = yes&lt;br /&gt;
imap_server = mail.example.org&lt;br /&gt;
imap_port = 143&lt;br /&gt;
imap_encryption = starttls&lt;br /&gt;
imap_auth = plaintext&lt;br /&gt;
imap_auth_identity = %s&lt;br /&gt;
imap_refresh_ttl = 6&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Apache ====&lt;br /&gt;
&lt;br /&gt;
e.g. /etc/{apache2,httpd}/conf.d/automx.conf:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
&amp;lt;IfModule mod_wsgi.c&amp;gt;&lt;br /&gt;
    WSGIChunkedRequest On&lt;br /&gt;
&lt;br /&gt;
    WSGIScriptAliasMatch \&lt;br /&gt;
      (?i)^/.+/(autodiscover|config-v1.1).xml \&lt;br /&gt;
      /usr/lib/automx/automx_wsgi.py&lt;br /&gt;
&lt;br /&gt;
    WSGIScriptAlias \&lt;br /&gt;
      /mobileconfig \&lt;br /&gt;
      /usr/lib/automx/automx_wsgi.py&lt;br /&gt;
&lt;br /&gt;
    &amp;lt;Directory &amp;quot;/usr/lib/automx&amp;quot;&amp;gt;&lt;br /&gt;
            Require all granted&lt;br /&gt;
    &amp;lt;/Directory&amp;gt;&lt;br /&gt;
&amp;lt;/IfModule&amp;gt;&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In case the iOS/MacOS web provisioning should be provided there should also be a /etc/{apache2,httpd}/conf.d/automx-web.conf:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
Alias /automx &amp;quot;/usr/share/automx/&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;Directory &amp;quot;/usr/share/automx&amp;quot;&amp;gt;&lt;br /&gt;
    Options Indexes MultiViews&lt;br /&gt;
    Require all granted&lt;br /&gt;
&amp;lt;/Directory&amp;gt;&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
eMClient for OX App Suite has a special requirement to make the autoconfiguration experience nice and straightforward. To make it ask directly for a password instead of later in the setup process (where it requires a restart of the application to be fully functional) it is required to protect the autodiscover.xml via basic auth. In our scenario there is nothing to protect really so in this example we allow any credentials for access but still ask for some.&lt;br /&gt;
&lt;br /&gt;
For this add the following section to /etc/{apache2,httpd}/conf.d/automx.conf:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
    &amp;lt;Location &amp;quot;/autodiscover/autodiscover.xml&amp;quot;&amp;gt;&lt;br /&gt;
            AuthType Basic&lt;br /&gt;
            AuthName &amp;quot;Restricted&amp;quot;&lt;br /&gt;
            AuthBasicProvider anon&lt;br /&gt;
            Anonymous_NoUserID off&lt;br /&gt;
            Anonymous_MustGiveEmail off&lt;br /&gt;
            Anonymous_VerifyEmail off&lt;br /&gt;
            Anonymous_LogEmail off&lt;br /&gt;
            Anonymous *&lt;br /&gt;
            Require valid-user&lt;br /&gt;
    &amp;lt;/Location&amp;gt;&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Related links ==&lt;br /&gt;
&lt;br /&gt;
[[Caldav_carddav_Bundles#Autodiscovery|DAV autodiscovery]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: Clients]]&lt;br /&gt;
[[Category: Administrator]]&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:OX_Guard&amp;diff=25681</id>
		<title>AppSuite:OX Guard</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:OX_Guard&amp;diff=25681"/>
		<updated>2021-01-12T21:46:05Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: /* Apache */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= OX Guard (Version 2.10) =&lt;br /&gt;
&lt;br /&gt;
For previous versions of OX Guard, please click here&lt;br /&gt;
* [[AppSuite:OX_Guard_2-0 | Installation and information of OX Guard 2.0 - 2.2]]&lt;br /&gt;
* [[Appsuite:OX_Guard_2_8 | Installation and information of OX Guard 2.4 - 2.8]]&lt;br /&gt;
&lt;br /&gt;
If upgrading from 2.6 or 2.8, please see&lt;br /&gt;
* [[Appsuite:OX_Guard_Upgrade_2_10|Upgrading to 2.10]]&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
&lt;br /&gt;
OX Guard is a fully integrated security add-on to OX App Suite that provides end users with a flexible email and file encryption solution. OX Guard is a highly scalable, multi server, feature rich solution that is so simple-to-use that end users will actually use it. With a single click a user can take control of their security and send secure emails and share encrypted files. This can be done from any device to both OX App Suite and non-OX App Suite users.&lt;br /&gt;
&lt;br /&gt;
OX Guard uses standard PGP encryption for the encryption of email and files. PGP has been around for a long time, yet has not really caught on with the masses. This is generally blamed on the confusion and complications of managing the keys, understanding trust, PGP format types, and lack of trusted central key repositories. Guard simplifies all of this, making PGP encryption as easy as a one click process, with no keys to keep track of, yet the options of advanced PGP management for those that know how.&lt;br /&gt;
&lt;br /&gt;
This article will guide you through the installation of Guard and describes the basic configuration and software requirements. As it is intended as a quick walk-through it assumes an existing installation of the operating system including a single server App Suite setup as well as average system administration skills. This guide will also show you how to setup a basic installation with none of the typically used distributed environment settings. The objective of this guide is:&lt;br /&gt;
&lt;br /&gt;
* To setup a single server installation&lt;br /&gt;
* To setup a single Guard instance on an existing Open-Xchange installation, no cluster&lt;br /&gt;
* To use the database service on the existing Open-Xchange installation for Guard, no replication&lt;br /&gt;
* To provide a basic configuration setup, no mail server configuration&lt;br /&gt;
&lt;br /&gt;
=== Key Features ===&lt;br /&gt;
&lt;br /&gt;
* Simple security at the touch of a button&lt;br /&gt;
* Provides user based security - Separate from provider&lt;br /&gt;
* Supplementary security to Provider based security - Layered&lt;br /&gt;
* Powerful features yet simple to use and understand&lt;br /&gt;
* Security - Inside and outside of the OX environment&lt;br /&gt;
* Email and Drive integration&lt;br /&gt;
* Uses proven PGP security&lt;br /&gt;
&lt;br /&gt;
=== Availability ===&lt;br /&gt;
&lt;br /&gt;
If an OX App Suite customer would like to evaluate OX Guard integration, the first step is to contact OX Sales. OX Sales will then work on the request and send prices and license/API (for the hosted infrastructure) key details to the customer.&lt;br /&gt;
&lt;br /&gt;
=== Requirements ===&lt;br /&gt;
&lt;br /&gt;
Please review [https://oxpedia.org/wiki/index.php?title=AppSuite:OX_System_Requirements#OX_Guard OX Guard Requirements] for a full list of requirements.&lt;br /&gt;
&lt;br /&gt;
Since OX Guard is a Microservice it can either be added to an existing Open-Xchange installation or it can be deployed on a dedicated environment. The version of Guard installed is dependent on the Appsuite version installed.  Please refer to the version matrix below.&lt;br /&gt;
&lt;br /&gt;
==== Prerequisites ====&lt;br /&gt;
&lt;br /&gt;
* Open-Xchange REST API&lt;br /&gt;
* Grizzly HTTP connector (open-xchange-grizzly)&lt;br /&gt;
* A supported Java Virtual Machine (Java 8)&lt;br /&gt;
* An Open-Xchange App Suite installation (see version Matrix)&lt;br /&gt;
* Please Note: To get access to the latest minor features and bug fixes, you need to have a valid license. The article [https://oxpedia.org/wiki/index.php?title=AppSuite:UpdatingOXPackages Updating OX-Packages] explains how that can be done.&lt;br /&gt;
&lt;br /&gt;
==== Version Matrix ====&lt;br /&gt;
{|&lt;br /&gt;
! style=&amp;quot;text-align:left;&amp;quot;| Core Version&lt;br /&gt;
! Guard Version&lt;br /&gt;
|-&lt;br /&gt;
|7.8.1&lt;br /&gt;
|2.4.0 or 2.4.2&lt;br /&gt;
|-&lt;br /&gt;
|7.8.2&lt;br /&gt;
|2.4.2&lt;br /&gt;
|-&lt;br /&gt;
|7.8.3&lt;br /&gt;
|2.6.0&lt;br /&gt;
|-&lt;br /&gt;
|7.8.4&lt;br /&gt;
|2.8.0&lt;br /&gt;
|-&lt;br /&gt;
|7.10.0&lt;br /&gt;
|2.10.0&lt;br /&gt;
|-&lt;br /&gt;
|7.10.1&lt;br /&gt;
|2.10.1&lt;br /&gt;
|-&lt;br /&gt;
|7.10.2&lt;br /&gt;
|2.10.2&lt;br /&gt;
|-&lt;br /&gt;
|7.10.3&lt;br /&gt;
|2.10.3&lt;br /&gt;
|-&lt;br /&gt;
|7.10.4&lt;br /&gt;
|2.10.4&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Important Notes ===&lt;br /&gt;
&lt;br /&gt;
==== Customisation ====&lt;br /&gt;
&lt;br /&gt;
OX Guard version supports branding / theming using the configuration cascade, defining a templateID for a user or context. Check the [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCustomization OX Guard Customisation] article for more details.&lt;br /&gt;
&lt;br /&gt;
==== Mail Resolver ====&lt;br /&gt;
&lt;br /&gt;
READ THIS VERY CAREFULLY; BEFORE PROCEEDING WITH GUARD INSTALLATION!&lt;br /&gt;
&lt;br /&gt;
The Guard installation must be able to determine if an email recipient is a local OX user or if it should be a guest account. The default MailResolver uses the context domain name to do this. On many installations, domains may extend across multiple context and multiple database shards. In these cases, the default MailResolver won&#039;t work. In addition, if a custom authentication package is used, the Mail Resolver will likely not work.&lt;br /&gt;
&lt;br /&gt;
Once Guard is installed, please be sure to test the mail resolver using:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;/opt/open-xchange/sbin/guard test email@domain&amp;lt;/source&amp;gt;&lt;br /&gt;
to see if the mail Resolver works.&lt;br /&gt;
&lt;br /&gt;
If the test does not work, you will likely need a custom Mail Resolver. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardMailResolver Mail Resolver] page&lt;br /&gt;
&lt;br /&gt;
This resolver software &#039;&#039;depends heavily on your local deployment&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Download and Installation ==&lt;br /&gt;
&lt;br /&gt;
=== General ===&lt;br /&gt;
&lt;br /&gt;
The installation of the &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; package which is required for Guard and the main &amp;lt;code&amp;gt;open-xchange-guard&amp;lt;/code&amp;gt; package in version 2.4.0 or higher will eventually execute database update tasks if installed and activated. Please take this into account.&lt;br /&gt;
&lt;br /&gt;
There are several components to the Guard service. They can be all installed on the same server as the OX middleware or on a separate server.&lt;br /&gt;
&lt;br /&gt;
The components required for the OX middleware are: &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
The components required for the OX frontend are: &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; and optionally &amp;lt;code&amp;gt;open-xchange-guard-help-en-us&amp;lt;/code&amp;gt; (or preferred language for help files).&lt;br /&gt;
&lt;br /&gt;
The components required for the Guard server &amp;lt;code&amp;gt;open-xchange-guard&amp;lt;/code&amp;gt; and either &amp;lt;code&amp;gt;open-xchange-guard-file-storage&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;open-xchange-guard-s3-storage&amp;lt;/code&amp;gt; depending on what storage you want to use. The examples below make use of the &amp;lt;code&amp;gt;open-xchange-guard-file-storage&amp;lt;/code&amp;gt;. Adjust the commands accordingly to fit your needs. In addition &amp;lt;code&amp;gt;open-xchange&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-core&amp;lt;/code&amp;gt; are required to run OX Guard.&lt;br /&gt;
&lt;br /&gt;
=== Debian Linux 9.0 (Stretch) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 deb https://software.open-xchange.com/products/guard/stable/guard/DebianStretch /&lt;br /&gt;
 deb https://software.open-xchange.com/products/appsuite/stable/backend/DebianStretch /&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== Debian Linux 10.0 (Buster) *Version 2.10.3+ only* ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 deb https://software.open-xchange.com/products/guard/stable/guard/DebianBuster /&lt;br /&gt;
 deb https://software.open-xchange.com/products/appsuite/stable/backend/DebianBuster /&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== RedHat Enterprise Linux 6 or CentOS 6 (valid until v2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/guard/2.10.3/guard/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/7.10.3/backend/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== Redhat Enterprise Linux 7 or CentOS 7 ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/guard/stable/guard/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/stable/backend/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== SUSE Linux Enterprise Server 12 (valid until 2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
Add the package repository using zypper if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ar https://software.open-xchange.com/products/guard/2.10.3/guard/SLE_12 guard-stable-guard&lt;br /&gt;
 $ zypper ar https://software.open-xchange.com/products/appsuite/7.10.3/backend/SLE_12 ox-backend&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&lt;br /&gt;
 $ zypper in open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static&lt;br /&gt;
&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&lt;br /&gt;
 $ zypper in open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== Univention Corporate Server ===&lt;br /&gt;
&lt;br /&gt;
If you have purchased the OX App Suite for UCS, the OX Guard is part of the offering. OX Guard is available in the Univention App Center. Please check the UMC module App Center for the installation of the OX Guard at your already available environment.&lt;br /&gt;
&lt;br /&gt;
Please note: By default, OX Guard generates the link to the secure content for external recipients on the basis of the local fully qualified domain name (FQDN). If the local FQDN is not reachable from the Internet, it has to be specified manually. This can be done by setting a UCR variable, e.g. via the UMC module &amp;amp;quot;Univention Configuration Registry&amp;amp;quot;. The variable has to contain the external FQDN of the OX Guard system:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;oxguard/cfg/guard.properties/com.openexchange.guard.externalEmailURL=HOSTNAME.DOMAINNAME&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Update OX Guard ==&lt;br /&gt;
&lt;br /&gt;
This section contains information about updating a 2.10.0 version (e.g. for patch fixes). Upgrading from prior versions is discussed in different articles.&lt;br /&gt;
&lt;br /&gt;
=== Debian Linux 9.0 (Stretch) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 deb &amp;lt;https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/stable/guard/updates/DebianStretch /&amp;gt;&lt;br /&gt;
 deb &amp;lt;https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/stable/backend/DebianStretch /&amp;lt;/source&amp;gt;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Then run:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get dist-upgrade&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If you want to see, what apt-get is going to do without actually doing it, you can run:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get dist-upgrade -s&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Redhat Enterprise Linux 6 or CentOS 6 (valid until 2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard-updates]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard-updates&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/2.10.3/guard/updates/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/7.10.3/backend/updates/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
and then run:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum upgrade&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Redhat Enterprise Linux 7 or CentOS 7 ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard-updates]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard-updates&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/stable/guard/updates/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/stable/backend/updates/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
and then run:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum upgrade&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== SUSE Linux Enterprise Server 12 (valid until 2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
Add the package repository using &amp;lt;code&amp;gt;zypper&amp;lt;/code&amp;gt; if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ar https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/2.10.3/guard/updates/SLE_12 guard-stable-guard-updates&lt;br /&gt;
 $ zypper ar https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/7.10.3/backend/updates/SLE_12 ox-backend&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
and then run:&lt;br /&gt;
&lt;br /&gt;
 $ zypper dup -r guard-stable-guard-backend-updates&lt;br /&gt;
 $ zypper dup -r guard-stable-guard-ui-updates&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You might need to run:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
to update the repository metadata before running &amp;lt;code&amp;gt;zypper&amp;lt;/code&amp;gt; up.&lt;br /&gt;
&lt;br /&gt;
=== Univention Corporate Server ===&lt;br /&gt;
&lt;br /&gt;
If you have purchased the OX App Suite for UCS, the OX Guard is part of the offering. OX Guard is available in the Univention App Center. Please check the UMC module App Center for the update of the OX Guard.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Configuration ==&lt;br /&gt;
&lt;br /&gt;
The following gives an overview of the most important settings to enable Guard for users on the Open-Xchange installation. Some of those settings have to be modified in order to establish the database and REST API access from the Guard service. All settings relating to the Guard backend component are located in the configuration file &amp;lt;code&amp;gt;guard-core.properties&amp;lt;/code&amp;gt; located in &amp;lt;code&amp;gt;/opt/open-xchange/etc&amp;lt;/code&amp;gt;. The default configuration should be sufficient for a basic &amp;amp;quot;up-and-running&amp;amp;quot; setup (with the exception of defining the database username and password). Please refer to the inline documentation of the configuration file for more advanced options. Additional information can be found in the [https://oxpedia.org/wiki/index.php?title=AppSuite:OX_Guard_Configuration_2_10 Guard Configuration] article.&lt;br /&gt;
&lt;br /&gt;
=== Basic Configuration ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/guard-core.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
Guard database for storing Guard user information, main lookup tables:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.oxguardDatabaseHostname=localhost&amp;lt;/source&amp;gt;&lt;br /&gt;
Guard database that stores keys for guest users. May be the same as above. New guest shards will be created on this database as needed. If not supplied, will use the &amp;lt;code&amp;gt;oxguardDatabaseHostname&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.oxguardShardDatabase=localhost&amp;lt;/source&amp;gt;&lt;br /&gt;
Username and Password for the databases above:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.databaseUsername=openexchange&lt;br /&gt;
com.openexchange.guard.databasePassword=db_password&amp;lt;/source&amp;gt;&lt;br /&gt;
Open-Xchange REST API host:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.restApiHostname=localhost&amp;lt;/source&amp;gt;&lt;br /&gt;
Open-Xchange REST API username and password (need to be defined in the OX backend in the &amp;amp;quot;Configure services&amp;amp;quot; below):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.restApiUsername=apiusername&lt;br /&gt;
com.openexchange.guard.restApiPassword=apipassword&amp;lt;/source&amp;gt;&lt;br /&gt;
External URL for this Open-Xchange installation. This setting will be used to generate the link to the secure content for external recipients:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.externalEmailURL=URL_TO_OX&amp;lt;/source&amp;gt;&lt;br /&gt;
=== Middleware Configuration on OX Guard node ===&lt;br /&gt;
&lt;br /&gt;
If you are installing OX Guard on a node that until yet did not host an Open-Xchange middleware you have to additionally configure some parts of the following properties files:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;configdb.properties&amp;lt;/code&amp;gt;: information about the existing configuration database.&lt;br /&gt;
* &amp;lt;code&amp;gt;server.properties&amp;lt;/code&amp;gt;: information about the connections have to be set.&lt;br /&gt;
* &amp;lt;code&amp;gt;system.properties&amp;lt;/code&amp;gt;: at least &amp;lt;code&amp;gt;SERVER_NAME&amp;lt;/code&amp;gt; should be set.&lt;br /&gt;
&lt;br /&gt;
=== Sevices Configuration ===&lt;br /&gt;
&lt;br /&gt;
==== Apache ====&lt;br /&gt;
&lt;br /&gt;
Configure the &amp;lt;code&amp;gt;mod_proxy_http&amp;lt;/code&amp;gt; module by adding the Guard API.&lt;br /&gt;
&lt;br /&gt;
Debian GNU/Linux 9.0 and 10.0&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /etc/apache2/sites-enabled/000-default.conf&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Redhat Enterprise Linux 6/7 or CentOS 6/7&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /etc/httpd/conf.d/ox.conf&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Add the following section into VirtualHost definition:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;Directory /var/www/html/guard&amp;gt;&lt;br /&gt;
     Options -Indexes&lt;br /&gt;
 &amp;lt;/Directory&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Debian GNU/Linux 9.0 and 10.0&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /etc/apache2/conf-enabled/proxy_http.conf&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Redhat Enterprise Linux 6/7 or CentOS 6/7&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /etc/httpd/conf.d/proxy_http.conf&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;Proxy balancer://oxguard&amp;gt;&lt;br /&gt;
        Order deny,allow&lt;br /&gt;
        Allow from all&lt;br /&gt;
 &lt;br /&gt;
        BalancerMember http://localhost:8009/ timeout=1800 smax=0 ttl=60 retry=60 loadfactor=100 route=OX1&lt;br /&gt;
        ProxySet stickysession=JSESSIONID|jsessionid scolonpathdelim=ON&lt;br /&gt;
       SetEnv proxy-initial-not-pooled&lt;br /&gt;
        SetEnv proxy-sendchunked&lt;br /&gt;
 &amp;lt;/Proxy&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
 ProxyPass /appsuite/api/oxguard balancer://oxguard/oxguard&lt;br /&gt;
 ProxyPass /pks balancer://oxguard/pgp&lt;br /&gt;
 ProxyPass /.well-known/openpgpkey/hu balancer://oxguard/hu&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: The Guard API settings must be inserted &#039;&#039;&#039;&#039;&#039;before&#039;&#039;&#039;&#039;&#039; the existing &amp;lt;code&amp;gt;ProxyPass /appsuite/api&amp;lt;/code&amp;gt; parameter.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Also Note&#039;&#039;&#039;:  If you already have a Proxy balancer for the OX backend with the same URL (say http://localhost:8080) then you don&#039;t need the second BalancerMember entry, and you can just have the ProxyPass address that balancer instead.&lt;br /&gt;
&lt;br /&gt;
After the configuration is done, restart the Apache webserver&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ apachectl restart&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Open-Xchange Middleware Configuration ===&lt;br /&gt;
&lt;br /&gt;
Edit the &amp;lt;code&amp;gt;guard-api.properties&amp;lt;/code&amp;gt; configuration file for the OX backend where the guard-backend-plugin was installed. Please remove comments in front of the following settings to the configuration file &amp;lt;code&amp;gt;guard-api.properties&amp;lt;/code&amp;gt; on the Open-Xchange backend servers:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/guard-api.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;# OX Guard general permission, required to activate Guard in the AppSuite UI.&lt;br /&gt;
com.openexchange.capability.guard=true&lt;br /&gt;
&lt;br /&gt;
# Default theme template id for all users that have no custom template id configured.&lt;br /&gt;
com.openexchange.guard.templateID=0&amp;lt;/source&amp;gt;&lt;br /&gt;
Configure the API username and password that you assigned to Guard in the &amp;lt;code&amp;gt;server.properties&amp;lt;/code&amp;gt; file:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/server.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;# Specify the user name used for HTTP basic auth by internal REST servlet&lt;br /&gt;
com.openexchange.rest.services.basic-auth.login=apiusername&lt;br /&gt;
&lt;br /&gt;
# Specify the password used for HTTP basic auth by internal REST servlet&lt;br /&gt;
com.openexchange.rest.services.basic-auth.password=apipassword&amp;lt;/source&amp;gt;&lt;br /&gt;
Finally, the OX backend needs to know where the Guard server is located. This is used to notify the Guard server of changes in users, and to send emails marked for signature. The URL for the Guard server should include the URL suffix &amp;lt;code&amp;gt;/guardadmin&amp;lt;/code&amp;gt;. In the event of a cluster setup, any Guard server can be referenced here, as it is not session specific, though ideally would have a HTTP load balancer/failover URL:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/guard-api.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;# Specifies the URI to the OX Guard end-point; e.g. http://guard.host.invalid:8081/guardadmin&lt;br /&gt;
# Default is empty&lt;br /&gt;
com.openexchange.guard.endpoint=http://guardserver:8009/guardadmin&amp;lt;/source&amp;gt;&lt;br /&gt;
Restart the OX backend&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /etc/init.d/open-xchange restart&amp;lt;/source&amp;gt;&lt;br /&gt;
==== SELinux ====&lt;br /&gt;
&lt;br /&gt;
Running SELinux prohibits your local Open-Xchange backend service to connect to localhost:8009, which is where the Guard backend service listens to. In order to allow localhost connections to 8009 execute the following:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ setsebool -P httpd_can_network_connect 1&amp;lt;/source&amp;gt;&lt;br /&gt;
=== Generating the &amp;lt;code&amp;gt;oxguardpass&amp;lt;/code&amp;gt; ===&lt;br /&gt;
&lt;br /&gt;
Once the Guard configuration (database and backend configuration) and the service configuration has been applied, the Guard administration script needs to be executed in order to create the master password file in &amp;lt;code&amp;gt;/opt/open-xchange/etc/oxguardpass&amp;lt;/code&amp;gt;. The initiation only needs to be done &#039;&#039;&#039;once&#039;&#039;&#039; for a multi server setup, for details please see the sections &#039;&#039;&#039;Optional&#039;&#039;&#039; and/or &#039;&#039;&#039;Clustering&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: If you run a cluster of OX / Guard nodes, only execute this command on &#039;&#039;&#039;ONE&#039;&#039;&#039; node. Not on all nodes! See [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCluster OX Guard Clustering] for details.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /opt/open-xchange/sbin/guard --init&amp;lt;/source&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: It is important to understand that the master password file located at &amp;lt;code&amp;gt;/opt/open-xchange/etc/oxguardpass&amp;lt;/code&amp;gt; is required to reset user passwords; without them the administrator will not be able to reset user passwords anymore in the future. The file contains the passwords used to encrypt the master database key, as well as passwords used to encrypt protected data in the users table. It must be the same on all Guard servers.&lt;br /&gt;
&lt;br /&gt;
=== Test Setup ===&lt;br /&gt;
&lt;br /&gt;
Not required, but it is a good idea to test the Guard setup before enabling for any users. The test function will verify that Guard has a good connection to the OX backend, and that it can resolve email addresses to users.&lt;br /&gt;
&lt;br /&gt;
To test, use an email address that exists on the OX backend (john@example.com for this example)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;/opt/open-xchange/sbin/guard --test john@example.com&amp;lt;/source&amp;gt;&lt;br /&gt;
Guard should return information from the OX backend regarding the user associated with &amp;amp;quot;john@example.com&amp;amp;quot;. Problems resolving information for the user should be resolved before using Guard. Check Rest API passwords and settings if errors returned.&lt;br /&gt;
&lt;br /&gt;
=== Enabling Guard for Users ===&lt;br /&gt;
&lt;br /&gt;
Guard provides three capabilities for users in the environment as well as a basic &amp;amp;quot;core&amp;amp;quot; level:&lt;br /&gt;
&lt;br /&gt;
* Guard: &amp;lt;code&amp;gt;com.openexchange.capability.guard&amp;lt;/code&amp;gt;&lt;br /&gt;
* Guard Mail: &amp;lt;code&amp;gt;com.openexchange.capability.guard-mail&amp;lt;/code&amp;gt;&lt;br /&gt;
* Guard Drive: &amp;lt;code&amp;gt;com.openexchange.capability.guard-drive&amp;lt;/code&amp;gt;&lt;br /&gt;
* Guard Docs: &amp;lt;code&amp;gt;com.openexchange.capability.guard-docs&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The &amp;amp;quot;core&amp;amp;quot; Guard enabled a basic read functionality for Guard encrypted emails. We recommend enabling this for all users, as this allows all recipients to read Guard emails sent to them. Great opportunity for upsell. Recipients with only Guard enabled can then do a secure reply to the sender, but they can&#039;t start a new email or add recipients.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Guard Mail&#039;&#039;&#039;, &#039;&#039;&#039;Guard Drive&#039;&#039;&#039; and &#039;&#039;&#039;Guard Docs&#039;&#039;&#039; are additional options for users. &amp;amp;quot;Guard Mail&amp;amp;quot; allows users the full functionality of Guard emails. &amp;amp;quot;Guard Drive&amp;amp;quot; allows for encryption and decryption of Drive files and &amp;amp;quot;Guard Docs&amp;amp;quot; allows direct integration of Guard into Documents.&lt;br /&gt;
&lt;br /&gt;
Each of those three Guard components is enabled for all users that have the according capability configured. Please note that users need to have the Drive permission set to use Guard Drive. So the users that have Guard Drive enabled must be a subset of those users with OX Drive permission. Since v7.6.0 we enforce this via the default configuration. Those capabilities can be activated for specific user by using the Open-Xchange provisioning scripts:&lt;br /&gt;
&lt;br /&gt;
==== Guard Mail: ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /opt/open-xchange/sbin/changeuser -c 1 -A oxadmin -P admin_password -u testuser --config/com.openexchange.capability.guard-mail=true&amp;lt;/source&amp;gt;&lt;br /&gt;
==== Guard Drive: ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /opt/open-xchange/sbin/changeuser -c 1 -A oxadmin -P admin_password -u testuser --config/com.openexchange.capability.guard-drive=true&amp;lt;/source&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: Guard Drive requires Guard Mail to be configured for the user as well. In addition, these capabilities may be configured globally by editing the &amp;lt;code&amp;gt;guard-api.properties&amp;lt;/code&amp;gt; file on the OX backend.&lt;br /&gt;
&lt;br /&gt;
=== External Guest recipients ===&lt;br /&gt;
Starting in Guard 2.10.0, when an encrypted email is sent to a user that does not have Guard, a guest account is created for them in appsuite.  The recipient uses the Guest account to read the encrypted email.  These guest users MUST have guard capabilities.  To do this, guard capability must be added to guest accounts.&lt;br /&gt;
&amp;lt;code&amp;gt;/opt/open-xchange/etc/share.properties&amp;lt;/code&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.share.guestCapabilityMode=static&lt;br /&gt;
com.openexchange.share.staticGuestCapabilities=guard&amp;lt;/source&amp;gt;&lt;br /&gt;
In a distributed system, the Guest accounts should not be considered transient.  Guard servers must be able to verify the guest account exists in the session storage services.&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.share.transientSessions=false&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Guest Storage ===&lt;br /&gt;
When an encrypted email is sent to an external Guest, a copy of the fully encrypted email is stored on the server.  This is used to create an inbox of encrypted emails for the guest.  By entering in a password, the emails can be decrypted and displayed.&lt;br /&gt;
&lt;br /&gt;
How these files are stored depend on which package, open-xchange-guard-file-storage or open-xchange-guard-s3-storage, was installed.&lt;br /&gt;
&lt;br /&gt;
The file retention policy is configured in the guard-core.properties file.&lt;br /&gt;
&lt;br /&gt;
=== Recipient key detection ===&lt;br /&gt;
&lt;br /&gt;
==== Local ====&lt;br /&gt;
&lt;br /&gt;
Guard needs to determine if an email recipients email address is an internal or external (non-ox) user.&lt;br /&gt;
&lt;br /&gt;
To detect if the recipient is an account on the same OX Guard system there is a mechanism needed to map a recipient mail address to the correct local OX context. The default implementation delivered in the product achieves that by looking up the mail domain (@example.com) within the list of context mappings. That is at least not possible in case of ISPs where different users/contexts use the same mail domain. In case your OX system does not use mail domains in context mappings it is required to deploy an OX OSGi bundle implementing the &amp;lt;code&amp;gt;com.openexchange.mailmapping.MailResolver&amp;lt;/code&amp;gt; class or by interfacing Guard with your mail resolver system. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardMailResolver OX Guard Mail Resolver] for details.&lt;br /&gt;
&lt;br /&gt;
==== External ====&lt;br /&gt;
&lt;br /&gt;
Starting with Guard 2.0, Guard will use public PGP Key servers if configured to find PGP Public keys. In addition, Guard will also look up SRV records for PGP Key servers for a recipients domain. This follows the standards [http://tools.ietf.org/html/draft-shaw-openpgp-hkp-00#page-9 OpenPGP Draft].&lt;br /&gt;
&lt;br /&gt;
External PGP servers to use can be configured in the guard.properties file on the Guard servers.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.publicPGPDirectory = hkp://keys.gnupg.net:11371, hkp://pgp.mit.edu:11371&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If you would like this Guard installation discoverable as HKP service by other Guard servers, then create an SRV record for each domain (&amp;amp;quot;example.com&amp;amp;quot; in this illustration):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;_hkp._tcp.example.com. 28800 IN    SRV     10 1 80 appsuite.example.com.&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039; PGP Public key servers by default append the path /pks when the record is obtained from an SRV record. The proxy (also included in Apache config above) routes anything under /pks to the OX Guard PGP server.&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;ProxyPass /pks balancer://oxguard/pgp&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Guard keys are also discoverable using the webkey service as specified here: https://tools.ietf.org/html/draft-koch-openpgp-webkey-service-02&lt;br /&gt;
This is enabled if you include the &lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;ProxyPass /.well-known/openpgpkey/hu balancer://oxguard/hu&amp;lt;/source&amp;gt;&lt;br /&gt;
in the proxy_http.conf as above.&lt;br /&gt;
Please note that the well-known request is targeted at the domain part of the mail address. Therefore clients will request for a mail address name@example.com the URI https://example.com/.well-known/openpgpkey/hu/...&lt;br /&gt;
&lt;br /&gt;
That means that there is the very likely need that some sort of proxying or rewriting from the webserver providing the domain needs to happen. For example for proxying using Apache 2.4 it would roughly look like this:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
SSLProxyEngine on&lt;br /&gt;
&amp;lt;LocationMatch /.well-known/openpgpkey/&amp;gt;&lt;br /&gt;
    ProxyPass https://ox.example.com/.well-known/openpgpkey/&lt;br /&gt;
&amp;lt;/LocationMatch&amp;gt;&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clustering ===&lt;br /&gt;
&lt;br /&gt;
You can run multiple OX Guard servers in your environment to ensure high availability or enhance scalability. OX Guard integrates seamlessly into the existing Open-Xchange infrastructure by using the existing interface standards and is therefor transparent to the environment. A couple of things have to be prepared in order to loosely couple OX Guard servers with Open-Xchange servers in a cluster.&lt;br /&gt;
&lt;br /&gt;
==== MySQL ====&lt;br /&gt;
&lt;br /&gt;
The MySQL servers need to be configured in order to allow access to the configdb of Open-Xchange. To do so you need to set the following configuration in the MySQL &amp;lt;code&amp;gt;my.cnf&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;bind = 0.0.0.0&amp;lt;/source&amp;gt;&lt;br /&gt;
This allows the Guard backend to bind to the MySQL host which is configured in the &amp;lt;code&amp;gt;guard-core.properties&amp;lt;/code&amp;gt; file with &amp;lt;code&amp;gt;com.openexchange.guard.configdbHostname&amp;lt;/code&amp;gt;. After the bind for the MySQL instance is configured and the OX Guard backend would be able to connect to the configured host, you have to grant access for the OX Guard service on the MySQL instance to manage the databases. Do so by connecting to the MySQL server via the MySQL client. Authenticate if necessary and execute the following, please note that you have to modify the hostname / IP address of the client who should be able to connect to this database, it should include all possible OX Guard servers:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;sql&amp;quot;&amp;gt;GRANT ALL PRIVILEGES ON *.* TO &#039;openexchange&#039;@&#039;oxguard.example.com&#039; IDENTIFIED BY ‘secret’;&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Apache ====&lt;br /&gt;
&lt;br /&gt;
OX Guard uses the Open-Xchange REST API to store and fetch data from the Open-Xchange databases. The REST API is a servlet running in the Grizzly container. By default it is not exposed as a servlet through Apache and is only accessibly via port 8009. In order to use Apache&#039;s load balancing via &amp;lt;code&amp;gt;mod_proxy&amp;lt;/code&amp;gt; we need to add a servlet called &amp;amp;quot;preliminary&amp;amp;quot; to &amp;lt;code&amp;gt;proxy_http.conf&amp;lt;/code&amp;gt;, example based on a clustered &amp;lt;code&amp;gt;mod_proxy&amp;lt;/code&amp;gt;configuration:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;Location /preliminary&amp;gt;&lt;br /&gt;
      Order Deny,Allow&lt;br /&gt;
      Deny from all&lt;br /&gt;
      # Only allow access from Guard servers within the network. Do not expose this&lt;br /&gt;
      # location outside of your network. In case you use a load balancing service in front&lt;br /&gt;
      # of your Apache infrastructure you should make sure that access to /preliminary will&lt;br /&gt;
      # be blocked from the Internet / outside clients. Examples:&lt;br /&gt;
      # Allow from 192.168.0.1&lt;br /&gt;
      # Allow from 192.168.1.1 192.168.1.2&lt;br /&gt;
      # Allow from 192.168.0.&lt;br /&gt;
 &amp;lt;/Location&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
 ProxyPass /preliminary balancer://oxcluster/preliminary&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Make sure that the balancer is properly configured in the &amp;lt;code&amp;gt;mod_proxy&amp;lt;/code&amp;gt; configuration. Examples on how to do so can be found in our clustering configuration for Open-Xchange AppSuite. Like explained in the example above, please make sure that this location is only available in your internal network, there is no need to expose &amp;lt;code&amp;gt;/preliminary&amp;lt;/code&amp;gt; to the public, it is only used by Guard servers to connect to the OX backend. If you have a load balancer in front of the Apache cluster you should consider blocking access to &amp;lt;code&amp;gt;/preliminary&amp;lt;/code&amp;gt; from WAN to restrict access to the servlet to internal network services only.&lt;br /&gt;
&lt;br /&gt;
Now add the OX Guard &amp;lt;code&amp;gt;BalancerMembers&amp;lt;/code&amp;gt; to the oxguard balancer configuration (also in &amp;lt;code&amp;gt;proxy_http.conf&amp;lt;/code&amp;gt;) to address all your OX Guard nodes in the cluster in this balancer configuration. The configuration has to be applied to all Apache nodes within the cluster.&lt;br /&gt;
&lt;br /&gt;
If the Apache server is a dedicated server &amp;lt;code&amp;gt;/&amp;lt;/code&amp;gt; instance you also have to install the OX Guard UI-Static package on all Apache nodes in the cluster in order to provide static files like images or CSS to the OX Guard client. Example for Debian (the OX Guard repository has to be configured in the package management prior):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ apt-get install open-xchange-guard-ui-static&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Open-Xchange ====&lt;br /&gt;
&lt;br /&gt;
Disable the Open-Xchange IPCheck for session verification. This is required because OX Guard will use the users session cookie to connect to the Open-Xchange REST API, but as a different IP address than the OX Guard server has been used during authentication the request would fail if you don&#039;t disable the IPCheck:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/server.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
and set:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.IPCheck=false&amp;lt;/source&amp;gt;&lt;br /&gt;
The OX Guard UI package has to be installed on all Open-Xchange backend nodes as well, example for Debian (the OX Guard repository has to be configured in the package management prior):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ apt-get install open-xchange-guard-ui&amp;lt;/source&amp;gt;&lt;br /&gt;
Restart the Open-Xchange service afterwards.&lt;br /&gt;
&lt;br /&gt;
==== OX Guard ====&lt;br /&gt;
&lt;br /&gt;
For details in clustering Guard servers, please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCluster OX Guard Clustering]. It is &#039;&#039;&#039;critical&#039;&#039;&#039; that all Guard servers have the same &amp;lt;code&amp;gt;oxguardpass&amp;lt;/code&amp;gt; file. Please see the clustering link for details. Do not run &amp;lt;code&amp;gt;/opt/open-xchange/sbin/guard --init&amp;lt;/code&amp;gt; on more than one server.&lt;br /&gt;
&lt;br /&gt;
After all the services like MySQL, Apache and Open-Xchange have been configured you need to update the OX Guard backend configuration to point to the correct API endpoints. Set the REST API endpoint to an Apache server by setting the following value in &amp;lt;code&amp;gt;/opt/open-xchange/etc/guard-core.properties&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.restApiHostname=apache.example.com&amp;lt;/source&amp;gt;&lt;br /&gt;
Per default Guard will try to connect to port 8009 to this host, but as we configured the REST API to be proxies thorugh the servlet &amp;lt;code&amp;gt;/preliminary&amp;lt;/code&amp;gt; on every Apache we now also need to change the target port for the REST API. You can do so by adding the following line into &amp;lt;code&amp;gt;/opt/open-xchange/etc/guard-core.properties&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.oxBackendPort=80&amp;lt;/source&amp;gt;&lt;br /&gt;
Please also change all settings in regards to MySQL like &amp;lt;code&amp;gt;com.openexchange.guard.configdbHostname&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;com.openexchange.guard.oxguardDatabaseHostname&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;com.openexchange.guard.databaseUsername&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;om.openexchange.guard.databasePassword&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Afterwards restart the OX Guard service and check the log file if the OX Guard backend is able to connect to the configured REST API.&lt;br /&gt;
&lt;br /&gt;
=== Multi Node ===&lt;br /&gt;
&lt;br /&gt;
If you have multiple OX and Guard installations, please see the following documentation [https://oxpedia.org/wiki/index.php?title=AppSuite:OX_Guard_Modular OX Guard Modular Setup].&lt;br /&gt;
&lt;br /&gt;
=== Mail Filter Integration (2.10.4+) ===&lt;br /&gt;
&lt;br /&gt;
To add additional mail filter tests (verify PGP signature, or encrypt incoming), please see&lt;br /&gt;
[[AppSuite:OX_Guard_MailFilter | MailFilter Integration]]&lt;br /&gt;
&lt;br /&gt;
== Support API ==&lt;br /&gt;
&lt;br /&gt;
The OX Guard Support API enables administrative access to various functions for maintaining OX Guard from a client in a role as a support employee. A client has to do a BASIC AUTH authentication in order to access the API. Username and password can be configured in the guard-core.properties file using the following settings:&lt;br /&gt;
&lt;br /&gt;
 # Specify the username and password for accessing the Support API of Guard&lt;br /&gt;
 com.openexchange.guard.supportApiUsername=&lt;br /&gt;
 com.openexchange.guard.supportApiPassword=&lt;br /&gt;
&lt;br /&gt;
In contrast to the rest of the OX Guard requests, the OX Guard support API requests are accessible using: /guardsupport. This distinction allows more flexible configuration since the support API should not always be accessible from everywhere. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Warning&#039;&#039;&#039;: Exposing the support API to the internet could be huge security risk. Only add to Apache if you know what you are doing.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Reset password ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=reset_password&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Performs a password reset and sends a new random generated password to a specified email address by the user or a default address if the user did not specify an email address. (&#039;&#039;Since Guard 2.0&#039;&#039;)&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;email&amp;lt;/code&amp;gt; – The email address of the user to reset the password for&lt;br /&gt;
* &amp;lt;code&amp;gt;default&amp;lt;/code&amp;gt; (optional) – The email address to send the new password to, if the user did not specify a secondary email address&lt;br /&gt;
&lt;br /&gt;
Response:&lt;br /&gt;
PRIMARY if the reset was sent to the primary email address.  SECONDARY if the reset email was sent to the secondary email address that the user specified&lt;br /&gt;
&lt;br /&gt;
=== Expose key ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=expose_key&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Marks a deleted user key temporary as “exposed” and creates a unique URL for downloading the exposed key. Automatic resetting of exposed keys to &amp;amp;quot;not exposed&amp;amp;quot; is scheduled once a day and resets all exposed keys which have been exposed before X hours, where X can be configured using com.openexchange.guard.exposedKeyDurationInHours in the guard.properties files. (&#039;&#039;Since Guard 2.0&#039;&#039;)&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;email&amp;lt;/code&amp;gt; – The email address of the user to expose the deleted keys for&lt;br /&gt;
* &amp;lt;code&amp;gt;cid&amp;lt;/code&amp;gt; – The context id&lt;br /&gt;
&lt;br /&gt;
Response: A URL pointing to the downloadable exposed keys.&lt;br /&gt;
&lt;br /&gt;
=== Delete user ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=delete_user&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deletes all keys related to a certain user. The keys are backed up and can be exposed using the “expose_key” call. (&#039;&#039;Since Guard 2.0&#039;&#039;)&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;user_id&amp;lt;/code&amp;gt; – The user&#039;s id&lt;br /&gt;
* &amp;lt;code&amp;gt;cid&amp;lt;/code&amp;gt; - The context id&lt;br /&gt;
&lt;br /&gt;
=== Upgrade User (Release 2.10 and later) ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=upgrade_guest&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Upgrades a Guest account.  This action copies all of the keys from the Guest account to a full OX account, assuming that user has Guard capabilities.&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;email&amp;lt;/code&amp;gt; - The email address of the Guest user&lt;br /&gt;
* &amp;lt;code&amp;gt;user_id&amp;lt;/code&amp;gt; – The user&#039;s new id&lt;br /&gt;
* &amp;lt;code&amp;gt;cid&amp;lt;/code&amp;gt; - The user&#039;s new context id&lt;br /&gt;
&lt;br /&gt;
== Customisation ==&lt;br /&gt;
&lt;br /&gt;
Guard&#039;s templates are customisable at the user and context level. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCustomization Customisation] for details.&lt;br /&gt;
&lt;br /&gt;
== Entropy ==&lt;br /&gt;
&lt;br /&gt;
Guard requires entropy (randomness) to generate the private/public keys that are used. Depending on the server and it&#039;s environment, this may become a problem. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardEntropy Entropy] for a possible solution.&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:Available_Translations&amp;diff=25652</id>
		<title>AppSuite:Available Translations</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:Available_Translations&amp;diff=25652"/>
		<updated>2020-11-18T14:51:23Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Open-Xchange Server Translations for OX App Suite =&lt;br /&gt;
&lt;br /&gt;
=== Available Language Translations ===&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;3&amp;quot; cellspacing=&amp;quot;0&amp;quot;&lt;br /&gt;
!align=&amp;quot;left&amp;quot; |Language&lt;br /&gt;
!align=&amp;quot;left&amp;quot; |Code&lt;br /&gt;
!align=&amp;quot;left&amp;quot; |Status&lt;br /&gt;
!align=&amp;quot;left&amp;quot; |Documentation&lt;br /&gt;
!align=&amp;quot;left&amp;quot; |Contributor&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_us.png]] US English&lt;br /&gt;
| en_US&lt;br /&gt;
| Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange &lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_gb.png]] British English&lt;br /&gt;
| en_GB&lt;br /&gt;
| Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange &lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_de.png]] German&lt;br /&gt;
| de_DE&lt;br /&gt;
| Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_fr.png]] French&lt;br /&gt;
| fr_FR&lt;br /&gt;
| Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_cn.png]] Canadian French&lt;br /&gt;
| fr_CA&lt;br /&gt;
| Supported&lt;br /&gt;
| &lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_es.png]] Spanish &lt;br /&gt;
| es_ES&lt;br /&gt;
| Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_mx.png]] Mexican Spanish &lt;br /&gt;
| es_MX&lt;br /&gt;
| Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_nl.png]] Dutch &lt;br /&gt;
| nl_NL&lt;br /&gt;
| Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_pl.png]] Polish&lt;br /&gt;
| pl_PL&lt;br /&gt;
| Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:japanese.jpeg]] Japanese&lt;br /&gt;
| ja_JP&lt;br /&gt;
| Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_it.png]] Italian&lt;br /&gt;
| it_IT&lt;br /&gt;
| Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:china.jpg]] Simplified Chinese&lt;br /&gt;
| zh_CN&lt;br /&gt;
| Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:china.jpg]] Traditional Chinese&lt;br /&gt;
| zh_TW&lt;br /&gt;
| Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:ungarn.jpg]] Hungarian&lt;br /&gt;
| hu_HU&lt;br /&gt;
| Supported&lt;br /&gt;
| &lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Slovakia.jpg]] Slovak&lt;br /&gt;
| sk_SK&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Czech.jpg]] Czech&lt;br /&gt;
| cs_CZ&lt;br /&gt;
| Supported&lt;br /&gt;
| &lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:latvia.jpg]] Latvian&lt;br /&gt;
| lv_LV&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
|[[Image:Flag_romania.png]] Romanian&lt;br /&gt;
| ro_RO&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:brazil.png|17px]] Brazilian Portuguese&lt;br /&gt;
| pt_BR&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Flag_se.png|17px]] Swedish&lt;br /&gt;
| sv_SE&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Flag_dk.png|17px]] Danish&lt;br /&gt;
| da_DK&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Russian.png|17px]] Russian&lt;br /&gt;
| ru_RU&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[File:flag_fin.png|17px]] Finnish&lt;br /&gt;
| fi_FI&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[File:flag_Tur.png|17px]] Turkish&lt;br /&gt;
| tr_TR&lt;br /&gt;
| Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Any other languages which may be provided by installation packages are not supported and might even have a bad UI/UX impact when installed. Please use at your own risk!&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
[[Category: OX7]]&lt;br /&gt;
[[Category: AppSuite]]&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:OX_Guard&amp;diff=25643</id>
		<title>AppSuite:OX Guard</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:OX_Guard&amp;diff=25643"/>
		<updated>2020-11-04T22:52:23Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: /* Enabling Guard for Users */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= OX Guard (Version 2.10) =&lt;br /&gt;
&lt;br /&gt;
For previous versions of OX Guard, please click here&lt;br /&gt;
* [[AppSuite:OX_Guard_2-0 | Installation and information of OX Guard 2.0 - 2.2]]&lt;br /&gt;
* [[Appsuite:OX_Guard_2_8 | Installation and information of OX Guard 2.4 - 2.8]]&lt;br /&gt;
&lt;br /&gt;
If upgrading from 2.6 or 2.8, please see&lt;br /&gt;
* [[Appsuite:OX_Guard_Upgrade_2_10|Upgrading to 2.10]]&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
&lt;br /&gt;
OX Guard is a fully integrated security add-on to OX App Suite that provides end users with a flexible email and file encryption solution. OX Guard is a highly scalable, multi server, feature rich solution that is so simple-to-use that end users will actually use it. With a single click a user can take control of their security and send secure emails and share encrypted files. This can be done from any device to both OX App Suite and non-OX App Suite users.&lt;br /&gt;
&lt;br /&gt;
OX Guard uses standard PGP encryption for the encryption of email and files. PGP has been around for a long time, yet has not really caught on with the masses. This is generally blamed on the confusion and complications of managing the keys, understanding trust, PGP format types, and lack of trusted central key repositories. Guard simplifies all of this, making PGP encryption as easy as a one click process, with no keys to keep track of, yet the options of advanced PGP management for those that know how.&lt;br /&gt;
&lt;br /&gt;
This article will guide you through the installation of Guard and describes the basic configuration and software requirements. As it is intended as a quick walk-through it assumes an existing installation of the operating system including a single server App Suite setup as well as average system administration skills. This guide will also show you how to setup a basic installation with none of the typically used distributed environment settings. The objective of this guide is:&lt;br /&gt;
&lt;br /&gt;
* To setup a single server installation&lt;br /&gt;
* To setup a single Guard instance on an existing Open-Xchange installation, no cluster&lt;br /&gt;
* To use the database service on the existing Open-Xchange installation for Guard, no replication&lt;br /&gt;
* To provide a basic configuration setup, no mail server configuration&lt;br /&gt;
&lt;br /&gt;
=== Key Features ===&lt;br /&gt;
&lt;br /&gt;
* Simple security at the touch of a button&lt;br /&gt;
* Provides user based security - Separate from provider&lt;br /&gt;
* Supplementary security to Provider based security - Layered&lt;br /&gt;
* Powerful features yet simple to use and understand&lt;br /&gt;
* Security - Inside and outside of the OX environment&lt;br /&gt;
* Email and Drive integration&lt;br /&gt;
* Uses proven PGP security&lt;br /&gt;
&lt;br /&gt;
=== Availability ===&lt;br /&gt;
&lt;br /&gt;
If an OX App Suite customer would like to evaluate OX Guard integration, the first step is to contact OX Sales. OX Sales will then work on the request and send prices and license/API (for the hosted infrastructure) key details to the customer.&lt;br /&gt;
&lt;br /&gt;
=== Requirements ===&lt;br /&gt;
&lt;br /&gt;
Please review [https://oxpedia.org/wiki/index.php?title=AppSuite:OX_System_Requirements#OX_Guard OX Guard Requirements] for a full list of requirements.&lt;br /&gt;
&lt;br /&gt;
Since OX Guard is a Microservice it can either be added to an existing Open-Xchange installation or it can be deployed on a dedicated environment. The version of Guard installed is dependent on the Appsuite version installed.  Please refer to the version matrix below.&lt;br /&gt;
&lt;br /&gt;
==== Prerequisites ====&lt;br /&gt;
&lt;br /&gt;
* Open-Xchange REST API&lt;br /&gt;
* Grizzly HTTP connector (open-xchange-grizzly)&lt;br /&gt;
* A supported Java Virtual Machine (Java 8)&lt;br /&gt;
* An Open-Xchange App Suite installation (see version Matrix)&lt;br /&gt;
* Please Note: To get access to the latest minor features and bug fixes, you need to have a valid license. The article [https://oxpedia.org/wiki/index.php?title=AppSuite:UpdatingOXPackages Updating OX-Packages] explains how that can be done.&lt;br /&gt;
&lt;br /&gt;
==== Version Matrix ====&lt;br /&gt;
{|&lt;br /&gt;
! style=&amp;quot;text-align:left;&amp;quot;| Core Version&lt;br /&gt;
! Guard Version&lt;br /&gt;
|-&lt;br /&gt;
|7.8.1&lt;br /&gt;
|2.4.0 or 2.4.2&lt;br /&gt;
|-&lt;br /&gt;
|7.8.2&lt;br /&gt;
|2.4.2&lt;br /&gt;
|-&lt;br /&gt;
|7.8.3&lt;br /&gt;
|2.6.0&lt;br /&gt;
|-&lt;br /&gt;
|7.8.4&lt;br /&gt;
|2.8.0&lt;br /&gt;
|-&lt;br /&gt;
|7.10.0&lt;br /&gt;
|2.10.0&lt;br /&gt;
|-&lt;br /&gt;
|7.10.1&lt;br /&gt;
|2.10.1&lt;br /&gt;
|-&lt;br /&gt;
|7.10.2&lt;br /&gt;
|2.10.2&lt;br /&gt;
|-&lt;br /&gt;
|7.10.3&lt;br /&gt;
|2.10.3&lt;br /&gt;
|-&lt;br /&gt;
|7.10.4&lt;br /&gt;
|2.10.4&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Important Notes ===&lt;br /&gt;
&lt;br /&gt;
==== Customisation ====&lt;br /&gt;
&lt;br /&gt;
OX Guard version supports branding / theming using the configuration cascade, defining a templateID for a user or context. Check the [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCustomization OX Guard Customisation] article for more details.&lt;br /&gt;
&lt;br /&gt;
==== Mail Resolver ====&lt;br /&gt;
&lt;br /&gt;
READ THIS VERY CAREFULLY; BEFORE PROCEEDING WITH GUARD INSTALLATION!&lt;br /&gt;
&lt;br /&gt;
The Guard installation must be able to determine if an email recipient is a local OX user or if it should be a guest account. The default MailResolver uses the context domain name to do this. On many installations, domains may extend across multiple context and multiple database shards. In these cases, the default MailResolver won&#039;t work. In addition, if a custom authentication package is used, the Mail Resolver will likely not work.&lt;br /&gt;
&lt;br /&gt;
Once Guard is installed, please be sure to test the mail resolver using:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;/opt/open-xchange/sbin/guard test email@domain&amp;lt;/source&amp;gt;&lt;br /&gt;
to see if the mail Resolver works.&lt;br /&gt;
&lt;br /&gt;
If the test does not work, you will likely need a custom Mail Resolver. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardMailResolver Mail Resolver] page&lt;br /&gt;
&lt;br /&gt;
This resolver software &#039;&#039;depends heavily on your local deployment&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Download and Installation ==&lt;br /&gt;
&lt;br /&gt;
=== General ===&lt;br /&gt;
&lt;br /&gt;
The installation of the &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; package which is required for Guard and the main &amp;lt;code&amp;gt;open-xchange-guard&amp;lt;/code&amp;gt; package in version 2.4.0 or higher will eventually execute database update tasks if installed and activated. Please take this into account.&lt;br /&gt;
&lt;br /&gt;
There are several components to the Guard service. They can be all installed on the same server as the OX middleware or on a separate server.&lt;br /&gt;
&lt;br /&gt;
The components required for the OX middleware are: &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
The components required for the OX frontend are: &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; and optionally &amp;lt;code&amp;gt;open-xchange-guard-help-en-us&amp;lt;/code&amp;gt; (or preferred language for help files).&lt;br /&gt;
&lt;br /&gt;
The components required for the Guard server &amp;lt;code&amp;gt;open-xchange-guard&amp;lt;/code&amp;gt; and either &amp;lt;code&amp;gt;open-xchange-guard-file-storage&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;open-xchange-guard-s3-storage&amp;lt;/code&amp;gt; depending on what storage you want to use. The examples below make use of the &amp;lt;code&amp;gt;open-xchange-guard-file-storage&amp;lt;/code&amp;gt;. Adjust the commands accordingly to fit your needs. In addition &amp;lt;code&amp;gt;open-xchange&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-core&amp;lt;/code&amp;gt; are required to run OX Guard.&lt;br /&gt;
&lt;br /&gt;
=== Debian Linux 9.0 (Stretch) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 deb https://software.open-xchange.com/products/guard/stable/guard/DebianStretch /&lt;br /&gt;
 deb https://software.open-xchange.com/products/appsuite/stable/backend/DebianStretch /&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== Debian Linux 10.0 (Buster) *Version 2.10.3+ only* ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 deb https://software.open-xchange.com/products/guard/stable/guard/DebianBuster /&lt;br /&gt;
 deb https://software.open-xchange.com/products/appsuite/stable/backend/DebianBuster /&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== RedHat Enterprise Linux 6 or CentOS 6 (valid until v2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/guard/2.10.3/guard/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/7.10.3/backend/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== Redhat Enterprise Linux 7 or CentOS 7 ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/guard/stable/guard/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/stable/backend/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== SUSE Linux Enterprise Server 12 (valid until 2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
Add the package repository using zypper if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ar https://software.open-xchange.com/products/guard/2.10.3/guard/SLE_12 guard-stable-guard&lt;br /&gt;
 $ zypper ar https://software.open-xchange.com/products/appsuite/7.10.3/backend/SLE_12 ox-backend&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&lt;br /&gt;
 $ zypper in open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static&lt;br /&gt;
&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&lt;br /&gt;
 $ zypper in open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== Univention Corporate Server ===&lt;br /&gt;
&lt;br /&gt;
If you have purchased the OX App Suite for UCS, the OX Guard is part of the offering. OX Guard is available in the Univention App Center. Please check the UMC module App Center for the installation of the OX Guard at your already available environment.&lt;br /&gt;
&lt;br /&gt;
Please note: By default, OX Guard generates the link to the secure content for external recipients on the basis of the local fully qualified domain name (FQDN). If the local FQDN is not reachable from the Internet, it has to be specified manually. This can be done by setting a UCR variable, e.g. via the UMC module &amp;amp;quot;Univention Configuration Registry&amp;amp;quot;. The variable has to contain the external FQDN of the OX Guard system:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;oxguard/cfg/guard.properties/com.openexchange.guard.externalEmailURL=HOSTNAME.DOMAINNAME&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Update OX Guard ==&lt;br /&gt;
&lt;br /&gt;
This section contains information about updating a 2.10.0 version (e.g. for patch fixes). Upgrading from prior versions is discussed in different articles.&lt;br /&gt;
&lt;br /&gt;
=== Debian Linux 9.0 (Stretch) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 deb &amp;lt;https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/stable/guard/updates/DebianStretch /&amp;gt;&lt;br /&gt;
 deb &amp;lt;https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/stable/backend/DebianStretch /&amp;lt;/source&amp;gt;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Then run:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get dist-upgrade&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If you want to see, what apt-get is going to do without actually doing it, you can run:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get dist-upgrade -s&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Redhat Enterprise Linux 6 or CentOS 6 (valid until 2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard-updates]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard-updates&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/2.10.3/guard/updates/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/7.10.3/backend/updates/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
and then run:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum upgrade&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Redhat Enterprise Linux 7 or CentOS 7 ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard-updates]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard-updates&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/stable/guard/updates/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/stable/backend/updates/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
and then run:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum upgrade&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== SUSE Linux Enterprise Server 12 (valid until 2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
Add the package repository using &amp;lt;code&amp;gt;zypper&amp;lt;/code&amp;gt; if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ar https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/2.10.3/guard/updates/SLE_12 guard-stable-guard-updates&lt;br /&gt;
 $ zypper ar https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/7.10.3/backend/updates/SLE_12 ox-backend&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
and then run:&lt;br /&gt;
&lt;br /&gt;
 $ zypper dup -r guard-stable-guard-backend-updates&lt;br /&gt;
 $ zypper dup -r guard-stable-guard-ui-updates&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You might need to run:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
to update the repository metadata before running &amp;lt;code&amp;gt;zypper&amp;lt;/code&amp;gt; up.&lt;br /&gt;
&lt;br /&gt;
=== Univention Corporate Server ===&lt;br /&gt;
&lt;br /&gt;
If you have purchased the OX App Suite for UCS, the OX Guard is part of the offering. OX Guard is available in the Univention App Center. Please check the UMC module App Center for the update of the OX Guard.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Configuration ==&lt;br /&gt;
&lt;br /&gt;
The following gives an overview of the most important settings to enable Guard for users on the Open-Xchange installation. Some of those settings have to be modified in order to establish the database and REST API access from the Guard service. All settings relating to the Guard backend component are located in the configuration file &amp;lt;code&amp;gt;guard-core.properties&amp;lt;/code&amp;gt; located in &amp;lt;code&amp;gt;/opt/open-xchange/etc&amp;lt;/code&amp;gt;. The default configuration should be sufficient for a basic &amp;amp;quot;up-and-running&amp;amp;quot; setup (with the exception of defining the database username and password). Please refer to the inline documentation of the configuration file for more advanced options. Additional information can be found in the [https://oxpedia.org/wiki/index.php?title=AppSuite:OX_Guard_Configuration_2_10 Guard Configuration] article.&lt;br /&gt;
&lt;br /&gt;
=== Basic Configuration ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/guard-core.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
Guard database for storing Guard user information, main lookup tables:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.oxguardDatabaseHostname=localhost&amp;lt;/source&amp;gt;&lt;br /&gt;
Guard database that stores keys for guest users. May be the same as above. New guest shards will be created on this database as needed. If not supplied, will use the &amp;lt;code&amp;gt;oxguardDatabaseHostname&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.oxguardShardDatabase=localhost&amp;lt;/source&amp;gt;&lt;br /&gt;
Username and Password for the databases above:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.databaseUsername=openexchange&lt;br /&gt;
com.openexchange.guard.databasePassword=db_password&amp;lt;/source&amp;gt;&lt;br /&gt;
Open-Xchange REST API host:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.restApiHostname=localhost&amp;lt;/source&amp;gt;&lt;br /&gt;
Open-Xchange REST API username and password (need to be defined in the OX backend in the &amp;amp;quot;Configure services&amp;amp;quot; below):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.restApiUsername=apiusername&lt;br /&gt;
com.openexchange.guard.restApiPassword=apipassword&amp;lt;/source&amp;gt;&lt;br /&gt;
External URL for this Open-Xchange installation. This setting will be used to generate the link to the secure content for external recipients:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.externalEmailURL=URL_TO_OX&amp;lt;/source&amp;gt;&lt;br /&gt;
=== Middleware Configuration on OX Guard node ===&lt;br /&gt;
&lt;br /&gt;
If you are installing OX Guard on a node that until yet did not host an Open-Xchange middleware you have to additionally configure some parts of the following properties files:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;configdb.properties&amp;lt;/code&amp;gt;: information about the existing configuration database.&lt;br /&gt;
* &amp;lt;code&amp;gt;server.properties&amp;lt;/code&amp;gt;: information about the connections have to be set.&lt;br /&gt;
* &amp;lt;code&amp;gt;system.properties&amp;lt;/code&amp;gt;: at least &amp;lt;code&amp;gt;SERVER_NAME&amp;lt;/code&amp;gt; should be set.&lt;br /&gt;
&lt;br /&gt;
=== Sevices Configuration ===&lt;br /&gt;
&lt;br /&gt;
==== Apache ====&lt;br /&gt;
&lt;br /&gt;
Configure the &amp;lt;code&amp;gt;mod_proxy_http&amp;lt;/code&amp;gt; module by adding the Guard API.&lt;br /&gt;
&lt;br /&gt;
===== Redhat Enterprise Linux 6 or CentOS 6 =====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /etc/httpd/conf.d/proxy_http.conf&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Debian GNU/Linux 9.0 =====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /etc/apache2/conf-enabled/proxy_http.conf&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;Proxy balancer://oxguard&amp;gt;&lt;br /&gt;
        Order deny,allow&lt;br /&gt;
        Allow from all&lt;br /&gt;
 &lt;br /&gt;
        BalancerMember http://localhost:8009/ timeout=1800 smax=0 ttl=60 retry=60 loadfactor=100 route=OX1&lt;br /&gt;
        ProxySet stickysession=JSESSIONID|jsessionid scolonpathdelim=ON&lt;br /&gt;
       SetEnv proxy-initial-not-pooled&lt;br /&gt;
        SetEnv proxy-sendchunked&lt;br /&gt;
 &amp;lt;/Proxy&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
 ProxyPass /appsuite/api/oxguard balancer://oxguard/oxguard&lt;br /&gt;
 ProxyPass /pks balancer://oxguard/pgp&lt;br /&gt;
 ProxyPass /.well-known/openpgpkey/hu balancer://oxguard/hu&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: The Guard API settings must be inserted &#039;&#039;&#039;&#039;&#039;before&#039;&#039;&#039;&#039;&#039; the existing &amp;lt;code&amp;gt;ProxyPass /appsuite/api&amp;lt;/code&amp;gt; parameter.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Also Note&#039;&#039;&#039;:  If you already have a Proxy balancer for the OX backend with the same URL (say http://localhost:8080) then you don&#039;t need the second BalancerMember entry, and you can just have the ProxyPass address that balancer instead.&lt;br /&gt;
&lt;br /&gt;
After the configuration is done, restart the Apache webserver&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ apachectl restart&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Open-Xchange Middleware Configuration ===&lt;br /&gt;
&lt;br /&gt;
Edit the &amp;lt;code&amp;gt;guard-api.properties&amp;lt;/code&amp;gt; configuration file for the OX backend where the guard-backend-plugin was installed. Please remove comments in front of the following settings to the configuration file &amp;lt;code&amp;gt;guard-api.properties&amp;lt;/code&amp;gt; on the Open-Xchange backend servers:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/guard-api.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;# OX Guard general permission, required to activate Guard in the AppSuite UI.&lt;br /&gt;
com.openexchange.capability.guard=true&lt;br /&gt;
&lt;br /&gt;
# Default theme template id for all users that have no custom template id configured.&lt;br /&gt;
com.openexchange.guard.templateID=0&amp;lt;/source&amp;gt;&lt;br /&gt;
Configure the API username and password that you assigned to Guard in the &amp;lt;code&amp;gt;server.properties&amp;lt;/code&amp;gt; file:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/server.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;# Specify the user name used for HTTP basic auth by internal REST servlet&lt;br /&gt;
com.openexchange.rest.services.basic-auth.login=apiusername&lt;br /&gt;
&lt;br /&gt;
# Specify the password used for HTTP basic auth by internal REST servlet&lt;br /&gt;
com.openexchange.rest.services.basic-auth.password=apipassword&amp;lt;/source&amp;gt;&lt;br /&gt;
Finally, the OX backend needs to know where the Guard server is located. This is used to notify the Guard server of changes in users, and to send emails marked for signature. The URL for the Guard server should include the URL suffix &amp;lt;code&amp;gt;/guardadmin&amp;lt;/code&amp;gt;. In the event of a cluster setup, any Guard server can be referenced here, as it is not session specific, though ideally would have a HTTP load balancer/failover URL:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/guard-api.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;# Specifies the URI to the OX Guard end-point; e.g. http://guard.host.invalid:8081/guardadmin&lt;br /&gt;
# Default is empty&lt;br /&gt;
com.openexchange.guard.endpoint=http://guardserver:8009/guardadmin&amp;lt;/source&amp;gt;&lt;br /&gt;
Restart the OX backend&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /etc/init.d/open-xchange restart&amp;lt;/source&amp;gt;&lt;br /&gt;
==== SELinux ====&lt;br /&gt;
&lt;br /&gt;
Running SELinux prohibits your local Open-Xchange backend service to connect to localhost:8009, which is where the Guard backend service listens to. In order to allow localhost connections to 8009 execute the following:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ setsebool -P httpd_can_network_connect 1&amp;lt;/source&amp;gt;&lt;br /&gt;
=== Generating the &amp;lt;code&amp;gt;oxguardpass&amp;lt;/code&amp;gt; ===&lt;br /&gt;
&lt;br /&gt;
Once the Guard configuration (database and backend configuration) and the service configuration has been applied, the Guard administration script needs to be executed in order to create the master password file in &amp;lt;code&amp;gt;/opt/open-xchange/etc/oxguardpass&amp;lt;/code&amp;gt;. The initiation only needs to be done &#039;&#039;&#039;once&#039;&#039;&#039; for a multi server setup, for details please see the sections &#039;&#039;&#039;Optional&#039;&#039;&#039; and/or &#039;&#039;&#039;Clustering&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: If you run a cluster of OX / Guard nodes, only execute this command on &#039;&#039;&#039;ONE&#039;&#039;&#039; node. Not on all nodes! See [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCluster OX Guard Clustering] for details.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /opt/open-xchange/sbin/guard --init&amp;lt;/source&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: It is important to understand that the master password file located at &amp;lt;code&amp;gt;/opt/open-xchange/etc/oxguardpass&amp;lt;/code&amp;gt; is required to reset user passwords; without them the administrator will not be able to reset user passwords anymore in the future. The file contains the passwords used to encrypt the master database key, as well as passwords used to encrypt protected data in the users table. It must be the same on all Guard servers.&lt;br /&gt;
&lt;br /&gt;
=== Test Setup ===&lt;br /&gt;
&lt;br /&gt;
Not required, but it is a good idea to test the Guard setup before enabling for any users. The test function will verify that Guard has a good connection to the OX backend, and that it can resolve email addresses to users.&lt;br /&gt;
&lt;br /&gt;
To test, use an email address that exists on the OX backend (john@example.com for this example)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;/opt/open-xchange/sbin/guard --test john@example.com&amp;lt;/source&amp;gt;&lt;br /&gt;
Guard should return information from the OX backend regarding the user associated with &amp;amp;quot;john@example.com&amp;amp;quot;. Problems resolving information for the user should be resolved before using Guard. Check Rest API passwords and settings if errors returned.&lt;br /&gt;
&lt;br /&gt;
=== Enabling Guard for Users ===&lt;br /&gt;
&lt;br /&gt;
Guard provides three capabilities for users in the environment as well as a basic &amp;amp;quot;core&amp;amp;quot; level:&lt;br /&gt;
&lt;br /&gt;
* Guard: &amp;lt;code&amp;gt;com.openexchange.capability.guard&amp;lt;/code&amp;gt;&lt;br /&gt;
* Guard Mail: &amp;lt;code&amp;gt;com.openexchange.capability.guard-mail&amp;lt;/code&amp;gt;&lt;br /&gt;
* Guard Drive: &amp;lt;code&amp;gt;com.openexchange.capability.guard-drive&amp;lt;/code&amp;gt;&lt;br /&gt;
* Guard Docs: &amp;lt;code&amp;gt;com.openexchange.capability.guard-docs&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The &amp;amp;quot;core&amp;amp;quot; Guard enabled a basic read functionality for Guard encrypted emails. We recommend enabling this for all users, as this allows all recipients to read Guard emails sent to them. Great opportunity for upsell. Recipients with only Guard enabled can then do a secure reply to the sender, but they can&#039;t start a new email or add recipients.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Guard Mail&#039;&#039;&#039;, &#039;&#039;&#039;Guard Drive&#039;&#039;&#039; and &#039;&#039;&#039;Guard Docs&#039;&#039;&#039; are additional options for users. &amp;amp;quot;Guard Mail&amp;amp;quot; allows users the full functionality of Guard emails. &amp;amp;quot;Guard Drive&amp;amp;quot; allows for encryption and decryption of Drive files and &amp;amp;quot;Guard Docs&amp;amp;quot; allows direct integration of Guard into Documents.&lt;br /&gt;
&lt;br /&gt;
Each of those three Guard components is enabled for all users that have the according capability configured. Please note that users need to have the Drive permission set to use Guard Drive. So the users that have Guard Drive enabled must be a subset of those users with OX Drive permission. Since v7.6.0 we enforce this via the default configuration. Those capabilities can be activated for specific user by using the Open-Xchange provisioning scripts:&lt;br /&gt;
&lt;br /&gt;
==== Guard Mail: ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /opt/open-xchange/sbin/changeuser -c 1 -A oxadmin -P admin_password -u testuser --config/com.openexchange.capability.guard-mail=true&amp;lt;/source&amp;gt;&lt;br /&gt;
==== Guard Drive: ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /opt/open-xchange/sbin/changeuser -c 1 -A oxadmin -P admin_password -u testuser --config/com.openexchange.capability.guard-drive=true&amp;lt;/source&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: Guard Drive requires Guard Mail to be configured for the user as well. In addition, these capabilities may be configured globally by editing the &amp;lt;code&amp;gt;guard-api.properties&amp;lt;/code&amp;gt; file on the OX backend.&lt;br /&gt;
&lt;br /&gt;
=== External Guest recipients ===&lt;br /&gt;
Starting in Guard 2.10.0, when an encrypted email is sent to a user that does not have Guard, a guest account is created for them in appsuite.  The recipient uses the Guest account to read the encrypted email.  These guest users MUST have guard capabilities.  To do this, guard capability must be added to guest accounts.&lt;br /&gt;
&amp;lt;code&amp;gt;/opt/open-xchange/etc/share.properties&amp;lt;/code&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.share.guestCapabilityMode=static&lt;br /&gt;
com.openexchange.share.staticGuestCapabilities=guard&amp;lt;/source&amp;gt;&lt;br /&gt;
In a distributed system, the Guest accounts should not be considered transient.  Guard servers must be able to verify the guest account exists in the session storage services.&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.share.transientSessions=false&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Guest Storage ===&lt;br /&gt;
When an encrypted email is sent to an external Guest, a copy of the fully encrypted email is stored on the server.  This is used to create an inbox of encrypted emails for the guest.  By entering in a password, the emails can be decrypted and displayed.&lt;br /&gt;
&lt;br /&gt;
How these files are stored depend on which package, open-xchange-guard-file-storage or open-xchange-guard-s3-storage, was installed.&lt;br /&gt;
&lt;br /&gt;
The file retention policy is configured in the guard-core.properties file.&lt;br /&gt;
&lt;br /&gt;
=== Recipient key detection ===&lt;br /&gt;
&lt;br /&gt;
==== Local ====&lt;br /&gt;
&lt;br /&gt;
Guard needs to determine if an email recipients email address is an internal or external (non-ox) user.&lt;br /&gt;
&lt;br /&gt;
To detect if the recipient is an account on the same OX Guard system there is a mechanism needed to map a recipient mail address to the correct local OX context. The default implementation delivered in the product achieves that by looking up the mail domain (@example.com) within the list of context mappings. That is at least not possible in case of ISPs where different users/contexts use the same mail domain. In case your OX system does not use mail domains in context mappings it is required to deploy an OX OSGi bundle implementing the &amp;lt;code&amp;gt;com.openexchange.mailmapping.MailResolver&amp;lt;/code&amp;gt; class or by interfacing Guard with your mail resolver system. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardMailResolver OX Guard Mail Resolver] for details.&lt;br /&gt;
&lt;br /&gt;
==== External ====&lt;br /&gt;
&lt;br /&gt;
Starting with Guard 2.0, Guard will use public PGP Key servers if configured to find PGP Public keys. In addition, Guard will also look up SRV records for PGP Key servers for a recipients domain. This follows the standards [http://tools.ietf.org/html/draft-shaw-openpgp-hkp-00#page-9 OpenPGP Draft].&lt;br /&gt;
&lt;br /&gt;
External PGP servers to use can be configured in the guard.properties file on the Guard servers.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.publicPGPDirectory = hkp://keys.gnupg.net:11371, hkp://pgp.mit.edu:11371&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If you would like this Guard installation discoverable as HKP service by other Guard servers, then create an SRV record for each domain (&amp;amp;quot;example.com&amp;amp;quot; in this illustration):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;_hkp._tcp.example.com. 28800 IN    SRV     10 1 80 appsuite.example.com.&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039; PGP Public key servers by default append the path /pks when the record is obtained from an SRV record. The proxy (also included in Apache config above) routes anything under /pks to the OX Guard PGP server.&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;ProxyPass /pks balancer://oxguard/pgp&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Guard keys are also discoverable using the webkey service as specified here: https://tools.ietf.org/html/draft-koch-openpgp-webkey-service-02&lt;br /&gt;
This is enabled if you include the &lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;ProxyPass /.well-known/openpgpkey/hu balancer://oxguard/hu&amp;lt;/source&amp;gt;&lt;br /&gt;
in the proxy_http.conf as above.&lt;br /&gt;
Please note that the well-known request is targeted at the domain part of the mail address. Therefore clients will request for a mail address name@example.com the URI https://example.com/.well-known/openpgpkey/hu/...&lt;br /&gt;
&lt;br /&gt;
That means that there is the very likely need that some sort of proxying or rewriting from the webserver providing the domain needs to happen. For example for proxying using Apache 2.4 it would roughly look like this:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
SSLProxyEngine on&lt;br /&gt;
&amp;lt;LocationMatch /.well-known/openpgpkey/&amp;gt;&lt;br /&gt;
    ProxyPass https://ox.example.com/.well-known/openpgpkey/&lt;br /&gt;
&amp;lt;/LocationMatch&amp;gt;&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clustering ===&lt;br /&gt;
&lt;br /&gt;
You can run multiple OX Guard servers in your environment to ensure high availability or enhance scalability. OX Guard integrates seamlessly into the existing Open-Xchange infrastructure by using the existing interface standards and is therefor transparent to the environment. A couple of things have to be prepared in order to loosely couple OX Guard servers with Open-Xchange servers in a cluster.&lt;br /&gt;
&lt;br /&gt;
==== MySQL ====&lt;br /&gt;
&lt;br /&gt;
The MySQL servers need to be configured in order to allow access to the configdb of Open-Xchange. To do so you need to set the following configuration in the MySQL &amp;lt;code&amp;gt;my.cnf&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;bind = 0.0.0.0&amp;lt;/source&amp;gt;&lt;br /&gt;
This allows the Guard backend to bind to the MySQL host which is configured in the &amp;lt;code&amp;gt;guard-core.properties&amp;lt;/code&amp;gt; file with &amp;lt;code&amp;gt;com.openexchange.guard.configdbHostname&amp;lt;/code&amp;gt;. After the bind for the MySQL instance is configured and the OX Guard backend would be able to connect to the configured host, you have to grant access for the OX Guard service on the MySQL instance to manage the databases. Do so by connecting to the MySQL server via the MySQL client. Authenticate if necessary and execute the following, please note that you have to modify the hostname / IP address of the client who should be able to connect to this database, it should include all possible OX Guard servers:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;sql&amp;quot;&amp;gt;GRANT ALL PRIVILEGES ON *.* TO &#039;openexchange&#039;@&#039;oxguard.example.com&#039; IDENTIFIED BY ‘secret’;&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Apache ====&lt;br /&gt;
&lt;br /&gt;
OX Guard uses the Open-Xchange REST API to store and fetch data from the Open-Xchange databases. The REST API is a servlet running in the Grizzly container. By default it is not exposed as a servlet through Apache and is only accessibly via port 8009. In order to use Apache&#039;s load balancing via &amp;lt;code&amp;gt;mod_proxy&amp;lt;/code&amp;gt; we need to add a servlet called &amp;amp;quot;preliminary&amp;amp;quot; to &amp;lt;code&amp;gt;proxy_http.conf&amp;lt;/code&amp;gt;, example based on a clustered &amp;lt;code&amp;gt;mod_proxy&amp;lt;/code&amp;gt;configuration:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;Location /preliminary&amp;gt;&lt;br /&gt;
      Order Deny,Allow&lt;br /&gt;
      Deny from all&lt;br /&gt;
      # Only allow access from Guard servers within the network. Do not expose this&lt;br /&gt;
      # location outside of your network. In case you use a load balancing service in front&lt;br /&gt;
      # of your Apache infrastructure you should make sure that access to /preliminary will&lt;br /&gt;
      # be blocked from the Internet / outside clients. Examples:&lt;br /&gt;
      # Allow from 192.168.0.1&lt;br /&gt;
      # Allow from 192.168.1.1 192.168.1.2&lt;br /&gt;
      # Allow from 192.168.0.&lt;br /&gt;
 &amp;lt;/Location&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
 ProxyPass /preliminary balancer://oxcluster/preliminary&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Make sure that the balancer is properly configured in the &amp;lt;code&amp;gt;mod_proxy&amp;lt;/code&amp;gt; configuration. Examples on how to do so can be found in our clustering configuration for Open-Xchange AppSuite. Like explained in the example above, please make sure that this location is only available in your internal network, there is no need to expose &amp;lt;code&amp;gt;/preliminary&amp;lt;/code&amp;gt; to the public, it is only used by Guard servers to connect to the OX backend. If you have a load balancer in front of the Apache cluster you should consider blocking access to &amp;lt;code&amp;gt;/preliminary&amp;lt;/code&amp;gt; from WAN to restrict access to the servlet to internal network services only.&lt;br /&gt;
&lt;br /&gt;
Now add the OX Guard &amp;lt;code&amp;gt;BalancerMembers&amp;lt;/code&amp;gt; to the oxguard balancer configuration (also in &amp;lt;code&amp;gt;proxy_http.conf&amp;lt;/code&amp;gt;) to address all your OX Guard nodes in the cluster in this balancer configuration. The configuration has to be applied to all Apache nodes within the cluster.&lt;br /&gt;
&lt;br /&gt;
If the Apache server is a dedicated server &amp;lt;code&amp;gt;/&amp;lt;/code&amp;gt; instance you also have to install the OX Guard UI-Static package on all Apache nodes in the cluster in order to provide static files like images or CSS to the OX Guard client. Example for Debian (the OX Guard repository has to be configured in the package management prior):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ apt-get install open-xchange-guard-ui-static&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Open-Xchange ====&lt;br /&gt;
&lt;br /&gt;
Disable the Open-Xchange IPCheck for session verification. This is required because OX Guard will use the users session cookie to connect to the Open-Xchange REST API, but as a different IP address than the OX Guard server has been used during authentication the request would fail if you don&#039;t disable the IPCheck:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/server.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
and set:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.IPCheck=false&amp;lt;/source&amp;gt;&lt;br /&gt;
The OX Guard UI package has to be installed on all Open-Xchange backend nodes as well, example for Debian (the OX Guard repository has to be configured in the package management prior):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ apt-get install open-xchange-guard-ui&amp;lt;/source&amp;gt;&lt;br /&gt;
Restart the Open-Xchange service afterwards.&lt;br /&gt;
&lt;br /&gt;
==== OX Guard ====&lt;br /&gt;
&lt;br /&gt;
For details in clustering Guard servers, please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCluster OX Guard Clustering]. It is &#039;&#039;&#039;critical&#039;&#039;&#039; that all Guard servers have the same &amp;lt;code&amp;gt;oxguardpass&amp;lt;/code&amp;gt; file. Please see the clustering link for details. Do not run &amp;lt;code&amp;gt;/opt/open-xchange/sbin/guard --init&amp;lt;/code&amp;gt; on more than one server.&lt;br /&gt;
&lt;br /&gt;
After all the services like MySQL, Apache and Open-Xchange have been configured you need to update the OX Guard backend configuration to point to the correct API endpoints. Set the REST API endpoint to an Apache server by setting the following value in &amp;lt;code&amp;gt;/opt/open-xchange/etc/guard-core.properties&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.restApiHostname=apache.example.com&amp;lt;/source&amp;gt;&lt;br /&gt;
Per default Guard will try to connect to port 8009 to this host, but as we configured the REST API to be proxies thorugh the servlet &amp;lt;code&amp;gt;/preliminary&amp;lt;/code&amp;gt; on every Apache we now also need to change the target port for the REST API. You can do so by adding the following line into &amp;lt;code&amp;gt;/opt/open-xchange/etc/guard-core.properties&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.oxBackendPort=80&amp;lt;/source&amp;gt;&lt;br /&gt;
Please also change all settings in regards to MySQL like &amp;lt;code&amp;gt;com.openexchange.guard.configdbHostname&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;com.openexchange.guard.oxguardDatabaseHostname&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;com.openexchange.guard.databaseUsername&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;om.openexchange.guard.databasePassword&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Afterwards restart the OX Guard service and check the log file if the OX Guard backend is able to connect to the configured REST API.&lt;br /&gt;
&lt;br /&gt;
=== Multi Node ===&lt;br /&gt;
&lt;br /&gt;
If you have multiple OX and Guard installations, please see the following documentation [https://oxpedia.org/wiki/index.php?title=AppSuite:OX_Guard_Modular OX Guard Modular Setup].&lt;br /&gt;
&lt;br /&gt;
=== Mail Filter Integration (2.10.4+) ===&lt;br /&gt;
&lt;br /&gt;
To add additional mail filter tests (verify PGP signature, or encrypt incoming), please see&lt;br /&gt;
[[AppSuite:OX_Guard_MailFilter | MailFilter Integration]]&lt;br /&gt;
&lt;br /&gt;
== Support API ==&lt;br /&gt;
&lt;br /&gt;
The OX Guard Support API enables administrative access to various functions for maintaining OX Guard from a client in a role as a support employee. A client has to do a BASIC AUTH authentication in order to access the API. Username and password can be configured in the guard-core.properties file using the following settings:&lt;br /&gt;
&lt;br /&gt;
 # Specify the username and password for accessing the Support API of Guard&lt;br /&gt;
 com.openexchange.guard.supportApiUsername=&lt;br /&gt;
 com.openexchange.guard.supportApiPassword=&lt;br /&gt;
&lt;br /&gt;
In contrast to the rest of the OX Guard requests, the OX Guard support API requests are accessible using: /guardsupport. This distinction allows more flexible configuration since the support API should not always be accessible from everywhere. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Warning&#039;&#039;&#039;: Exposing the support API to the internet could be huge security risk. Only add to Apache if you know what you are doing.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Reset password ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=reset_password&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Performs a password reset and sends a new random generated password to a specified email address by the user or a default address if the user did not specify an email address. (&#039;&#039;Since Guard 2.0&#039;&#039;)&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;email&amp;lt;/code&amp;gt; – The email address of the user to reset the password for&lt;br /&gt;
* &amp;lt;code&amp;gt;default&amp;lt;/code&amp;gt; (optional) – The email address to send the new password to, if the user did not specify a secondary email address&lt;br /&gt;
&lt;br /&gt;
Response:&lt;br /&gt;
PRIMARY if the reset was sent to the primary email address.  SECONDARY if the reset email was sent to the secondary email address that the user specified&lt;br /&gt;
&lt;br /&gt;
=== Expose key ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=expose_key&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Marks a deleted user key temporary as “exposed” and creates a unique URL for downloading the exposed key. Automatic resetting of exposed keys to &amp;amp;quot;not exposed&amp;amp;quot; is scheduled once a day and resets all exposed keys which have been exposed before X hours, where X can be configured using com.openexchange.guard.exposedKeyDurationInHours in the guard.properties files. (&#039;&#039;Since Guard 2.0&#039;&#039;)&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;email&amp;lt;/code&amp;gt; – The email address of the user to expose the deleted keys for&lt;br /&gt;
* &amp;lt;code&amp;gt;cid&amp;lt;/code&amp;gt; – The context id&lt;br /&gt;
&lt;br /&gt;
Response: A URL pointing to the downloadable exposed keys.&lt;br /&gt;
&lt;br /&gt;
=== Delete user ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=delete_user&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deletes all keys related to a certain user. The keys are backed up and can be exposed using the “expose_key” call. (&#039;&#039;Since Guard 2.0&#039;&#039;)&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;user_id&amp;lt;/code&amp;gt; – The user&#039;s id&lt;br /&gt;
* &amp;lt;code&amp;gt;cid&amp;lt;/code&amp;gt; - The context id&lt;br /&gt;
&lt;br /&gt;
=== Upgrade User (Release 2.10 and later) ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=upgrade_guest&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Upgrades a Guest account.  This action copies all of the keys from the Guest account to a full OX account, assuming that user has Guard capabilities.&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;email&amp;lt;/code&amp;gt; - The email address of the Guest user&lt;br /&gt;
* &amp;lt;code&amp;gt;user_id&amp;lt;/code&amp;gt; – The user&#039;s new id&lt;br /&gt;
* &amp;lt;code&amp;gt;cid&amp;lt;/code&amp;gt; - The user&#039;s new context id&lt;br /&gt;
&lt;br /&gt;
== Customisation ==&lt;br /&gt;
&lt;br /&gt;
Guard&#039;s templates are customisable at the user and context level. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCustomization Customisation] for details.&lt;br /&gt;
&lt;br /&gt;
== Entropy ==&lt;br /&gt;
&lt;br /&gt;
Guard requires entropy (randomness) to generate the private/public keys that are used. Depending on the server and it&#039;s environment, this may become a problem. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardEntropy Entropy] for a possible solution.&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:OX_Guard&amp;diff=25623</id>
		<title>AppSuite:OX Guard</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:OX_Guard&amp;diff=25623"/>
		<updated>2020-10-10T07:05:38Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: /* External */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= OX Guard (Version 2.10) =&lt;br /&gt;
&lt;br /&gt;
For previous versions of OX Guard, please click here&lt;br /&gt;
* [[AppSuite:OX_Guard_2-0 | Installation and information of OX Guard 2.0 - 2.2]]&lt;br /&gt;
* [[Appsuite:OX_Guard_2_8 | Installation and information of OX Guard 2.4 - 2.8]]&lt;br /&gt;
&lt;br /&gt;
If upgrading from 2.6 or 2.8, please see&lt;br /&gt;
* [[Appsuite:OX_Guard_Upgrade_2_10|Upgrading to 2.10]]&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
&lt;br /&gt;
OX Guard is a fully integrated security add-on to OX App Suite that provides end users with a flexible email and file encryption solution. OX Guard is a highly scalable, multi server, feature rich solution that is so simple-to-use that end users will actually use it. With a single click a user can take control of their security and send secure emails and share encrypted files. This can be done from any device to both OX App Suite and non-OX App Suite users.&lt;br /&gt;
&lt;br /&gt;
OX Guard uses standard PGP encryption for the encryption of email and files. PGP has been around for a long time, yet has not really caught on with the masses. This is generally blamed on the confusion and complications of managing the keys, understanding trust, PGP format types, and lack of trusted central key repositories. Guard simplifies all of this, making PGP encryption as easy as a one click process, with no keys to keep track of, yet the options of advanced PGP management for those that know how.&lt;br /&gt;
&lt;br /&gt;
This article will guide you through the installation of Guard and describes the basic configuration and software requirements. As it is intended as a quick walk-through it assumes an existing installation of the operating system including a single server App Suite setup as well as average system administration skills. This guide will also show you how to setup a basic installation with none of the typically used distributed environment settings. The objective of this guide is:&lt;br /&gt;
&lt;br /&gt;
* To setup a single server installation&lt;br /&gt;
* To setup a single Guard instance on an existing Open-Xchange installation, no cluster&lt;br /&gt;
* To use the database service on the existing Open-Xchange installation for Guard, no replication&lt;br /&gt;
* To provide a basic configuration setup, no mail server configuration&lt;br /&gt;
&lt;br /&gt;
=== Key Features ===&lt;br /&gt;
&lt;br /&gt;
* Simple security at the touch of a button&lt;br /&gt;
* Provides user based security - Separate from provider&lt;br /&gt;
* Supplementary security to Provider based security - Layered&lt;br /&gt;
* Powerful features yet simple to use and understand&lt;br /&gt;
* Security - Inside and outside of the OX environment&lt;br /&gt;
* Email and Drive integration&lt;br /&gt;
* Uses proven PGP security&lt;br /&gt;
&lt;br /&gt;
=== Availability ===&lt;br /&gt;
&lt;br /&gt;
If an OX App Suite customer would like to evaluate OX Guard integration, the first step is to contact OX Sales. OX Sales will then work on the request and send prices and license/API (for the hosted infrastructure) key details to the customer.&lt;br /&gt;
&lt;br /&gt;
=== Requirements ===&lt;br /&gt;
&lt;br /&gt;
Please review [https://oxpedia.org/wiki/index.php?title=AppSuite:OX_System_Requirements#OX_Guard OX Guard Requirements] for a full list of requirements.&lt;br /&gt;
&lt;br /&gt;
Since OX Guard is a Microservice it can either be added to an existing Open-Xchange installation or it can be deployed on a dedicated environment. The version of Guard installed is dependent on the Appsuite version installed.  Please refer to the version matrix below.&lt;br /&gt;
&lt;br /&gt;
==== Prerequisites ====&lt;br /&gt;
&lt;br /&gt;
* Open-Xchange REST API&lt;br /&gt;
* Grizzly HTTP connector (open-xchange-grizzly)&lt;br /&gt;
* A supported Java Virtual Machine (Java 8)&lt;br /&gt;
* An Open-Xchange App Suite installation (see version Matrix)&lt;br /&gt;
* Please Note: To get access to the latest minor features and bug fixes, you need to have a valid license. The article [https://oxpedia.org/wiki/index.php?title=AppSuite:UpdatingOXPackages Updating OX-Packages] explains how that can be done.&lt;br /&gt;
&lt;br /&gt;
==== Version Matrix ====&lt;br /&gt;
{|&lt;br /&gt;
! style=&amp;quot;text-align:left;&amp;quot;| Core Version&lt;br /&gt;
! Guard Version&lt;br /&gt;
|-&lt;br /&gt;
|7.8.1&lt;br /&gt;
|2.4.0 or 2.4.2&lt;br /&gt;
|-&lt;br /&gt;
|7.8.2&lt;br /&gt;
|2.4.2&lt;br /&gt;
|-&lt;br /&gt;
|7.8.3&lt;br /&gt;
|2.6.0&lt;br /&gt;
|-&lt;br /&gt;
|7.8.4&lt;br /&gt;
|2.8.0&lt;br /&gt;
|-&lt;br /&gt;
|7.10.0&lt;br /&gt;
|2.10.0&lt;br /&gt;
|-&lt;br /&gt;
|7.10.1&lt;br /&gt;
|2.10.1&lt;br /&gt;
|-&lt;br /&gt;
|7.10.2&lt;br /&gt;
|2.10.2&lt;br /&gt;
|-&lt;br /&gt;
|7.10.3&lt;br /&gt;
|2.10.3&lt;br /&gt;
|-&lt;br /&gt;
|7.10.4&lt;br /&gt;
|2.10.4&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Important Notes ===&lt;br /&gt;
&lt;br /&gt;
==== Customisation ====&lt;br /&gt;
&lt;br /&gt;
OX Guard version supports branding / theming using the configuration cascade, defining a templateID for a user or context. Check the [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCustomization OX Guard Customisation] article for more details.&lt;br /&gt;
&lt;br /&gt;
==== Mail Resolver ====&lt;br /&gt;
&lt;br /&gt;
READ THIS VERY CAREFULLY; BEFORE PROCEEDING WITH GUARD INSTALLATION!&lt;br /&gt;
&lt;br /&gt;
The Guard installation must be able to determine if an email recipient is a local OX user or if it should be a guest account. The default MailResolver uses the context domain name to do this. On many installations, domains may extend across multiple context and multiple database shards. In these cases, the default MailResolver won&#039;t work. In addition, if a custom authentication package is used, the Mail Resolver will likely not work.&lt;br /&gt;
&lt;br /&gt;
Once Guard is installed, please be sure to test the mail resolver using:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;/opt/open-xchange/sbin/guard test email@domain&amp;lt;/source&amp;gt;&lt;br /&gt;
to see if the mail Resolver works.&lt;br /&gt;
&lt;br /&gt;
If the test does not work, you will likely need a custom Mail Resolver. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardMailResolver Mail Resolver] page&lt;br /&gt;
&lt;br /&gt;
This resolver software &#039;&#039;depends heavily on your local deployment&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Download and Installation ==&lt;br /&gt;
&lt;br /&gt;
=== General ===&lt;br /&gt;
&lt;br /&gt;
The installation of the &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; package which is required for Guard and the main &amp;lt;code&amp;gt;open-xchange-guard&amp;lt;/code&amp;gt; package in version 2.4.0 or higher will eventually execute database update tasks if installed and activated. Please take this into account.&lt;br /&gt;
&lt;br /&gt;
There are several components to the Guard service. They can be all installed on the same server as the OX middleware or on a separate server.&lt;br /&gt;
&lt;br /&gt;
The components required for the OX middleware are: &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
The components required for the OX frontend are: &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; and optionally &amp;lt;code&amp;gt;open-xchange-guard-help-en-us&amp;lt;/code&amp;gt; (or preferred language for help files).&lt;br /&gt;
&lt;br /&gt;
The components required for the Guard server &amp;lt;code&amp;gt;open-xchange-guard&amp;lt;/code&amp;gt; and either &amp;lt;code&amp;gt;open-xchange-guard-file-storage&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;open-xchange-guard-s3-storage&amp;lt;/code&amp;gt; depending on what storage you want to use. The examples below make use of the &amp;lt;code&amp;gt;open-xchange-guard-file-storage&amp;lt;/code&amp;gt;. Adjust the commands accordingly to fit your needs. In addition &amp;lt;code&amp;gt;open-xchange&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-core&amp;lt;/code&amp;gt; are required to run OX Guard.&lt;br /&gt;
&lt;br /&gt;
=== Debian Linux 9.0 (Stretch) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 deb https://software.open-xchange.com/products/guard/stable/guard/DebianStretch /&lt;br /&gt;
 deb https://software.open-xchange.com/products/appsuite/stable/backend/DebianStretch /&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== Debian Linux 10.0 (Buster) *Version 2.10.3+ only* ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 deb https://software.open-xchange.com/products/guard/stable/guard/DebianBuster /&lt;br /&gt;
 deb https://software.open-xchange.com/products/appsuite/stable/backend/DebianBuster /&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== RedHat Enterprise Linux 6 or CentOS 6 (valid until v2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/guard/2.10.3/guard/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/7.10.3/backend/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== Redhat Enterprise Linux 7 or CentOS 7 ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/guard/stable/guard/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/stable/backend/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== SUSE Linux Enterprise Server 12 (valid until 2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
Add the package repository using zypper if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ar https://software.open-xchange.com/products/guard/2.10.3/guard/SLE_12 guard-stable-guard&lt;br /&gt;
 $ zypper ar https://software.open-xchange.com/products/appsuite/7.10.3/backend/SLE_12 ox-backend&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&lt;br /&gt;
 $ zypper in open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static&lt;br /&gt;
&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&lt;br /&gt;
 $ zypper in open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== Univention Corporate Server ===&lt;br /&gt;
&lt;br /&gt;
If you have purchased the OX App Suite for UCS, the OX Guard is part of the offering. OX Guard is available in the Univention App Center. Please check the UMC module App Center for the installation of the OX Guard at your already available environment.&lt;br /&gt;
&lt;br /&gt;
Please note: By default, OX Guard generates the link to the secure content for external recipients on the basis of the local fully qualified domain name (FQDN). If the local FQDN is not reachable from the Internet, it has to be specified manually. This can be done by setting a UCR variable, e.g. via the UMC module &amp;amp;quot;Univention Configuration Registry&amp;amp;quot;. The variable has to contain the external FQDN of the OX Guard system:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;oxguard/cfg/guard.properties/com.openexchange.guard.externalEmailURL=HOSTNAME.DOMAINNAME&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Update OX Guard ==&lt;br /&gt;
&lt;br /&gt;
This section contains information about updating a 2.10.0 version (e.g. for patch fixes). Upgrading from prior versions is discussed in different articles.&lt;br /&gt;
&lt;br /&gt;
=== Debian Linux 9.0 (Stretch) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 deb &amp;lt;https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/stable/guard/updates/DebianStretch /&amp;gt;&lt;br /&gt;
 deb &amp;lt;https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/stable/backend/DebianStretch /&amp;lt;/source&amp;gt;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Then run:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get dist-upgrade&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If you want to see, what apt-get is going to do without actually doing it, you can run:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get dist-upgrade -s&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Redhat Enterprise Linux 6 or CentOS 6 (valid until 2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard-updates]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard-updates&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/2.10.3/guard/updates/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/7.10.3/backend/updates/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
and then run:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum upgrade&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Redhat Enterprise Linux 7 or CentOS 7 ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard-updates]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard-updates&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/stable/guard/updates/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/stable/backend/updates/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
and then run:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum upgrade&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== SUSE Linux Enterprise Server 12 (valid until 2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
Add the package repository using &amp;lt;code&amp;gt;zypper&amp;lt;/code&amp;gt; if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ar https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/2.10.3/guard/updates/SLE_12 guard-stable-guard-updates&lt;br /&gt;
 $ zypper ar https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/7.10.3/backend/updates/SLE_12 ox-backend&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
and then run:&lt;br /&gt;
&lt;br /&gt;
 $ zypper dup -r guard-stable-guard-backend-updates&lt;br /&gt;
 $ zypper dup -r guard-stable-guard-ui-updates&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You might need to run:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
to update the repository metadata before running &amp;lt;code&amp;gt;zypper&amp;lt;/code&amp;gt; up.&lt;br /&gt;
&lt;br /&gt;
=== Univention Corporate Server ===&lt;br /&gt;
&lt;br /&gt;
If you have purchased the OX App Suite for UCS, the OX Guard is part of the offering. OX Guard is available in the Univention App Center. Please check the UMC module App Center for the update of the OX Guard.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Configuration ==&lt;br /&gt;
&lt;br /&gt;
The following gives an overview of the most important settings to enable Guard for users on the Open-Xchange installation. Some of those settings have to be modified in order to establish the database and REST API access from the Guard service. All settings relating to the Guard backend component are located in the configuration file &amp;lt;code&amp;gt;guard-core.properties&amp;lt;/code&amp;gt; located in &amp;lt;code&amp;gt;/opt/open-xchange/etc&amp;lt;/code&amp;gt;. The default configuration should be sufficient for a basic &amp;amp;quot;up-and-running&amp;amp;quot; setup (with the exception of defining the database username and password). Please refer to the inline documentation of the configuration file for more advanced options. Additional information can be found in the [https://oxpedia.org/wiki/index.php?title=AppSuite:OX_Guard_Configuration_2_10 Guard Configuration] article.&lt;br /&gt;
&lt;br /&gt;
=== Basic Configuration ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/guard-core.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
Guard database for storing Guard user information, main lookup tables:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.oxguardDatabaseHostname=localhost&amp;lt;/source&amp;gt;&lt;br /&gt;
Guard database that stores keys for guest users. May be the same as above. New guest shards will be created on this database as needed. If not supplied, will use the &amp;lt;code&amp;gt;oxguardDatabaseHostname&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.oxguardShardDatabase=localhost&amp;lt;/source&amp;gt;&lt;br /&gt;
Username and Password for the databases above:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.databaseUsername=openexchange&lt;br /&gt;
com.openexchange.guard.databasePassword=db_password&amp;lt;/source&amp;gt;&lt;br /&gt;
Open-Xchange REST API host:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.restApiHostname=localhost&amp;lt;/source&amp;gt;&lt;br /&gt;
Open-Xchange REST API username and password (need to be defined in the OX backend in the &amp;amp;quot;Configure services&amp;amp;quot; below):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.restApiUsername=apiusername&lt;br /&gt;
com.openexchange.guard.restApiPassword=apipassword&amp;lt;/source&amp;gt;&lt;br /&gt;
External URL for this Open-Xchange installation. This setting will be used to generate the link to the secure content for external recipients:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.externalEmailURL=URL_TO_OX&amp;lt;/source&amp;gt;&lt;br /&gt;
=== Middleware Configuration on OX Guard node ===&lt;br /&gt;
&lt;br /&gt;
If you are installing OX Guard on a node that until yet did not host an Open-Xchange middleware you have to additionally configure some parts of the following properties files:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;configdb.properties&amp;lt;/code&amp;gt;: information about the existing configuration database.&lt;br /&gt;
* &amp;lt;code&amp;gt;server.properties&amp;lt;/code&amp;gt;: information about the connections have to be set.&lt;br /&gt;
* &amp;lt;code&amp;gt;system.properties&amp;lt;/code&amp;gt;: at least &amp;lt;code&amp;gt;SERVER_NAME&amp;lt;/code&amp;gt; should be set.&lt;br /&gt;
&lt;br /&gt;
=== Sevices Configuration ===&lt;br /&gt;
&lt;br /&gt;
==== Apache ====&lt;br /&gt;
&lt;br /&gt;
Configure the &amp;lt;code&amp;gt;mod_proxy_http&amp;lt;/code&amp;gt; module by adding the Guard API.&lt;br /&gt;
&lt;br /&gt;
===== Redhat Enterprise Linux 6 or CentOS 6 =====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /etc/httpd/conf.d/proxy_http.conf&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Debian GNU/Linux 9.0 =====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /etc/apache2/conf-enabled/proxy_http.conf&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;Proxy balancer://oxguard&amp;gt;&lt;br /&gt;
        Order deny,allow&lt;br /&gt;
        Allow from all&lt;br /&gt;
 &lt;br /&gt;
        BalancerMember http://localhost:8009/ timeout=1800 smax=0 ttl=60 retry=60 loadfactor=100 route=OX1&lt;br /&gt;
        ProxySet stickysession=JSESSIONID|jsessionid scolonpathdelim=ON&lt;br /&gt;
       SetEnv proxy-initial-not-pooled&lt;br /&gt;
        SetEnv proxy-sendchunked&lt;br /&gt;
 &amp;lt;/Proxy&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
 ProxyPass /appsuite/api/oxguard balancer://oxguard/oxguard&lt;br /&gt;
 ProxyPass /pks balancer://oxguard/pgp&lt;br /&gt;
 ProxyPass /.well-known/openpgpkey/hu balancer://oxguard/hu&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: The Guard API settings must be inserted &#039;&#039;&#039;&#039;&#039;before&#039;&#039;&#039;&#039;&#039; the existing &amp;lt;code&amp;gt;ProxyPass /appsuite/api&amp;lt;/code&amp;gt; parameter.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Also Note&#039;&#039;&#039;:  If you already have a Proxy balancer for the OX backend with the same URL (say http://localhost:8080) then you don&#039;t need the second BalancerMember entry, and you can just have the ProxyPass address that balancer instead.&lt;br /&gt;
&lt;br /&gt;
After the configuration is done, restart the Apache webserver&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ apachectl restart&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Open-Xchange Middleware Configuration ===&lt;br /&gt;
&lt;br /&gt;
Edit the &amp;lt;code&amp;gt;guard-api.properties&amp;lt;/code&amp;gt; configuration file for the OX backend where the guard-backend-plugin was installed. Please remove comments in front of the following settings to the configuration file &amp;lt;code&amp;gt;guard-api.properties&amp;lt;/code&amp;gt; on the Open-Xchange backend servers:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/guard-api.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;# OX Guard general permission, required to activate Guard in the AppSuite UI.&lt;br /&gt;
com.openexchange.capability.guard=true&lt;br /&gt;
&lt;br /&gt;
# Default theme template id for all users that have no custom template id configured.&lt;br /&gt;
com.openexchange.guard.templateID=0&amp;lt;/source&amp;gt;&lt;br /&gt;
Configure the API username and password that you assigned to Guard in the &amp;lt;code&amp;gt;server.properties&amp;lt;/code&amp;gt; file:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/server.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;# Specify the user name used for HTTP basic auth by internal REST servlet&lt;br /&gt;
com.openexchange.rest.services.basic-auth.login=apiusername&lt;br /&gt;
&lt;br /&gt;
# Specify the password used for HTTP basic auth by internal REST servlet&lt;br /&gt;
com.openexchange.rest.services.basic-auth.password=apipassword&amp;lt;/source&amp;gt;&lt;br /&gt;
Finally, the OX backend needs to know where the Guard server is located. This is used to notify the Guard server of changes in users, and to send emails marked for signature. The URL for the Guard server should include the URL suffix &amp;lt;code&amp;gt;/guardadmin&amp;lt;/code&amp;gt;. In the event of a cluster setup, any Guard server can be referenced here, as it is not session specific, though ideally would have a HTTP load balancer/failover URL:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/guard-api.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;# Specifies the URI to the OX Guard end-point; e.g. http://guard.host.invalid:8081/guardadmin&lt;br /&gt;
# Default is empty&lt;br /&gt;
com.openexchange.guard.endpoint=http://guardserver:8009/guardadmin&amp;lt;/source&amp;gt;&lt;br /&gt;
Restart the OX backend&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /etc/init.d/open-xchange restart&amp;lt;/source&amp;gt;&lt;br /&gt;
==== SELinux ====&lt;br /&gt;
&lt;br /&gt;
Running SELinux prohibits your local Open-Xchange backend service to connect to localhost:8009, which is where the Guard backend service listens to. In order to allow localhost connections to 8009 execute the following:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ setsebool -P httpd_can_network_connect 1&amp;lt;/source&amp;gt;&lt;br /&gt;
=== Generating the &amp;lt;code&amp;gt;oxguardpass&amp;lt;/code&amp;gt; ===&lt;br /&gt;
&lt;br /&gt;
Once the Guard configuration (database and backend configuration) and the service configuration has been applied, the Guard administration script needs to be executed in order to create the master password file in &amp;lt;code&amp;gt;/opt/open-xchange/etc/oxguardpass&amp;lt;/code&amp;gt;. The initiation only needs to be done &#039;&#039;&#039;once&#039;&#039;&#039; for a multi server setup, for details please see the sections &#039;&#039;&#039;Optional&#039;&#039;&#039; and/or &#039;&#039;&#039;Clustering&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: If you run a cluster of OX / Guard nodes, only execute this command on &#039;&#039;&#039;ONE&#039;&#039;&#039; node. Not on all nodes! See [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCluster OX Guard Clustering] for details.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /opt/open-xchange/sbin/guard --init&amp;lt;/source&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: It is important to understand that the master password file located at &amp;lt;code&amp;gt;/opt/open-xchange/etc/oxguardpass&amp;lt;/code&amp;gt; is required to reset user passwords; without them the administrator will not be able to reset user passwords anymore in the future. The file contains the passwords used to encrypt the master database key, as well as passwords used to encrypt protected data in the users table. It must be the same on all Guard servers.&lt;br /&gt;
&lt;br /&gt;
=== Test Setup ===&lt;br /&gt;
&lt;br /&gt;
Not required, but it is a good idea to test the Guard setup before enabling for any users. The test function will verify that Guard has a good connection to the OX backend, and that it can resolve email addresses to users.&lt;br /&gt;
&lt;br /&gt;
To test, use an email address that exists on the OX backend (john@example.com for this example)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;/opt/open-xchange/sbin/guard --test john@example.com&amp;lt;/source&amp;gt;&lt;br /&gt;
Guard should return information from the OX backend regarding the user associated with &amp;amp;quot;john@example.com&amp;amp;quot;. Problems resolving information for the user should be resolved before using Guard. Check Rest API passwords and settings if errors returned.&lt;br /&gt;
&lt;br /&gt;
=== Enabling Guard for Users ===&lt;br /&gt;
&lt;br /&gt;
Guard provides two capabilities for users in the environment as well as a basic &amp;amp;quot;core&amp;amp;quot; level:&lt;br /&gt;
&lt;br /&gt;
* Guard: &amp;lt;code&amp;gt;com.openexchange.capability.guard&amp;lt;/code&amp;gt;&lt;br /&gt;
* Guard Mail: &amp;lt;code&amp;gt;com.openexchange.capability.guard-mail&amp;lt;/code&amp;gt;&lt;br /&gt;
* Guard Drive: &amp;lt;code&amp;gt;com.openexchange.capability.guard-drive&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The &amp;amp;quot;core&amp;amp;quot; Guard enabled a basic read functionality for Guard encrypted emails. We recommend enabling this for all users, as this allows all recipients to read Guard emails sent to them. Great opportunity for upsell. Recipients with only Guard enabled can then do a secure reply to the sender, but they can&#039;t start a new email or add recipients.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Guard Mail&#039;&#039;&#039; and &#039;&#039;&#039;Guard Drive&#039;&#039;&#039; are additional options for users. &amp;amp;quot;Guard Mail&amp;amp;quot; allows users the full functionality of Guard emails. &amp;amp;quot;Guard Drive&amp;amp;quot; allows for encryption and decryption of drive files.&lt;br /&gt;
&lt;br /&gt;
Each of those two Guard components is enabled for all users that have the according capability configured. Please note that users need to have the Drive permission set to use Guard Drive. So the users that have Guard Drive enabled must be a subset of those users with OX Drive permission. Since v7.6.0 we enforce this via the default configuration. Those capabilities can be activated for specific user by using the Open-Xchange provisioning scripts:&lt;br /&gt;
&lt;br /&gt;
==== Guard Mail: ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /opt/open-xchange/sbin/changeuser -c 1 -A oxadmin -P admin_password -u testuser --config/com.openexchange.capability.guard-mail=true&amp;lt;/source&amp;gt;&lt;br /&gt;
==== Guard Drive: ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /opt/open-xchange/sbin/changeuser -c 1 -A oxadmin -P admin_password -u testuser --config/com.openexchange.capability.guard-drive=true&amp;lt;/source&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: Guard Drive requires Guard Mail to be configured for the user as well. In addition, these capabilities may be configured globally by editing the &amp;lt;code&amp;gt;guard-api.properties&amp;lt;/code&amp;gt; file on the OX backend.&lt;br /&gt;
&lt;br /&gt;
=== External Guest recipients ===&lt;br /&gt;
Starting in Guard 2.10.0, when an encrypted email is sent to a user that does not have Guard, a guest account is created for them in appsuite.  The recipient uses the Guest account to read the encrypted email.  These guest users MUST have guard capabilities.  To do this, guard capability must be added to guest accounts.&lt;br /&gt;
&amp;lt;code&amp;gt;/opt/open-xchange/etc/share.properties&amp;lt;/code&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.share.guestCapabilityMode=static&lt;br /&gt;
com.openexchange.share.staticGuestCapabilities=guard&amp;lt;/source&amp;gt;&lt;br /&gt;
In a distributed system, the Guest accounts should not be considered transient.  Guard servers must be able to verify the guest account exists in the session storage services.&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.share.transientSessions=false&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Guest Storage ===&lt;br /&gt;
When an encrypted email is sent to an external Guest, a copy of the fully encrypted email is stored on the server.  This is used to create an inbox of encrypted emails for the guest.  By entering in a password, the emails can be decrypted and displayed.&lt;br /&gt;
&lt;br /&gt;
How these files are stored depend on which package, open-xchange-guard-file-storage or open-xchange-guard-s3-storage, was installed.&lt;br /&gt;
&lt;br /&gt;
The file retention policy is configured in the guard-core.properties file.&lt;br /&gt;
&lt;br /&gt;
=== Recipient key detection ===&lt;br /&gt;
&lt;br /&gt;
==== Local ====&lt;br /&gt;
&lt;br /&gt;
Guard needs to determine if an email recipients email address is an internal or external (non-ox) user.&lt;br /&gt;
&lt;br /&gt;
To detect if the recipient is an account on the same OX Guard system there is a mechanism needed to map a recipient mail address to the correct local OX context. The default implementation delivered in the product achieves that by looking up the mail domain (@example.com) within the list of context mappings. That is at least not possible in case of ISPs where different users/contexts use the same mail domain. In case your OX system does not use mail domains in context mappings it is required to deploy an OX OSGi bundle implementing the &amp;lt;code&amp;gt;com.openexchange.mailmapping.MailResolver&amp;lt;/code&amp;gt; class or by interfacing Guard with your mail resolver system. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardMailResolver OX Guard Mail Resolver] for details.&lt;br /&gt;
&lt;br /&gt;
==== External ====&lt;br /&gt;
&lt;br /&gt;
Starting with Guard 2.0, Guard will use public PGP Key servers if configured to find PGP Public keys. In addition, Guard will also look up SRV records for PGP Key servers for a recipients domain. This follows the standards [http://tools.ietf.org/html/draft-shaw-openpgp-hkp-00#page-9 OpenPGP Draft].&lt;br /&gt;
&lt;br /&gt;
External PGP servers to use can be configured in the guard.properties file on the Guard servers.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.publicPGPDirectory = hkp://keys.gnupg.net:11371, hkp://pgp.mit.edu:11371&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If you would like this Guard installation discoverable as HKP service by other Guard servers, then create an SRV record for each domain (&amp;amp;quot;example.com&amp;amp;quot; in this illustration):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;_hkp._tcp.example.com. 28800 IN    SRV     10 1 80 appsuite.example.com.&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039; PGP Public key servers by default append the path /pks when the record is obtained from an SRV record. The proxy (also included in Apache config above) routes anything under /pks to the OX Guard PGP server.&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;ProxyPass /pks balancer://oxguard/pgp&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Guard keys are also discoverable using the webkey service as specified here: https://tools.ietf.org/html/draft-koch-openpgp-webkey-service-02&lt;br /&gt;
This is enabled if you include the &lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;ProxyPass /.well-known/openpgpkey/hu balancer://oxguard/hu&amp;lt;/source&amp;gt;&lt;br /&gt;
in the proxy_http.conf as above.&lt;br /&gt;
Please note that the well-known request is targeted at the domain part of the mail address. Therefore clients will request for a mail address name@example.com the URI https://example.com/.well-known/openpgpkey/hu/...&lt;br /&gt;
&lt;br /&gt;
That means that there is the very likely need that some sort of proxying or rewriting from the webserver providing the domain needs to happen. For example for proxying using Apache 2.4 it would roughly look like this:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
SSLProxyEngine on&lt;br /&gt;
&amp;lt;LocationMatch /.well-known/openpgpkey/&amp;gt;&lt;br /&gt;
    ProxyPass https://ox.example.com/.well-known/openpgpkey/&lt;br /&gt;
&amp;lt;/LocationMatch&amp;gt;&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clustering ===&lt;br /&gt;
&lt;br /&gt;
You can run multiple OX Guard servers in your environment to ensure high availability or enhance scalability. OX Guard integrates seamlessly into the existing Open-Xchange infrastructure by using the existing interface standards and is therefor transparent to the environment. A couple of things have to be prepared in order to loosely couple OX Guard servers with Open-Xchange servers in a cluster.&lt;br /&gt;
&lt;br /&gt;
==== MySQL ====&lt;br /&gt;
&lt;br /&gt;
The MySQL servers need to be configured in order to allow access to the configdb of Open-Xchange. To do so you need to set the following configuration in the MySQL &amp;lt;code&amp;gt;my.cnf&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;bind = 0.0.0.0&amp;lt;/source&amp;gt;&lt;br /&gt;
This allows the Guard backend to bind to the MySQL host which is configured in the &amp;lt;code&amp;gt;guard-core.properties&amp;lt;/code&amp;gt; file with &amp;lt;code&amp;gt;com.openexchange.guard.configdbHostname&amp;lt;/code&amp;gt;. After the bind for the MySQL instance is configured and the OX Guard backend would be able to connect to the configured host, you have to grant access for the OX Guard service on the MySQL instance to manage the databases. Do so by connecting to the MySQL server via the MySQL client. Authenticate if necessary and execute the following, please note that you have to modify the hostname / IP address of the client who should be able to connect to this database, it should include all possible OX Guard servers:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;sql&amp;quot;&amp;gt;GRANT ALL PRIVILEGES ON *.* TO &#039;openexchange&#039;@&#039;oxguard.example.com&#039; IDENTIFIED BY ‘secret’;&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Apache ====&lt;br /&gt;
&lt;br /&gt;
OX Guard uses the Open-Xchange REST API to store and fetch data from the Open-Xchange databases. The REST API is a servlet running in the Grizzly container. By default it is not exposed as a servlet through Apache and is only accessibly via port 8009. In order to use Apache&#039;s load balancing via &amp;lt;code&amp;gt;mod_proxy&amp;lt;/code&amp;gt; we need to add a servlet called &amp;amp;quot;preliminary&amp;amp;quot; to &amp;lt;code&amp;gt;proxy_http.conf&amp;lt;/code&amp;gt;, example based on a clustered &amp;lt;code&amp;gt;mod_proxy&amp;lt;/code&amp;gt;configuration:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;Location /preliminary&amp;gt;&lt;br /&gt;
      Order Deny,Allow&lt;br /&gt;
      Deny from all&lt;br /&gt;
      # Only allow access from Guard servers within the network. Do not expose this&lt;br /&gt;
      # location outside of your network. In case you use a load balancing service in front&lt;br /&gt;
      # of your Apache infrastructure you should make sure that access to /preliminary will&lt;br /&gt;
      # be blocked from the Internet / outside clients. Examples:&lt;br /&gt;
      # Allow from 192.168.0.1&lt;br /&gt;
      # Allow from 192.168.1.1 192.168.1.2&lt;br /&gt;
      # Allow from 192.168.0.&lt;br /&gt;
 &amp;lt;/Location&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
 ProxyPass /preliminary balancer://oxcluster/preliminary&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Make sure that the balancer is properly configured in the &amp;lt;code&amp;gt;mod_proxy&amp;lt;/code&amp;gt; configuration. Examples on how to do so can be found in our clustering configuration for Open-Xchange AppSuite. Like explained in the example above, please make sure that this location is only available in your internal network, there is no need to expose &amp;lt;code&amp;gt;/preliminary&amp;lt;/code&amp;gt; to the public, it is only used by Guard servers to connect to the OX backend. If you have a load balancer in front of the Apache cluster you should consider blocking access to &amp;lt;code&amp;gt;/preliminary&amp;lt;/code&amp;gt; from WAN to restrict access to the servlet to internal network services only.&lt;br /&gt;
&lt;br /&gt;
Now add the OX Guard &amp;lt;code&amp;gt;BalancerMembers&amp;lt;/code&amp;gt; to the oxguard balancer configuration (also in &amp;lt;code&amp;gt;proxy_http.conf&amp;lt;/code&amp;gt;) to address all your OX Guard nodes in the cluster in this balancer configuration. The configuration has to be applied to all Apache nodes within the cluster.&lt;br /&gt;
&lt;br /&gt;
If the Apache server is a dedicated server &amp;lt;code&amp;gt;/&amp;lt;/code&amp;gt; instance you also have to install the OX Guard UI-Static package on all Apache nodes in the cluster in order to provide static files like images or CSS to the OX Guard client. Example for Debian (the OX Guard repository has to be configured in the package management prior):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ apt-get install open-xchange-guard-ui-static&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Open-Xchange ====&lt;br /&gt;
&lt;br /&gt;
Disable the Open-Xchange IPCheck for session verification. This is required because OX Guard will use the users session cookie to connect to the Open-Xchange REST API, but as a different IP address than the OX Guard server has been used during authentication the request would fail if you don&#039;t disable the IPCheck:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/server.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
and set:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.IPCheck=false&amp;lt;/source&amp;gt;&lt;br /&gt;
The OX Guard UI package has to be installed on all Open-Xchange backend nodes as well, example for Debian (the OX Guard repository has to be configured in the package management prior):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ apt-get install open-xchange-guard-ui&amp;lt;/source&amp;gt;&lt;br /&gt;
Restart the Open-Xchange service afterwards.&lt;br /&gt;
&lt;br /&gt;
==== OX Guard ====&lt;br /&gt;
&lt;br /&gt;
For details in clustering Guard servers, please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCluster OX Guard Clustering]. It is &#039;&#039;&#039;critical&#039;&#039;&#039; that all Guard servers have the same &amp;lt;code&amp;gt;oxguardpass&amp;lt;/code&amp;gt; file. Please see the clustering link for details. Do not run &amp;lt;code&amp;gt;/opt/open-xchange/sbin/guard --init&amp;lt;/code&amp;gt; on more than one server.&lt;br /&gt;
&lt;br /&gt;
After all the services like MySQL, Apache and Open-Xchange have been configured you need to update the OX Guard backend configuration to point to the correct API endpoints. Set the REST API endpoint to an Apache server by setting the following value in &amp;lt;code&amp;gt;/opt/open-xchange/etc/guard-core.properties&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.restApiHostname=apache.example.com&amp;lt;/source&amp;gt;&lt;br /&gt;
Per default Guard will try to connect to port 8009 to this host, but as we configured the REST API to be proxies thorugh the servlet &amp;lt;code&amp;gt;/preliminary&amp;lt;/code&amp;gt; on every Apache we now also need to change the target port for the REST API. You can do so by adding the following line into &amp;lt;code&amp;gt;/opt/open-xchange/etc/guard-core.properties&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.oxBackendPort=80&amp;lt;/source&amp;gt;&lt;br /&gt;
Please also change all settings in regards to MySQL like &amp;lt;code&amp;gt;com.openexchange.guard.configdbHostname&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;com.openexchange.guard.oxguardDatabaseHostname&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;com.openexchange.guard.databaseUsername&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;om.openexchange.guard.databasePassword&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Afterwards restart the OX Guard service and check the log file if the OX Guard backend is able to connect to the configured REST API.&lt;br /&gt;
&lt;br /&gt;
=== Multi Node ===&lt;br /&gt;
&lt;br /&gt;
If you have multiple OX and Guard installations, please see the following documentation [https://oxpedia.org/wiki/index.php?title=AppSuite:OX_Guard_Modular OX Guard Modular Setup].&lt;br /&gt;
&lt;br /&gt;
=== Mail Filter Integration (2.10.4+) ===&lt;br /&gt;
&lt;br /&gt;
To add additional mail filter tests (verify PGP signature, or encrypt incoming), please see&lt;br /&gt;
[[AppSuite:OX_Guard_MailFilter | MailFilter Integration]]&lt;br /&gt;
&lt;br /&gt;
== Support API ==&lt;br /&gt;
&lt;br /&gt;
The OX Guard Support API enables administrative access to various functions for maintaining OX Guard from a client in a role as a support employee. A client has to do a BASIC AUTH authentication in order to access the API. Username and password can be configured in the guard-core.properties file using the following settings:&lt;br /&gt;
&lt;br /&gt;
 # Specify the username and password for accessing the Support API of Guard&lt;br /&gt;
 com.openexchange.guard.supportApiUsername=&lt;br /&gt;
 com.openexchange.guard.supportApiPassword=&lt;br /&gt;
&lt;br /&gt;
In contrast to the rest of the OX Guard requests, the OX Guard support API requests are accessible using: /guardsupport. This distinction allows more flexible configuration since the support API should not always be accessible from everywhere. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Warning&#039;&#039;&#039;: Exposing the support API to the internet could be huge security risk. Only add to Apache if you know what you are doing.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Reset password ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=reset_password&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Performs a password reset and sends a new random generated password to a specified email address by the user or a default address if the user did not specify an email address. (&#039;&#039;Since Guard 2.0&#039;&#039;)&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;email&amp;lt;/code&amp;gt; – The email address of the user to reset the password for&lt;br /&gt;
* &amp;lt;code&amp;gt;default&amp;lt;/code&amp;gt; (optional) – The email address to send the new password to, if the user did not specify a secondary email address&lt;br /&gt;
&lt;br /&gt;
Response:&lt;br /&gt;
PRIMARY if the reset was sent to the primary email address.  SECONDARY if the reset email was sent to the secondary email address that the user specified&lt;br /&gt;
&lt;br /&gt;
=== Expose key ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=expose_key&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Marks a deleted user key temporary as “exposed” and creates a unique URL for downloading the exposed key. Automatic resetting of exposed keys to &amp;amp;quot;not exposed&amp;amp;quot; is scheduled once a day and resets all exposed keys which have been exposed before X hours, where X can be configured using com.openexchange.guard.exposedKeyDurationInHours in the guard.properties files. (&#039;&#039;Since Guard 2.0&#039;&#039;)&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;email&amp;lt;/code&amp;gt; – The email address of the user to expose the deleted keys for&lt;br /&gt;
* &amp;lt;code&amp;gt;cid&amp;lt;/code&amp;gt; – The context id&lt;br /&gt;
&lt;br /&gt;
Response: A URL pointing to the downloadable exposed keys.&lt;br /&gt;
&lt;br /&gt;
=== Delete user ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=delete_user&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deletes all keys related to a certain user. The keys are backed up and can be exposed using the “expose_key” call. (&#039;&#039;Since Guard 2.0&#039;&#039;)&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;user_id&amp;lt;/code&amp;gt; – The user&#039;s id&lt;br /&gt;
* &amp;lt;code&amp;gt;cid&amp;lt;/code&amp;gt; - The context id&lt;br /&gt;
&lt;br /&gt;
=== Upgrade User (Release 2.10 and later) ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=upgrade_guest&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Upgrades a Guest account.  This action copies all of the keys from the Guest account to a full OX account, assuming that user has Guard capabilities.&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;email&amp;lt;/code&amp;gt; - The email address of the Guest user&lt;br /&gt;
* &amp;lt;code&amp;gt;user_id&amp;lt;/code&amp;gt; – The user&#039;s new id&lt;br /&gt;
* &amp;lt;code&amp;gt;cid&amp;lt;/code&amp;gt; - The user&#039;s new context id&lt;br /&gt;
&lt;br /&gt;
== Customisation ==&lt;br /&gt;
&lt;br /&gt;
Guard&#039;s templates are customisable at the user and context level. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCustomization Customisation] for details.&lt;br /&gt;
&lt;br /&gt;
== Entropy ==&lt;br /&gt;
&lt;br /&gt;
Guard requires entropy (randomness) to generate the private/public keys that are used. Depending on the server and it&#039;s environment, this may become a problem. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardEntropy Entropy] for a possible solution.&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:OX_Guard&amp;diff=25622</id>
		<title>AppSuite:OX Guard</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:OX_Guard&amp;diff=25622"/>
		<updated>2020-10-10T07:00:25Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: /* External Guest recipients: */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= OX Guard (Version 2.10) =&lt;br /&gt;
&lt;br /&gt;
For previous versions of OX Guard, please click here&lt;br /&gt;
* [[AppSuite:OX_Guard_2-0 | Installation and information of OX Guard 2.0 - 2.2]]&lt;br /&gt;
* [[Appsuite:OX_Guard_2_8 | Installation and information of OX Guard 2.4 - 2.8]]&lt;br /&gt;
&lt;br /&gt;
If upgrading from 2.6 or 2.8, please see&lt;br /&gt;
* [[Appsuite:OX_Guard_Upgrade_2_10|Upgrading to 2.10]]&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
&lt;br /&gt;
OX Guard is a fully integrated security add-on to OX App Suite that provides end users with a flexible email and file encryption solution. OX Guard is a highly scalable, multi server, feature rich solution that is so simple-to-use that end users will actually use it. With a single click a user can take control of their security and send secure emails and share encrypted files. This can be done from any device to both OX App Suite and non-OX App Suite users.&lt;br /&gt;
&lt;br /&gt;
OX Guard uses standard PGP encryption for the encryption of email and files. PGP has been around for a long time, yet has not really caught on with the masses. This is generally blamed on the confusion and complications of managing the keys, understanding trust, PGP format types, and lack of trusted central key repositories. Guard simplifies all of this, making PGP encryption as easy as a one click process, with no keys to keep track of, yet the options of advanced PGP management for those that know how.&lt;br /&gt;
&lt;br /&gt;
This article will guide you through the installation of Guard and describes the basic configuration and software requirements. As it is intended as a quick walk-through it assumes an existing installation of the operating system including a single server App Suite setup as well as average system administration skills. This guide will also show you how to setup a basic installation with none of the typically used distributed environment settings. The objective of this guide is:&lt;br /&gt;
&lt;br /&gt;
* To setup a single server installation&lt;br /&gt;
* To setup a single Guard instance on an existing Open-Xchange installation, no cluster&lt;br /&gt;
* To use the database service on the existing Open-Xchange installation for Guard, no replication&lt;br /&gt;
* To provide a basic configuration setup, no mail server configuration&lt;br /&gt;
&lt;br /&gt;
=== Key Features ===&lt;br /&gt;
&lt;br /&gt;
* Simple security at the touch of a button&lt;br /&gt;
* Provides user based security - Separate from provider&lt;br /&gt;
* Supplementary security to Provider based security - Layered&lt;br /&gt;
* Powerful features yet simple to use and understand&lt;br /&gt;
* Security - Inside and outside of the OX environment&lt;br /&gt;
* Email and Drive integration&lt;br /&gt;
* Uses proven PGP security&lt;br /&gt;
&lt;br /&gt;
=== Availability ===&lt;br /&gt;
&lt;br /&gt;
If an OX App Suite customer would like to evaluate OX Guard integration, the first step is to contact OX Sales. OX Sales will then work on the request and send prices and license/API (for the hosted infrastructure) key details to the customer.&lt;br /&gt;
&lt;br /&gt;
=== Requirements ===&lt;br /&gt;
&lt;br /&gt;
Please review [https://oxpedia.org/wiki/index.php?title=AppSuite:OX_System_Requirements#OX_Guard OX Guard Requirements] for a full list of requirements.&lt;br /&gt;
&lt;br /&gt;
Since OX Guard is a Microservice it can either be added to an existing Open-Xchange installation or it can be deployed on a dedicated environment. The version of Guard installed is dependent on the Appsuite version installed.  Please refer to the version matrix below.&lt;br /&gt;
&lt;br /&gt;
==== Prerequisites ====&lt;br /&gt;
&lt;br /&gt;
* Open-Xchange REST API&lt;br /&gt;
* Grizzly HTTP connector (open-xchange-grizzly)&lt;br /&gt;
* A supported Java Virtual Machine (Java 8)&lt;br /&gt;
* An Open-Xchange App Suite installation (see version Matrix)&lt;br /&gt;
* Please Note: To get access to the latest minor features and bug fixes, you need to have a valid license. The article [https://oxpedia.org/wiki/index.php?title=AppSuite:UpdatingOXPackages Updating OX-Packages] explains how that can be done.&lt;br /&gt;
&lt;br /&gt;
==== Version Matrix ====&lt;br /&gt;
{|&lt;br /&gt;
! style=&amp;quot;text-align:left;&amp;quot;| Core Version&lt;br /&gt;
! Guard Version&lt;br /&gt;
|-&lt;br /&gt;
|7.8.1&lt;br /&gt;
|2.4.0 or 2.4.2&lt;br /&gt;
|-&lt;br /&gt;
|7.8.2&lt;br /&gt;
|2.4.2&lt;br /&gt;
|-&lt;br /&gt;
|7.8.3&lt;br /&gt;
|2.6.0&lt;br /&gt;
|-&lt;br /&gt;
|7.8.4&lt;br /&gt;
|2.8.0&lt;br /&gt;
|-&lt;br /&gt;
|7.10.0&lt;br /&gt;
|2.10.0&lt;br /&gt;
|-&lt;br /&gt;
|7.10.1&lt;br /&gt;
|2.10.1&lt;br /&gt;
|-&lt;br /&gt;
|7.10.2&lt;br /&gt;
|2.10.2&lt;br /&gt;
|-&lt;br /&gt;
|7.10.3&lt;br /&gt;
|2.10.3&lt;br /&gt;
|-&lt;br /&gt;
|7.10.4&lt;br /&gt;
|2.10.4&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Important Notes ===&lt;br /&gt;
&lt;br /&gt;
==== Customisation ====&lt;br /&gt;
&lt;br /&gt;
OX Guard version supports branding / theming using the configuration cascade, defining a templateID for a user or context. Check the [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCustomization OX Guard Customisation] article for more details.&lt;br /&gt;
&lt;br /&gt;
==== Mail Resolver ====&lt;br /&gt;
&lt;br /&gt;
READ THIS VERY CAREFULLY; BEFORE PROCEEDING WITH GUARD INSTALLATION!&lt;br /&gt;
&lt;br /&gt;
The Guard installation must be able to determine if an email recipient is a local OX user or if it should be a guest account. The default MailResolver uses the context domain name to do this. On many installations, domains may extend across multiple context and multiple database shards. In these cases, the default MailResolver won&#039;t work. In addition, if a custom authentication package is used, the Mail Resolver will likely not work.&lt;br /&gt;
&lt;br /&gt;
Once Guard is installed, please be sure to test the mail resolver using:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;/opt/open-xchange/sbin/guard test email@domain&amp;lt;/source&amp;gt;&lt;br /&gt;
to see if the mail Resolver works.&lt;br /&gt;
&lt;br /&gt;
If the test does not work, you will likely need a custom Mail Resolver. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardMailResolver Mail Resolver] page&lt;br /&gt;
&lt;br /&gt;
This resolver software &#039;&#039;depends heavily on your local deployment&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Download and Installation ==&lt;br /&gt;
&lt;br /&gt;
=== General ===&lt;br /&gt;
&lt;br /&gt;
The installation of the &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; package which is required for Guard and the main &amp;lt;code&amp;gt;open-xchange-guard&amp;lt;/code&amp;gt; package in version 2.4.0 or higher will eventually execute database update tasks if installed and activated. Please take this into account.&lt;br /&gt;
&lt;br /&gt;
There are several components to the Guard service. They can be all installed on the same server as the OX middleware or on a separate server.&lt;br /&gt;
&lt;br /&gt;
The components required for the OX middleware are: &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
The components required for the OX frontend are: &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; and optionally &amp;lt;code&amp;gt;open-xchange-guard-help-en-us&amp;lt;/code&amp;gt; (or preferred language for help files).&lt;br /&gt;
&lt;br /&gt;
The components required for the Guard server &amp;lt;code&amp;gt;open-xchange-guard&amp;lt;/code&amp;gt; and either &amp;lt;code&amp;gt;open-xchange-guard-file-storage&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;open-xchange-guard-s3-storage&amp;lt;/code&amp;gt; depending on what storage you want to use. The examples below make use of the &amp;lt;code&amp;gt;open-xchange-guard-file-storage&amp;lt;/code&amp;gt;. Adjust the commands accordingly to fit your needs. In addition &amp;lt;code&amp;gt;open-xchange&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-core&amp;lt;/code&amp;gt; are required to run OX Guard.&lt;br /&gt;
&lt;br /&gt;
=== Debian Linux 9.0 (Stretch) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 deb https://software.open-xchange.com/products/guard/stable/guard/DebianStretch /&lt;br /&gt;
 deb https://software.open-xchange.com/products/appsuite/stable/backend/DebianStretch /&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== Debian Linux 10.0 (Buster) *Version 2.10.3+ only* ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 deb https://software.open-xchange.com/products/guard/stable/guard/DebianBuster /&lt;br /&gt;
 deb https://software.open-xchange.com/products/appsuite/stable/backend/DebianBuster /&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== RedHat Enterprise Linux 6 or CentOS 6 (valid until v2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/guard/2.10.3/guard/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/7.10.3/backend/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== Redhat Enterprise Linux 7 or CentOS 7 ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/guard/stable/guard/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/stable/backend/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== SUSE Linux Enterprise Server 12 (valid until 2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
Add the package repository using zypper if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ar https://software.open-xchange.com/products/guard/2.10.3/guard/SLE_12 guard-stable-guard&lt;br /&gt;
 $ zypper ar https://software.open-xchange.com/products/appsuite/7.10.3/backend/SLE_12 ox-backend&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&lt;br /&gt;
 $ zypper in open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static&lt;br /&gt;
&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&lt;br /&gt;
 $ zypper in open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== Univention Corporate Server ===&lt;br /&gt;
&lt;br /&gt;
If you have purchased the OX App Suite for UCS, the OX Guard is part of the offering. OX Guard is available in the Univention App Center. Please check the UMC module App Center for the installation of the OX Guard at your already available environment.&lt;br /&gt;
&lt;br /&gt;
Please note: By default, OX Guard generates the link to the secure content for external recipients on the basis of the local fully qualified domain name (FQDN). If the local FQDN is not reachable from the Internet, it has to be specified manually. This can be done by setting a UCR variable, e.g. via the UMC module &amp;amp;quot;Univention Configuration Registry&amp;amp;quot;. The variable has to contain the external FQDN of the OX Guard system:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;oxguard/cfg/guard.properties/com.openexchange.guard.externalEmailURL=HOSTNAME.DOMAINNAME&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Update OX Guard ==&lt;br /&gt;
&lt;br /&gt;
This section contains information about updating a 2.10.0 version (e.g. for patch fixes). Upgrading from prior versions is discussed in different articles.&lt;br /&gt;
&lt;br /&gt;
=== Debian Linux 9.0 (Stretch) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 deb &amp;lt;https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/stable/guard/updates/DebianStretch /&amp;gt;&lt;br /&gt;
 deb &amp;lt;https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/stable/backend/DebianStretch /&amp;lt;/source&amp;gt;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Then run:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get dist-upgrade&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If you want to see, what apt-get is going to do without actually doing it, you can run:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get dist-upgrade -s&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Redhat Enterprise Linux 6 or CentOS 6 (valid until 2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard-updates]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard-updates&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/2.10.3/guard/updates/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/7.10.3/backend/updates/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
and then run:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum upgrade&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Redhat Enterprise Linux 7 or CentOS 7 ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard-updates]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard-updates&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/stable/guard/updates/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/stable/backend/updates/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
and then run:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum upgrade&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== SUSE Linux Enterprise Server 12 (valid until 2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
Add the package repository using &amp;lt;code&amp;gt;zypper&amp;lt;/code&amp;gt; if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ar https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/2.10.3/guard/updates/SLE_12 guard-stable-guard-updates&lt;br /&gt;
 $ zypper ar https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/7.10.3/backend/updates/SLE_12 ox-backend&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
and then run:&lt;br /&gt;
&lt;br /&gt;
 $ zypper dup -r guard-stable-guard-backend-updates&lt;br /&gt;
 $ zypper dup -r guard-stable-guard-ui-updates&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You might need to run:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
to update the repository metadata before running &amp;lt;code&amp;gt;zypper&amp;lt;/code&amp;gt; up.&lt;br /&gt;
&lt;br /&gt;
=== Univention Corporate Server ===&lt;br /&gt;
&lt;br /&gt;
If you have purchased the OX App Suite for UCS, the OX Guard is part of the offering. OX Guard is available in the Univention App Center. Please check the UMC module App Center for the update of the OX Guard.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Configuration ==&lt;br /&gt;
&lt;br /&gt;
The following gives an overview of the most important settings to enable Guard for users on the Open-Xchange installation. Some of those settings have to be modified in order to establish the database and REST API access from the Guard service. All settings relating to the Guard backend component are located in the configuration file &amp;lt;code&amp;gt;guard-core.properties&amp;lt;/code&amp;gt; located in &amp;lt;code&amp;gt;/opt/open-xchange/etc&amp;lt;/code&amp;gt;. The default configuration should be sufficient for a basic &amp;amp;quot;up-and-running&amp;amp;quot; setup (with the exception of defining the database username and password). Please refer to the inline documentation of the configuration file for more advanced options. Additional information can be found in the [https://oxpedia.org/wiki/index.php?title=AppSuite:OX_Guard_Configuration_2_10 Guard Configuration] article.&lt;br /&gt;
&lt;br /&gt;
=== Basic Configuration ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/guard-core.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
Guard database for storing Guard user information, main lookup tables:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.oxguardDatabaseHostname=localhost&amp;lt;/source&amp;gt;&lt;br /&gt;
Guard database that stores keys for guest users. May be the same as above. New guest shards will be created on this database as needed. If not supplied, will use the &amp;lt;code&amp;gt;oxguardDatabaseHostname&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.oxguardShardDatabase=localhost&amp;lt;/source&amp;gt;&lt;br /&gt;
Username and Password for the databases above:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.databaseUsername=openexchange&lt;br /&gt;
com.openexchange.guard.databasePassword=db_password&amp;lt;/source&amp;gt;&lt;br /&gt;
Open-Xchange REST API host:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.restApiHostname=localhost&amp;lt;/source&amp;gt;&lt;br /&gt;
Open-Xchange REST API username and password (need to be defined in the OX backend in the &amp;amp;quot;Configure services&amp;amp;quot; below):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.restApiUsername=apiusername&lt;br /&gt;
com.openexchange.guard.restApiPassword=apipassword&amp;lt;/source&amp;gt;&lt;br /&gt;
External URL for this Open-Xchange installation. This setting will be used to generate the link to the secure content for external recipients:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.externalEmailURL=URL_TO_OX&amp;lt;/source&amp;gt;&lt;br /&gt;
=== Middleware Configuration on OX Guard node ===&lt;br /&gt;
&lt;br /&gt;
If you are installing OX Guard on a node that until yet did not host an Open-Xchange middleware you have to additionally configure some parts of the following properties files:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;configdb.properties&amp;lt;/code&amp;gt;: information about the existing configuration database.&lt;br /&gt;
* &amp;lt;code&amp;gt;server.properties&amp;lt;/code&amp;gt;: information about the connections have to be set.&lt;br /&gt;
* &amp;lt;code&amp;gt;system.properties&amp;lt;/code&amp;gt;: at least &amp;lt;code&amp;gt;SERVER_NAME&amp;lt;/code&amp;gt; should be set.&lt;br /&gt;
&lt;br /&gt;
=== Sevices Configuration ===&lt;br /&gt;
&lt;br /&gt;
==== Apache ====&lt;br /&gt;
&lt;br /&gt;
Configure the &amp;lt;code&amp;gt;mod_proxy_http&amp;lt;/code&amp;gt; module by adding the Guard API.&lt;br /&gt;
&lt;br /&gt;
===== Redhat Enterprise Linux 6 or CentOS 6 =====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /etc/httpd/conf.d/proxy_http.conf&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Debian GNU/Linux 9.0 =====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /etc/apache2/conf-enabled/proxy_http.conf&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;Proxy balancer://oxguard&amp;gt;&lt;br /&gt;
        Order deny,allow&lt;br /&gt;
        Allow from all&lt;br /&gt;
 &lt;br /&gt;
        BalancerMember http://localhost:8009/ timeout=1800 smax=0 ttl=60 retry=60 loadfactor=100 route=OX1&lt;br /&gt;
        ProxySet stickysession=JSESSIONID|jsessionid scolonpathdelim=ON&lt;br /&gt;
       SetEnv proxy-initial-not-pooled&lt;br /&gt;
        SetEnv proxy-sendchunked&lt;br /&gt;
 &amp;lt;/Proxy&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
 ProxyPass /appsuite/api/oxguard balancer://oxguard/oxguard&lt;br /&gt;
 ProxyPass /pks balancer://oxguard/pgp&lt;br /&gt;
 ProxyPass /.well-known/openpgpkey/hu balancer://oxguard/hu&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: The Guard API settings must be inserted &#039;&#039;&#039;&#039;&#039;before&#039;&#039;&#039;&#039;&#039; the existing &amp;lt;code&amp;gt;ProxyPass /appsuite/api&amp;lt;/code&amp;gt; parameter.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Also Note&#039;&#039;&#039;:  If you already have a Proxy balancer for the OX backend with the same URL (say http://localhost:8080) then you don&#039;t need the second BalancerMember entry, and you can just have the ProxyPass address that balancer instead.&lt;br /&gt;
&lt;br /&gt;
After the configuration is done, restart the Apache webserver&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ apachectl restart&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Open-Xchange Middleware Configuration ===&lt;br /&gt;
&lt;br /&gt;
Edit the &amp;lt;code&amp;gt;guard-api.properties&amp;lt;/code&amp;gt; configuration file for the OX backend where the guard-backend-plugin was installed. Please remove comments in front of the following settings to the configuration file &amp;lt;code&amp;gt;guard-api.properties&amp;lt;/code&amp;gt; on the Open-Xchange backend servers:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/guard-api.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;# OX Guard general permission, required to activate Guard in the AppSuite UI.&lt;br /&gt;
com.openexchange.capability.guard=true&lt;br /&gt;
&lt;br /&gt;
# Default theme template id for all users that have no custom template id configured.&lt;br /&gt;
com.openexchange.guard.templateID=0&amp;lt;/source&amp;gt;&lt;br /&gt;
Configure the API username and password that you assigned to Guard in the &amp;lt;code&amp;gt;server.properties&amp;lt;/code&amp;gt; file:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/server.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;# Specify the user name used for HTTP basic auth by internal REST servlet&lt;br /&gt;
com.openexchange.rest.services.basic-auth.login=apiusername&lt;br /&gt;
&lt;br /&gt;
# Specify the password used for HTTP basic auth by internal REST servlet&lt;br /&gt;
com.openexchange.rest.services.basic-auth.password=apipassword&amp;lt;/source&amp;gt;&lt;br /&gt;
Finally, the OX backend needs to know where the Guard server is located. This is used to notify the Guard server of changes in users, and to send emails marked for signature. The URL for the Guard server should include the URL suffix &amp;lt;code&amp;gt;/guardadmin&amp;lt;/code&amp;gt;. In the event of a cluster setup, any Guard server can be referenced here, as it is not session specific, though ideally would have a HTTP load balancer/failover URL:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/guard-api.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;# Specifies the URI to the OX Guard end-point; e.g. http://guard.host.invalid:8081/guardadmin&lt;br /&gt;
# Default is empty&lt;br /&gt;
com.openexchange.guard.endpoint=http://guardserver:8009/guardadmin&amp;lt;/source&amp;gt;&lt;br /&gt;
Restart the OX backend&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /etc/init.d/open-xchange restart&amp;lt;/source&amp;gt;&lt;br /&gt;
==== SELinux ====&lt;br /&gt;
&lt;br /&gt;
Running SELinux prohibits your local Open-Xchange backend service to connect to localhost:8009, which is where the Guard backend service listens to. In order to allow localhost connections to 8009 execute the following:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ setsebool -P httpd_can_network_connect 1&amp;lt;/source&amp;gt;&lt;br /&gt;
=== Generating the &amp;lt;code&amp;gt;oxguardpass&amp;lt;/code&amp;gt; ===&lt;br /&gt;
&lt;br /&gt;
Once the Guard configuration (database and backend configuration) and the service configuration has been applied, the Guard administration script needs to be executed in order to create the master password file in &amp;lt;code&amp;gt;/opt/open-xchange/etc/oxguardpass&amp;lt;/code&amp;gt;. The initiation only needs to be done &#039;&#039;&#039;once&#039;&#039;&#039; for a multi server setup, for details please see the sections &#039;&#039;&#039;Optional&#039;&#039;&#039; and/or &#039;&#039;&#039;Clustering&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: If you run a cluster of OX / Guard nodes, only execute this command on &#039;&#039;&#039;ONE&#039;&#039;&#039; node. Not on all nodes! See [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCluster OX Guard Clustering] for details.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /opt/open-xchange/sbin/guard --init&amp;lt;/source&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: It is important to understand that the master password file located at &amp;lt;code&amp;gt;/opt/open-xchange/etc/oxguardpass&amp;lt;/code&amp;gt; is required to reset user passwords; without them the administrator will not be able to reset user passwords anymore in the future. The file contains the passwords used to encrypt the master database key, as well as passwords used to encrypt protected data in the users table. It must be the same on all Guard servers.&lt;br /&gt;
&lt;br /&gt;
=== Test Setup ===&lt;br /&gt;
&lt;br /&gt;
Not required, but it is a good idea to test the Guard setup before enabling for any users. The test function will verify that Guard has a good connection to the OX backend, and that it can resolve email addresses to users.&lt;br /&gt;
&lt;br /&gt;
To test, use an email address that exists on the OX backend (john@example.com for this example)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;/opt/open-xchange/sbin/guard --test john@example.com&amp;lt;/source&amp;gt;&lt;br /&gt;
Guard should return information from the OX backend regarding the user associated with &amp;amp;quot;john@example.com&amp;amp;quot;. Problems resolving information for the user should be resolved before using Guard. Check Rest API passwords and settings if errors returned.&lt;br /&gt;
&lt;br /&gt;
=== Enabling Guard for Users ===&lt;br /&gt;
&lt;br /&gt;
Guard provides two capabilities for users in the environment as well as a basic &amp;amp;quot;core&amp;amp;quot; level:&lt;br /&gt;
&lt;br /&gt;
* Guard: &amp;lt;code&amp;gt;com.openexchange.capability.guard&amp;lt;/code&amp;gt;&lt;br /&gt;
* Guard Mail: &amp;lt;code&amp;gt;com.openexchange.capability.guard-mail&amp;lt;/code&amp;gt;&lt;br /&gt;
* Guard Drive: &amp;lt;code&amp;gt;com.openexchange.capability.guard-drive&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The &amp;amp;quot;core&amp;amp;quot; Guard enabled a basic read functionality for Guard encrypted emails. We recommend enabling this for all users, as this allows all recipients to read Guard emails sent to them. Great opportunity for upsell. Recipients with only Guard enabled can then do a secure reply to the sender, but they can&#039;t start a new email or add recipients.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Guard Mail&#039;&#039;&#039; and &#039;&#039;&#039;Guard Drive&#039;&#039;&#039; are additional options for users. &amp;amp;quot;Guard Mail&amp;amp;quot; allows users the full functionality of Guard emails. &amp;amp;quot;Guard Drive&amp;amp;quot; allows for encryption and decryption of drive files.&lt;br /&gt;
&lt;br /&gt;
Each of those two Guard components is enabled for all users that have the according capability configured. Please note that users need to have the Drive permission set to use Guard Drive. So the users that have Guard Drive enabled must be a subset of those users with OX Drive permission. Since v7.6.0 we enforce this via the default configuration. Those capabilities can be activated for specific user by using the Open-Xchange provisioning scripts:&lt;br /&gt;
&lt;br /&gt;
==== Guard Mail: ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /opt/open-xchange/sbin/changeuser -c 1 -A oxadmin -P admin_password -u testuser --config/com.openexchange.capability.guard-mail=true&amp;lt;/source&amp;gt;&lt;br /&gt;
==== Guard Drive: ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /opt/open-xchange/sbin/changeuser -c 1 -A oxadmin -P admin_password -u testuser --config/com.openexchange.capability.guard-drive=true&amp;lt;/source&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: Guard Drive requires Guard Mail to be configured for the user as well. In addition, these capabilities may be configured globally by editing the &amp;lt;code&amp;gt;guard-api.properties&amp;lt;/code&amp;gt; file on the OX backend.&lt;br /&gt;
&lt;br /&gt;
=== External Guest recipients ===&lt;br /&gt;
Starting in Guard 2.10.0, when an encrypted email is sent to a user that does not have Guard, a guest account is created for them in appsuite.  The recipient uses the Guest account to read the encrypted email.  These guest users MUST have guard capabilities.  To do this, guard capability must be added to guest accounts.&lt;br /&gt;
&amp;lt;code&amp;gt;/opt/open-xchange/etc/share.properties&amp;lt;/code&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.share.guestCapabilityMode=static&lt;br /&gt;
com.openexchange.share.staticGuestCapabilities=guard&amp;lt;/source&amp;gt;&lt;br /&gt;
In a distributed system, the Guest accounts should not be considered transient.  Guard servers must be able to verify the guest account exists in the session storage services.&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.share.transientSessions=false&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Guest Storage ===&lt;br /&gt;
When an encrypted email is sent to an external Guest, a copy of the fully encrypted email is stored on the server.  This is used to create an inbox of encrypted emails for the guest.  By entering in a password, the emails can be decrypted and displayed.&lt;br /&gt;
&lt;br /&gt;
How these files are stored depend on which package, open-xchange-guard-file-storage or open-xchange-guard-s3-storage, was installed.&lt;br /&gt;
&lt;br /&gt;
The file retention policy is configured in the guard-core.properties file.&lt;br /&gt;
&lt;br /&gt;
=== Recipient key detection ===&lt;br /&gt;
&lt;br /&gt;
==== Local ====&lt;br /&gt;
&lt;br /&gt;
Guard needs to determine if an email recipients email address is an internal or external (non-ox) user.&lt;br /&gt;
&lt;br /&gt;
To detect if the recipient is an account on the same OX Guard system there is a mechanism needed to map a recipient mail address to the correct local OX context. The default implementation delivered in the product achieves that by looking up the mail domain (@example.com) within the list of context mappings. That is at least not possible in case of ISPs where different users/contexts use the same mail domain. In case your OX system does not use mail domains in context mappings it is required to deploy an OX OSGi bundle implementing the &amp;lt;code&amp;gt;com.openexchange.mailmapping.MailResolver&amp;lt;/code&amp;gt; class or by interfacing Guard with your mail resolver system. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardMailResolver OX Guard Mail Resolver] for details.&lt;br /&gt;
&lt;br /&gt;
==== External ====&lt;br /&gt;
&lt;br /&gt;
Starting with Guard 2.0, Guard will use public PGP Key servers if configured to find PGP Public keys. In addition, Guard will also look up SRV records for PGP Key servers for a recipients domain. This follows the standards [http://tools.ietf.org/html/draft-shaw-openpgp-hkp-00#page-9 OpenPGP Draft].&lt;br /&gt;
&lt;br /&gt;
External PGP servers to use can be configured in the guard.properties file on the Guard servers.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.publicPGPDirectory = hkp://keys.gnupg.net:11371, hkp://pgp.mit.edu:11371&amp;lt;/source&amp;gt;&lt;br /&gt;
If you would like this Guard installation discoverable by other Guard servers, then create an SRV record for each domain (&amp;amp;quot;example.com&amp;amp;quot; in this illustration):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;_hkp._tcp.example.com. 28800 IN    SRV     10 1 80 appsuite.example.com.&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039; PGP Public key servers by default append use the URL server/pks when the record is obtained from an SRV record. The proxy above routes anything with the Apache domain/pks to the OX Guard PGP server.&lt;br /&gt;
&lt;br /&gt;
Guard keys are also discoverable using the webkey service as specified here: https://tools.ietf.org/html/draft-koch-openpgp-webkey-service-02&lt;br /&gt;
This is enabled if you include the &lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;ProxyPass /.well-known/openpgpkey/hu balancer://oxguard/hu&amp;lt;/source&amp;gt;&lt;br /&gt;
in the proxy_http.conf as above.&lt;br /&gt;
Please note that the well-known request is targeted on the domain part of the mail adress. Therefore clients will request for a mail address name@example.com the URI https://example.com/.well-known/openpgpkey/hu/...&lt;br /&gt;
&lt;br /&gt;
That means that there is the likely need that some sort of proxying or rewriting from the webserver providing the domain needs to happen. For example for proxying using Apache 2.4 it would roughly look like this:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
SSLProxyEngine on&lt;br /&gt;
&amp;lt;LocationMatch /.well-known/openpgpkey/&amp;gt;&lt;br /&gt;
    ProxyPass https://ox.example.com/.well-known/openpgpkey/&lt;br /&gt;
&amp;lt;/LocationMatch&amp;gt;&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clustering ===&lt;br /&gt;
&lt;br /&gt;
You can run multiple OX Guard servers in your environment to ensure high availability or enhance scalability. OX Guard integrates seamlessly into the existing Open-Xchange infrastructure by using the existing interface standards and is therefor transparent to the environment. A couple of things have to be prepared in order to loosely couple OX Guard servers with Open-Xchange servers in a cluster.&lt;br /&gt;
&lt;br /&gt;
==== MySQL ====&lt;br /&gt;
&lt;br /&gt;
The MySQL servers need to be configured in order to allow access to the configdb of Open-Xchange. To do so you need to set the following configuration in the MySQL &amp;lt;code&amp;gt;my.cnf&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;bind = 0.0.0.0&amp;lt;/source&amp;gt;&lt;br /&gt;
This allows the Guard backend to bind to the MySQL host which is configured in the &amp;lt;code&amp;gt;guard-core.properties&amp;lt;/code&amp;gt; file with &amp;lt;code&amp;gt;com.openexchange.guard.configdbHostname&amp;lt;/code&amp;gt;. After the bind for the MySQL instance is configured and the OX Guard backend would be able to connect to the configured host, you have to grant access for the OX Guard service on the MySQL instance to manage the databases. Do so by connecting to the MySQL server via the MySQL client. Authenticate if necessary and execute the following, please note that you have to modify the hostname / IP address of the client who should be able to connect to this database, it should include all possible OX Guard servers:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;sql&amp;quot;&amp;gt;GRANT ALL PRIVILEGES ON *.* TO &#039;openexchange&#039;@&#039;oxguard.example.com&#039; IDENTIFIED BY ‘secret’;&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Apache ====&lt;br /&gt;
&lt;br /&gt;
OX Guard uses the Open-Xchange REST API to store and fetch data from the Open-Xchange databases. The REST API is a servlet running in the Grizzly container. By default it is not exposed as a servlet through Apache and is only accessibly via port 8009. In order to use Apache&#039;s load balancing via &amp;lt;code&amp;gt;mod_proxy&amp;lt;/code&amp;gt; we need to add a servlet called &amp;amp;quot;preliminary&amp;amp;quot; to &amp;lt;code&amp;gt;proxy_http.conf&amp;lt;/code&amp;gt;, example based on a clustered &amp;lt;code&amp;gt;mod_proxy&amp;lt;/code&amp;gt;configuration:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;Location /preliminary&amp;gt;&lt;br /&gt;
      Order Deny,Allow&lt;br /&gt;
      Deny from all&lt;br /&gt;
      # Only allow access from Guard servers within the network. Do not expose this&lt;br /&gt;
      # location outside of your network. In case you use a load balancing service in front&lt;br /&gt;
      # of your Apache infrastructure you should make sure that access to /preliminary will&lt;br /&gt;
      # be blocked from the Internet / outside clients. Examples:&lt;br /&gt;
      # Allow from 192.168.0.1&lt;br /&gt;
      # Allow from 192.168.1.1 192.168.1.2&lt;br /&gt;
      # Allow from 192.168.0.&lt;br /&gt;
 &amp;lt;/Location&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
 ProxyPass /preliminary balancer://oxcluster/preliminary&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Make sure that the balancer is properly configured in the &amp;lt;code&amp;gt;mod_proxy&amp;lt;/code&amp;gt; configuration. Examples on how to do so can be found in our clustering configuration for Open-Xchange AppSuite. Like explained in the example above, please make sure that this location is only available in your internal network, there is no need to expose &amp;lt;code&amp;gt;/preliminary&amp;lt;/code&amp;gt; to the public, it is only used by Guard servers to connect to the OX backend. If you have a load balancer in front of the Apache cluster you should consider blocking access to &amp;lt;code&amp;gt;/preliminary&amp;lt;/code&amp;gt; from WAN to restrict access to the servlet to internal network services only.&lt;br /&gt;
&lt;br /&gt;
Now add the OX Guard &amp;lt;code&amp;gt;BalancerMembers&amp;lt;/code&amp;gt; to the oxguard balancer configuration (also in &amp;lt;code&amp;gt;proxy_http.conf&amp;lt;/code&amp;gt;) to address all your OX Guard nodes in the cluster in this balancer configuration. The configuration has to be applied to all Apache nodes within the cluster.&lt;br /&gt;
&lt;br /&gt;
If the Apache server is a dedicated server &amp;lt;code&amp;gt;/&amp;lt;/code&amp;gt; instance you also have to install the OX Guard UI-Static package on all Apache nodes in the cluster in order to provide static files like images or CSS to the OX Guard client. Example for Debian (the OX Guard repository has to be configured in the package management prior):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ apt-get install open-xchange-guard-ui-static&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Open-Xchange ====&lt;br /&gt;
&lt;br /&gt;
Disable the Open-Xchange IPCheck for session verification. This is required because OX Guard will use the users session cookie to connect to the Open-Xchange REST API, but as a different IP address than the OX Guard server has been used during authentication the request would fail if you don&#039;t disable the IPCheck:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/server.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
and set:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.IPCheck=false&amp;lt;/source&amp;gt;&lt;br /&gt;
The OX Guard UI package has to be installed on all Open-Xchange backend nodes as well, example for Debian (the OX Guard repository has to be configured in the package management prior):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ apt-get install open-xchange-guard-ui&amp;lt;/source&amp;gt;&lt;br /&gt;
Restart the Open-Xchange service afterwards.&lt;br /&gt;
&lt;br /&gt;
==== OX Guard ====&lt;br /&gt;
&lt;br /&gt;
For details in clustering Guard servers, please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCluster OX Guard Clustering]. It is &#039;&#039;&#039;critical&#039;&#039;&#039; that all Guard servers have the same &amp;lt;code&amp;gt;oxguardpass&amp;lt;/code&amp;gt; file. Please see the clustering link for details. Do not run &amp;lt;code&amp;gt;/opt/open-xchange/sbin/guard --init&amp;lt;/code&amp;gt; on more than one server.&lt;br /&gt;
&lt;br /&gt;
After all the services like MySQL, Apache and Open-Xchange have been configured you need to update the OX Guard backend configuration to point to the correct API endpoints. Set the REST API endpoint to an Apache server by setting the following value in &amp;lt;code&amp;gt;/opt/open-xchange/etc/guard-core.properties&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.restApiHostname=apache.example.com&amp;lt;/source&amp;gt;&lt;br /&gt;
Per default Guard will try to connect to port 8009 to this host, but as we configured the REST API to be proxies thorugh the servlet &amp;lt;code&amp;gt;/preliminary&amp;lt;/code&amp;gt; on every Apache we now also need to change the target port for the REST API. You can do so by adding the following line into &amp;lt;code&amp;gt;/opt/open-xchange/etc/guard-core.properties&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.oxBackendPort=80&amp;lt;/source&amp;gt;&lt;br /&gt;
Please also change all settings in regards to MySQL like &amp;lt;code&amp;gt;com.openexchange.guard.configdbHostname&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;com.openexchange.guard.oxguardDatabaseHostname&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;com.openexchange.guard.databaseUsername&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;om.openexchange.guard.databasePassword&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Afterwards restart the OX Guard service and check the log file if the OX Guard backend is able to connect to the configured REST API.&lt;br /&gt;
&lt;br /&gt;
=== Multi Node ===&lt;br /&gt;
&lt;br /&gt;
If you have multiple OX and Guard installations, please see the following documentation [https://oxpedia.org/wiki/index.php?title=AppSuite:OX_Guard_Modular OX Guard Modular Setup].&lt;br /&gt;
&lt;br /&gt;
=== Mail Filter Integration (2.10.4+) ===&lt;br /&gt;
&lt;br /&gt;
To add additional mail filter tests (verify PGP signature, or encrypt incoming), please see&lt;br /&gt;
[[AppSuite:OX_Guard_MailFilter | MailFilter Integration]]&lt;br /&gt;
&lt;br /&gt;
== Support API ==&lt;br /&gt;
&lt;br /&gt;
The OX Guard Support API enables administrative access to various functions for maintaining OX Guard from a client in a role as a support employee. A client has to do a BASIC AUTH authentication in order to access the API. Username and password can be configured in the guard-core.properties file using the following settings:&lt;br /&gt;
&lt;br /&gt;
 # Specify the username and password for accessing the Support API of Guard&lt;br /&gt;
 com.openexchange.guard.supportApiUsername=&lt;br /&gt;
 com.openexchange.guard.supportApiPassword=&lt;br /&gt;
&lt;br /&gt;
In contrast to the rest of the OX Guard requests, the OX Guard support API requests are accessible using: /guardsupport. This distinction allows more flexible configuration since the support API should not always be accessible from everywhere. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Warning&#039;&#039;&#039;: Exposing the support API to the internet could be huge security risk. Only add to Apache if you know what you are doing.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Reset password ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=reset_password&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Performs a password reset and sends a new random generated password to a specified email address by the user or a default address if the user did not specify an email address. (&#039;&#039;Since Guard 2.0&#039;&#039;)&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;email&amp;lt;/code&amp;gt; – The email address of the user to reset the password for&lt;br /&gt;
* &amp;lt;code&amp;gt;default&amp;lt;/code&amp;gt; (optional) – The email address to send the new password to, if the user did not specify a secondary email address&lt;br /&gt;
&lt;br /&gt;
Response:&lt;br /&gt;
PRIMARY if the reset was sent to the primary email address.  SECONDARY if the reset email was sent to the secondary email address that the user specified&lt;br /&gt;
&lt;br /&gt;
=== Expose key ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=expose_key&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Marks a deleted user key temporary as “exposed” and creates a unique URL for downloading the exposed key. Automatic resetting of exposed keys to &amp;amp;quot;not exposed&amp;amp;quot; is scheduled once a day and resets all exposed keys which have been exposed before X hours, where X can be configured using com.openexchange.guard.exposedKeyDurationInHours in the guard.properties files. (&#039;&#039;Since Guard 2.0&#039;&#039;)&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;email&amp;lt;/code&amp;gt; – The email address of the user to expose the deleted keys for&lt;br /&gt;
* &amp;lt;code&amp;gt;cid&amp;lt;/code&amp;gt; – The context id&lt;br /&gt;
&lt;br /&gt;
Response: A URL pointing to the downloadable exposed keys.&lt;br /&gt;
&lt;br /&gt;
=== Delete user ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=delete_user&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deletes all keys related to a certain user. The keys are backed up and can be exposed using the “expose_key” call. (&#039;&#039;Since Guard 2.0&#039;&#039;)&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;user_id&amp;lt;/code&amp;gt; – The user&#039;s id&lt;br /&gt;
* &amp;lt;code&amp;gt;cid&amp;lt;/code&amp;gt; - The context id&lt;br /&gt;
&lt;br /&gt;
=== Upgrade User (Release 2.10 and later) ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=upgrade_guest&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Upgrades a Guest account.  This action copies all of the keys from the Guest account to a full OX account, assuming that user has Guard capabilities.&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;email&amp;lt;/code&amp;gt; - The email address of the Guest user&lt;br /&gt;
* &amp;lt;code&amp;gt;user_id&amp;lt;/code&amp;gt; – The user&#039;s new id&lt;br /&gt;
* &amp;lt;code&amp;gt;cid&amp;lt;/code&amp;gt; - The user&#039;s new context id&lt;br /&gt;
&lt;br /&gt;
== Customisation ==&lt;br /&gt;
&lt;br /&gt;
Guard&#039;s templates are customisable at the user and context level. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCustomization Customisation] for details.&lt;br /&gt;
&lt;br /&gt;
== Entropy ==&lt;br /&gt;
&lt;br /&gt;
Guard requires entropy (randomness) to generate the private/public keys that are used. Depending on the server and it&#039;s environment, this may become a problem. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardEntropy Entropy] for a possible solution.&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:OX_Guard&amp;diff=25611</id>
		<title>AppSuite:OX Guard</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:OX_Guard&amp;diff=25611"/>
		<updated>2020-09-23T07:17:36Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= OX Guard (Version 2.10) =&lt;br /&gt;
&lt;br /&gt;
For previous versions of OX Guard, please click here&lt;br /&gt;
* [[AppSuite:OX_Guard_2-0 | Installation and information of OX Guard 2.0 - 2.2]]&lt;br /&gt;
* [[Appsuite:OX_Guard_2_8 | Installation and information of OX Guard 2.4 - 2.8]]&lt;br /&gt;
&lt;br /&gt;
If upgrading from 2.6 or 2.8, please see&lt;br /&gt;
* [[Appsuite:OX_Guard_Upgrade_2_10|Upgrading to 2.10]]&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
&lt;br /&gt;
OX Guard is a fully integrated security add-on to OX App Suite that provides end users with a flexible email and file encryption solution. OX Guard is a highly scalable, multi server, feature rich solution that is so simple-to-use that end users will actually use it. With a single click a user can take control of their security and send secure emails and share encrypted files. This can be done from any device to both OX App Suite and non-OX App Suite users.&lt;br /&gt;
&lt;br /&gt;
OX Guard uses standard PGP encryption for the encryption of email and files. PGP has been around for a long time, yet has not really caught on with the masses. This is generally blamed on the confusion and complications of managing the keys, understanding trust, PGP format types, and lack of trusted central key repositories. Guard simplifies all of this, making PGP encryption as easy as a one click process, with no keys to keep track of, yet the options of advanced PGP management for those that know how.&lt;br /&gt;
&lt;br /&gt;
This article will guide you through the installation of Guard and describes the basic configuration and software requirements. As it is intended as a quick walk-through it assumes an existing installation of the operating system including a single server App Suite setup as well as average system administration skills. This guide will also show you how to setup a basic installation with none of the typically used distributed environment settings. The objective of this guide is:&lt;br /&gt;
&lt;br /&gt;
* To setup a single server installation&lt;br /&gt;
* To setup a single Guard instance on an existing Open-Xchange installation, no cluster&lt;br /&gt;
* To use the database service on the existing Open-Xchange installation for Guard, no replication&lt;br /&gt;
* To provide a basic configuration setup, no mail server configuration&lt;br /&gt;
&lt;br /&gt;
=== Key Features ===&lt;br /&gt;
&lt;br /&gt;
* Simple security at the touch of a button&lt;br /&gt;
* Provides user based security - Separate from provider&lt;br /&gt;
* Supplementary security to Provider based security - Layered&lt;br /&gt;
* Powerful features yet simple to use and understand&lt;br /&gt;
* Security - Inside and outside of the OX environment&lt;br /&gt;
* Email and Drive integration&lt;br /&gt;
* Uses proven PGP security&lt;br /&gt;
&lt;br /&gt;
=== Availability ===&lt;br /&gt;
&lt;br /&gt;
If an OX App Suite customer would like to evaluate OX Guard integration, the first step is to contact OX Sales. OX Sales will then work on the request and send prices and license/API (for the hosted infrastructure) key details to the customer.&lt;br /&gt;
&lt;br /&gt;
=== Requirements ===&lt;br /&gt;
&lt;br /&gt;
Please review [https://oxpedia.org/wiki/index.php?title=AppSuite:OX_System_Requirements#OX_Guard OX Guard Requirements] for a full list of requirements.&lt;br /&gt;
&lt;br /&gt;
Since OX Guard is a Microservice it can either be added to an existing Open-Xchange installation or it can be deployed on a dedicated environment. The version of Guard installed is dependent on the Appsuite version installed.  Please refer to the version matrix below.&lt;br /&gt;
&lt;br /&gt;
==== Prerequisites ====&lt;br /&gt;
&lt;br /&gt;
* Open-Xchange REST API&lt;br /&gt;
* Grizzly HTTP connector (open-xchange-grizzly)&lt;br /&gt;
* A supported Java Virtual Machine (Java 8)&lt;br /&gt;
* An Open-Xchange App Suite installation (see version Matrix)&lt;br /&gt;
* Please Note: To get access to the latest minor features and bug fixes, you need to have a valid license. The article [https://oxpedia.org/wiki/index.php?title=AppSuite:UpdatingOXPackages Updating OX-Packages] explains how that can be done.&lt;br /&gt;
&lt;br /&gt;
==== Version Matrix ====&lt;br /&gt;
{|&lt;br /&gt;
! style=&amp;quot;text-align:left;&amp;quot;| Core Version&lt;br /&gt;
! Guard Version&lt;br /&gt;
|-&lt;br /&gt;
|7.8.1&lt;br /&gt;
|2.4.0 or 2.4.2&lt;br /&gt;
|-&lt;br /&gt;
|7.8.2&lt;br /&gt;
|2.4.2&lt;br /&gt;
|-&lt;br /&gt;
|7.8.3&lt;br /&gt;
|2.6.0&lt;br /&gt;
|-&lt;br /&gt;
|7.8.4&lt;br /&gt;
|2.8.0&lt;br /&gt;
|-&lt;br /&gt;
|7.10.0&lt;br /&gt;
|2.10.0&lt;br /&gt;
|-&lt;br /&gt;
|7.10.1&lt;br /&gt;
|2.10.1&lt;br /&gt;
|-&lt;br /&gt;
|7.10.2&lt;br /&gt;
|2.10.2&lt;br /&gt;
|-&lt;br /&gt;
|7.10.3&lt;br /&gt;
|2.10.3&lt;br /&gt;
|-&lt;br /&gt;
|7.10.4&lt;br /&gt;
|2.10.4&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Important Notes ===&lt;br /&gt;
&lt;br /&gt;
==== Customisation ====&lt;br /&gt;
&lt;br /&gt;
OX Guard version supports branding / theming using the configuration cascade, defining a templateID for a user or context. Check the [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCustomization OX Guard Customisation] article for more details.&lt;br /&gt;
&lt;br /&gt;
==== Mail Resolver ====&lt;br /&gt;
&lt;br /&gt;
READ THIS VERY CAREFULLY; BEFORE PROCEEDING WITH GUARD INSTALLATION!&lt;br /&gt;
&lt;br /&gt;
The Guard installation must be able to determine if an email recipient is a local OX user or if it should be a guest account. The default MailResolver uses the context domain name to do this. On many installations, domains may extend across multiple context and multiple database shards. In these cases, the default MailResolver won&#039;t work. In addition, if a custom authentication package is used, the Mail Resolver will likely not work.&lt;br /&gt;
&lt;br /&gt;
Once Guard is installed, please be sure to test the mail resolver using:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;/opt/open-xchange/sbin/guard test email@domain&amp;lt;/source&amp;gt;&lt;br /&gt;
to see if the mail Resolver works.&lt;br /&gt;
&lt;br /&gt;
If the test does not work, you will likely need a custom Mail Resolver. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardMailResolver Mail Resolver] page&lt;br /&gt;
&lt;br /&gt;
This resolver software &#039;&#039;depends heavily on your local deployment&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Download and Installation ==&lt;br /&gt;
&lt;br /&gt;
=== General ===&lt;br /&gt;
&lt;br /&gt;
The installation of the &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; package which is required for Guard and the main &amp;lt;code&amp;gt;open-xchange-guard&amp;lt;/code&amp;gt; package in version 2.4.0 or higher will eventually execute database update tasks if installed and activated. Please take this into account.&lt;br /&gt;
&lt;br /&gt;
There are several components to the Guard service. They can be all installed on the same server as the OX middleware or on a separate server.&lt;br /&gt;
&lt;br /&gt;
The components required for the OX middleware are: &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
The components required for the OX frontend are: &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; and optionally &amp;lt;code&amp;gt;open-xchange-guard-help-en-us&amp;lt;/code&amp;gt; (or preferred language for help files).&lt;br /&gt;
&lt;br /&gt;
The components required for the Guard server &amp;lt;code&amp;gt;open-xchange-guard&amp;lt;/code&amp;gt; and either &amp;lt;code&amp;gt;open-xchange-guard-file-storage&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;open-xchange-guard-s3-storage&amp;lt;/code&amp;gt; depending on what storage you want to use. The examples below make use of the &amp;lt;code&amp;gt;open-xchange-guard-file-storage&amp;lt;/code&amp;gt;. Adjust the commands accordingly to fit your needs. In addition &amp;lt;code&amp;gt;open-xchange&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-core&amp;lt;/code&amp;gt; are required to run OX Guard.&lt;br /&gt;
&lt;br /&gt;
=== Debian Linux 9.0 (Stretch) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 deb https://software.open-xchange.com/products/guard/stable/guard/DebianStretch /&lt;br /&gt;
 deb https://software.open-xchange.com/products/appsuite/stable/backend/DebianStretch /&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== Debian Linux 10.0 (Buster) *Version 2.10.3+ only* ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 deb https://software.open-xchange.com/products/guard/stable/guard/DebianBuster /&lt;br /&gt;
 deb https://software.open-xchange.com/products/appsuite/stable/backend/DebianBuster /&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== RedHat Enterprise Linux 6 or CentOS 6 (valid until v2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/guard/2.10.3/guard/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/7.10.3/backend/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== Redhat Enterprise Linux 7 or CentOS 7 ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/guard/stable/guard/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/stable/backend/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== SUSE Linux Enterprise Server 12 (valid until 2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
Add the package repository using zypper if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ar https://software.open-xchange.com/products/guard/2.10.3/guard/SLE_12 guard-stable-guard&lt;br /&gt;
 $ zypper ar https://software.open-xchange.com/products/appsuite/7.10.3/backend/SLE_12 ox-backend&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&lt;br /&gt;
 $ zypper in open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static&lt;br /&gt;
&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&lt;br /&gt;
 $ zypper in open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== Univention Corporate Server ===&lt;br /&gt;
&lt;br /&gt;
If you have purchased the OX App Suite for UCS, the OX Guard is part of the offering. OX Guard is available in the Univention App Center. Please check the UMC module App Center for the installation of the OX Guard at your already available environment.&lt;br /&gt;
&lt;br /&gt;
Please note: By default, OX Guard generates the link to the secure content for external recipients on the basis of the local fully qualified domain name (FQDN). If the local FQDN is not reachable from the Internet, it has to be specified manually. This can be done by setting a UCR variable, e.g. via the UMC module &amp;amp;quot;Univention Configuration Registry&amp;amp;quot;. The variable has to contain the external FQDN of the OX Guard system:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;oxguard/cfg/guard.properties/com.openexchange.guard.externalEmailURL=HOSTNAME.DOMAINNAME&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Update OX Guard ==&lt;br /&gt;
&lt;br /&gt;
This section contains information about updating a 2.10.0 version (e.g. for patch fixes). Upgrading from prior versions is discussed in different articles.&lt;br /&gt;
&lt;br /&gt;
=== Debian Linux 9.0 (Stretch) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 deb &amp;lt;https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/stable/guard/updates/DebianStretch /&amp;gt;&lt;br /&gt;
 deb &amp;lt;https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/stable/backend/DebianStretch /&amp;lt;/source&amp;gt;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Then run:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get dist-upgrade&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If you want to see, what apt-get is going to do without actually doing it, you can run:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get dist-upgrade -s&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Redhat Enterprise Linux 6 or CentOS 6 (valid until 2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard-updates]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard-updates&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/2.10.3/guard/updates/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/7.10.3/backend/updates/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
and then run:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum upgrade&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Redhat Enterprise Linux 7 or CentOS 7 ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard-updates]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard-updates&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/stable/guard/updates/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/stable/backend/updates/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
and then run:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum upgrade&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== SUSE Linux Enterprise Server 12 (valid until 2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
Add the package repository using &amp;lt;code&amp;gt;zypper&amp;lt;/code&amp;gt; if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ar https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/2.10.3/guard/updates/SLE_12 guard-stable-guard-updates&lt;br /&gt;
 $ zypper ar https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/7.10.3/backend/updates/SLE_12 ox-backend&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
and then run:&lt;br /&gt;
&lt;br /&gt;
 $ zypper dup -r guard-stable-guard-backend-updates&lt;br /&gt;
 $ zypper dup -r guard-stable-guard-ui-updates&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You might need to run:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
to update the repository metadata before running &amp;lt;code&amp;gt;zypper&amp;lt;/code&amp;gt; up.&lt;br /&gt;
&lt;br /&gt;
=== Univention Corporate Server ===&lt;br /&gt;
&lt;br /&gt;
If you have purchased the OX App Suite for UCS, the OX Guard is part of the offering. OX Guard is available in the Univention App Center. Please check the UMC module App Center for the update of the OX Guard.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Configuration ==&lt;br /&gt;
&lt;br /&gt;
The following gives an overview of the most important settings to enable Guard for users on the Open-Xchange installation. Some of those settings have to be modified in order to establish the database and REST API access from the Guard service. All settings relating to the Guard backend component are located in the configuration file &amp;lt;code&amp;gt;guard-core.properties&amp;lt;/code&amp;gt; located in &amp;lt;code&amp;gt;/opt/open-xchange/etc&amp;lt;/code&amp;gt;. The default configuration should be sufficient for a basic &amp;amp;quot;up-and-running&amp;amp;quot; setup (with the exception of defining the database username and password). Please refer to the inline documentation of the configuration file for more advanced options. Additional information can be found in the [https://oxpedia.org/wiki/index.php?title=AppSuite:OX_Guard_Configuration_2_10 Guard Configuration] article.&lt;br /&gt;
&lt;br /&gt;
=== Basic Configuration ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/guard-core.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
Guard database for storing Guard user information, main lookup tables:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.oxguardDatabaseHostname=localhost&amp;lt;/source&amp;gt;&lt;br /&gt;
Guard database that stores keys for guest users. May be the same as above. New guest shards will be created on this database as needed. If not supplied, will use the &amp;lt;code&amp;gt;oxguardDatabaseHostname&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.oxguardShardDatabase=localhost&amp;lt;/source&amp;gt;&lt;br /&gt;
Username and Password for the databases above:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.databaseUsername=openexchange&lt;br /&gt;
com.openexchange.guard.databasePassword=db_password&amp;lt;/source&amp;gt;&lt;br /&gt;
Open-Xchange REST API host:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.restApiHostname=localhost&amp;lt;/source&amp;gt;&lt;br /&gt;
Open-Xchange REST API username and password (need to be defined in the OX backend in the &amp;amp;quot;Configure services&amp;amp;quot; below):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.restApiUsername=apiusername&lt;br /&gt;
com.openexchange.guard.restApiPassword=apipassword&amp;lt;/source&amp;gt;&lt;br /&gt;
External URL for this Open-Xchange installation. This setting will be used to generate the link to the secure content for external recipients:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.externalEmailURL=URL_TO_OX&amp;lt;/source&amp;gt;&lt;br /&gt;
=== Middleware Configuration on OX Guard node ===&lt;br /&gt;
&lt;br /&gt;
If you are installing OX Guard on a node that until yet did not host an Open-Xchange middleware you have to additionally configure some parts of the following properties files:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;configdb.properties&amp;lt;/code&amp;gt;: information about the existing configuration database.&lt;br /&gt;
* &amp;lt;code&amp;gt;server.properties&amp;lt;/code&amp;gt;: information about the connections have to be set.&lt;br /&gt;
* &amp;lt;code&amp;gt;system.properties&amp;lt;/code&amp;gt;: at least &amp;lt;code&amp;gt;SERVER_NAME&amp;lt;/code&amp;gt; should be set.&lt;br /&gt;
&lt;br /&gt;
=== Sevices Configuration ===&lt;br /&gt;
&lt;br /&gt;
==== Apache ====&lt;br /&gt;
&lt;br /&gt;
Configure the &amp;lt;code&amp;gt;mod_proxy_http&amp;lt;/code&amp;gt; module by adding the Guard API.&lt;br /&gt;
&lt;br /&gt;
===== Redhat Enterprise Linux 6 or CentOS 6 =====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /etc/httpd/conf.d/proxy_http.conf&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Debian GNU/Linux 9.0 =====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /etc/apache2/conf-enabled/proxy_http.conf&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;Proxy balancer://oxguard&amp;gt;&lt;br /&gt;
        Order deny,allow&lt;br /&gt;
        Allow from all&lt;br /&gt;
 &lt;br /&gt;
        BalancerMember http://localhost:8009/ timeout=1800 smax=0 ttl=60 retry=60 loadfactor=100 route=OX1&lt;br /&gt;
        ProxySet stickysession=JSESSIONID|jsessionid scolonpathdelim=ON&lt;br /&gt;
       SetEnv proxy-initial-not-pooled&lt;br /&gt;
        SetEnv proxy-sendchunked&lt;br /&gt;
 &amp;lt;/Proxy&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
 ProxyPass /appsuite/api/oxguard balancer://oxguard/oxguard&lt;br /&gt;
 ProxyPass /pks balancer://oxguard/pgp&lt;br /&gt;
 ProxyPass /.well-known/openpgpkey/hu balancer://oxguard/hu&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: The Guard API settings must be inserted &#039;&#039;&#039;&#039;&#039;before&#039;&#039;&#039;&#039;&#039; the existing &amp;lt;code&amp;gt;ProxyPass /appsuite/api&amp;lt;/code&amp;gt; parameter.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Also Note&#039;&#039;&#039;:  If you already have a Proxy balancer for the OX backend with the same URL (say http://localhost:8080) then you don&#039;t need the second BalancerMember entry, and you can just have the ProxyPass address that balancer instead.&lt;br /&gt;
&lt;br /&gt;
After the configuration is done, restart the Apache webserver&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ apachectl restart&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Open-Xchange Middleware Configuration ===&lt;br /&gt;
&lt;br /&gt;
Edit the &amp;lt;code&amp;gt;guard-api.properties&amp;lt;/code&amp;gt; configuration file for the OX backend where the guard-backend-plugin was installed. Please remove comments in front of the following settings to the configuration file &amp;lt;code&amp;gt;guard-api.properties&amp;lt;/code&amp;gt; on the Open-Xchange backend servers:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/guard-api.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;# OX Guard general permission, required to activate Guard in the AppSuite UI.&lt;br /&gt;
com.openexchange.capability.guard=true&lt;br /&gt;
&lt;br /&gt;
# Default theme template id for all users that have no custom template id configured.&lt;br /&gt;
com.openexchange.guard.templateID=0&amp;lt;/source&amp;gt;&lt;br /&gt;
Configure the API username and password that you assigned to Guard in the &amp;lt;code&amp;gt;server.properties&amp;lt;/code&amp;gt; file:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/server.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;# Specify the user name used for HTTP basic auth by internal REST servlet&lt;br /&gt;
com.openexchange.rest.services.basic-auth.login=apiusername&lt;br /&gt;
&lt;br /&gt;
# Specify the password used for HTTP basic auth by internal REST servlet&lt;br /&gt;
com.openexchange.rest.services.basic-auth.password=apipassword&amp;lt;/source&amp;gt;&lt;br /&gt;
Finally, the OX backend needs to know where the Guard server is located. This is used to notify the Guard server of changes in users, and to send emails marked for signature. The URL for the Guard server should include the URL suffix &amp;lt;code&amp;gt;/guardadmin&amp;lt;/code&amp;gt;. In the event of a cluster setup, any Guard server can be referenced here, as it is not session specific, though ideally would have a HTTP load balancer/failover URL:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/guard-api.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;# Specifies the URI to the OX Guard end-point; e.g. http://guard.host.invalid:8081/guardadmin&lt;br /&gt;
# Default is empty&lt;br /&gt;
com.openexchange.guard.endpoint=http://guardserver:8009/guardadmin&amp;lt;/source&amp;gt;&lt;br /&gt;
Restart the OX backend&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /etc/init.d/open-xchange restart&amp;lt;/source&amp;gt;&lt;br /&gt;
==== SELinux ====&lt;br /&gt;
&lt;br /&gt;
Running SELinux prohibits your local Open-Xchange backend service to connect to localhost:8009, which is where the Guard backend service listens to. In order to allow localhost connections to 8009 execute the following:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ setsebool -P httpd_can_network_connect 1&amp;lt;/source&amp;gt;&lt;br /&gt;
=== Generating the &amp;lt;code&amp;gt;oxguardpass&amp;lt;/code&amp;gt; ===&lt;br /&gt;
&lt;br /&gt;
Once the Guard configuration (database and backend configuration) and the service configuration has been applied, the Guard administration script needs to be executed in order to create the master password file in &amp;lt;code&amp;gt;/opt/open-xchange/etc/oxguardpass&amp;lt;/code&amp;gt;. The initiation only needs to be done &#039;&#039;&#039;once&#039;&#039;&#039; for a multi server setup, for details please see the sections &#039;&#039;&#039;Optional&#039;&#039;&#039; and/or &#039;&#039;&#039;Clustering&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: If you run a cluster of OX / Guard nodes, only execute this command on &#039;&#039;&#039;ONE&#039;&#039;&#039; node. Not on all nodes! See [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCluster OX Guard Clustering] for details.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /opt/open-xchange/sbin/guard --init&amp;lt;/source&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: It is important to understand that the master password file located at &amp;lt;code&amp;gt;/opt/open-xchange/etc/oxguardpass&amp;lt;/code&amp;gt; is required to reset user passwords; without them the administrator will not be able to reset user passwords anymore in the future. The file contains the passwords used to encrypt the master database key, as well as passwords used to encrypt protected data in the users table. It must be the same on all Guard servers.&lt;br /&gt;
&lt;br /&gt;
=== Test Setup ===&lt;br /&gt;
&lt;br /&gt;
Not required, but it is a good idea to test the Guard setup before enabling for any users. The test function will verify that Guard has a good connection to the OX backend, and that it can resolve email addresses to users.&lt;br /&gt;
&lt;br /&gt;
To test, use an email address that exists on the OX backend (john@example.com for this example)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;/opt/open-xchange/sbin/guard --test john@example.com&amp;lt;/source&amp;gt;&lt;br /&gt;
Guard should return information from the OX backend regarding the user associated with &amp;amp;quot;john@example.com&amp;amp;quot;. Problems resolving information for the user should be resolved before using Guard. Check Rest API passwords and settings if errors returned.&lt;br /&gt;
&lt;br /&gt;
=== Enabling Guard for Users ===&lt;br /&gt;
&lt;br /&gt;
Guard provides two capabilities for users in the environment as well as a basic &amp;amp;quot;core&amp;amp;quot; level:&lt;br /&gt;
&lt;br /&gt;
* Guard: &amp;lt;code&amp;gt;com.openexchange.capability.guard&amp;lt;/code&amp;gt;&lt;br /&gt;
* Guard Mail: &amp;lt;code&amp;gt;com.openexchange.capability.guard-mail&amp;lt;/code&amp;gt;&lt;br /&gt;
* Guard Drive: &amp;lt;code&amp;gt;com.openexchange.capability.guard-drive&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The &amp;amp;quot;core&amp;amp;quot; Guard enabled a basic read functionality for Guard encrypted emails. We recommend enabling this for all users, as this allows all recipients to read Guard emails sent to them. Great opportunity for upsell. Recipients with only Guard enabled can then do a secure reply to the sender, but they can&#039;t start a new email or add recipients.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Guard Mail&#039;&#039;&#039; and &#039;&#039;&#039;Guard Drive&#039;&#039;&#039; are additional options for users. &amp;amp;quot;Guard Mail&amp;amp;quot; allows users the full functionality of Guard emails. &amp;amp;quot;Guard Drive&amp;amp;quot; allows for encryption and decryption of drive files.&lt;br /&gt;
&lt;br /&gt;
Each of those two Guard components is enabled for all users that have the according capability configured. Please note that users need to have the Drive permission set to use Guard Drive. So the users that have Guard Drive enabled must be a subset of those users with OX Drive permission. Since v7.6.0 we enforce this via the default configuration. Those capabilities can be activated for specific user by using the Open-Xchange provisioning scripts:&lt;br /&gt;
&lt;br /&gt;
==== Guard Mail: ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /opt/open-xchange/sbin/changeuser -c 1 -A oxadmin -P admin_password -u testuser --config/com.openexchange.capability.guard-mail=true&amp;lt;/source&amp;gt;&lt;br /&gt;
==== Guard Drive: ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /opt/open-xchange/sbin/changeuser -c 1 -A oxadmin -P admin_password -u testuser --config/com.openexchange.capability.guard-drive=true&amp;lt;/source&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: Guard Drive requires Guard Mail to be configured for the user as well. In addition, these capabilities may be configured globally by editing the &amp;lt;code&amp;gt;guard-api.properties&amp;lt;/code&amp;gt; file on the OX backend.&lt;br /&gt;
&lt;br /&gt;
=== External Guest recipients: ===&lt;br /&gt;
Starting in Guard 2.10.0, when an encrypted email is sent to a user that does not have Guard, a guest account is created for them in appsuite.  The recipient uses the Guest account to read the encrypted email.  These guest users MUST have guard capabilities.  To do this, guard capability must be added to guest accounts.&lt;br /&gt;
&amp;lt;code&amp;gt;/opt/open-xchange/etc/share.properties&amp;lt;/code&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.share.guestCapabilityMode=static&lt;br /&gt;
com.openexchange.share.staticGuestCapabilities=guard&amp;lt;/source&amp;gt;&lt;br /&gt;
In a distributed system, the Guest accounts should not be considered transient.  Guard servers must be able to verify the guest account exists in the session storage services.&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.share.transientSessions=false&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Guest Storage ===&lt;br /&gt;
When an encrypted email is sent to an external Guest, a copy of the fully encrypted email is stored on the server.  This is used to create an inbox of encrypted emails for the guest.  By entering in a password, the emails can be decrypted and displayed.&lt;br /&gt;
&lt;br /&gt;
How these files are stored depend on which package, open-xchange-guard-file-storage or open-xchange-guard-s3-storage, was installed.&lt;br /&gt;
&lt;br /&gt;
The file retention policy is configured in the guard-core.properties file.&lt;br /&gt;
&lt;br /&gt;
=== Recipient key detection ===&lt;br /&gt;
&lt;br /&gt;
==== Local ====&lt;br /&gt;
&lt;br /&gt;
Guard needs to determine if an email recipients email address is an internal or external (non-ox) user.&lt;br /&gt;
&lt;br /&gt;
To detect if the recipient is an account on the same OX Guard system there is a mechanism needed to map a recipient mail address to the correct local OX context. The default implementation delivered in the product achieves that by looking up the mail domain (@example.com) within the list of context mappings. That is at least not possible in case of ISPs where different users/contexts use the same mail domain. In case your OX system does not use mail domains in context mappings it is required to deploy an OX OSGi bundle implementing the &amp;lt;code&amp;gt;com.openexchange.mailmapping.MailResolver&amp;lt;/code&amp;gt; class or by interfacing Guard with your mail resolver system. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardMailResolver OX Guard Mail Resolver] for details.&lt;br /&gt;
&lt;br /&gt;
==== External ====&lt;br /&gt;
&lt;br /&gt;
Starting with Guard 2.0, Guard will use public PGP Key servers if configured to find PGP Public keys. In addition, Guard will also look up SRV records for PGP Key servers for a recipients domain. This follows the standards [http://tools.ietf.org/html/draft-shaw-openpgp-hkp-00#page-9 OpenPGP Draft].&lt;br /&gt;
&lt;br /&gt;
External PGP servers to use can be configured in the guard.properties file on the Guard servers.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.publicPGPDirectory = hkp://keys.gnupg.net:11371, hkp://pgp.mit.edu:11371&amp;lt;/source&amp;gt;&lt;br /&gt;
If you would like this Guard installation discoverable by other Guard servers, then create an SRV record for each domain (&amp;amp;quot;example.com&amp;amp;quot; in this illustration):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;_hkp._tcp.example.com. 28800 IN    SRV     10 1 80 appsuite.example.com.&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039; PGP Public key servers by default append use the URL server/pks when the record is obtained from an SRV record. The proxy above routes anything with the Apache domain/pks to the OX Guard PGP server.&lt;br /&gt;
&lt;br /&gt;
Guard keys are also discoverable using the webkey service as specified here: https://tools.ietf.org/html/draft-koch-openpgp-webkey-service-02&lt;br /&gt;
This is enabled if you include the &lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;ProxyPass /.well-known/openpgpkey/hu balancer://oxguard/hu&amp;lt;/source&amp;gt;&lt;br /&gt;
in the proxy_http.conf as above.&lt;br /&gt;
Please note that the well-known request is targeted on the domain part of the mail adress. Therefore clients will request for a mail address name@example.com the URI https://example.com/.well-known/openpgpkey/hu/...&lt;br /&gt;
&lt;br /&gt;
That means that there is the likely need that some sort of proxying or rewriting from the webserver providing the domain needs to happen. For example for proxying using Apache 2.4 it would roughly look like this:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
SSLProxyEngine on&lt;br /&gt;
&amp;lt;LocationMatch /.well-known/openpgpkey/&amp;gt;&lt;br /&gt;
    ProxyPass https://ox.example.com/.well-known/openpgpkey/&lt;br /&gt;
&amp;lt;/LocationMatch&amp;gt;&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clustering ===&lt;br /&gt;
&lt;br /&gt;
You can run multiple OX Guard servers in your environment to ensure high availability or enhance scalability. OX Guard integrates seamlessly into the existing Open-Xchange infrastructure by using the existing interface standards and is therefor transparent to the environment. A couple of things have to be prepared in order to loosely couple OX Guard servers with Open-Xchange servers in a cluster.&lt;br /&gt;
&lt;br /&gt;
==== MySQL ====&lt;br /&gt;
&lt;br /&gt;
The MySQL servers need to be configured in order to allow access to the configdb of Open-Xchange. To do so you need to set the following configuration in the MySQL &amp;lt;code&amp;gt;my.cnf&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;bind = 0.0.0.0&amp;lt;/source&amp;gt;&lt;br /&gt;
This allows the Guard backend to bind to the MySQL host which is configured in the &amp;lt;code&amp;gt;guard-core.properties&amp;lt;/code&amp;gt; file with &amp;lt;code&amp;gt;com.openexchange.guard.configdbHostname&amp;lt;/code&amp;gt;. After the bind for the MySQL instance is configured and the OX Guard backend would be able to connect to the configured host, you have to grant access for the OX Guard service on the MySQL instance to manage the databases. Do so by connecting to the MySQL server via the MySQL client. Authenticate if necessary and execute the following, please note that you have to modify the hostname / IP address of the client who should be able to connect to this database, it should include all possible OX Guard servers:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;sql&amp;quot;&amp;gt;GRANT ALL PRIVILEGES ON *.* TO &#039;openexchange&#039;@&#039;oxguard.example.com&#039; IDENTIFIED BY ‘secret’;&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Apache ====&lt;br /&gt;
&lt;br /&gt;
OX Guard uses the Open-Xchange REST API to store and fetch data from the Open-Xchange databases. The REST API is a servlet running in the Grizzly container. By default it is not exposed as a servlet through Apache and is only accessibly via port 8009. In order to use Apache&#039;s load balancing via &amp;lt;code&amp;gt;mod_proxy&amp;lt;/code&amp;gt; we need to add a servlet called &amp;amp;quot;preliminary&amp;amp;quot; to &amp;lt;code&amp;gt;proxy_http.conf&amp;lt;/code&amp;gt;, example based on a clustered &amp;lt;code&amp;gt;mod_proxy&amp;lt;/code&amp;gt;configuration:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;Location /preliminary&amp;gt;&lt;br /&gt;
      Order Deny,Allow&lt;br /&gt;
      Deny from all&lt;br /&gt;
      # Only allow access from Guard servers within the network. Do not expose this&lt;br /&gt;
      # location outside of your network. In case you use a load balancing service in front&lt;br /&gt;
      # of your Apache infrastructure you should make sure that access to /preliminary will&lt;br /&gt;
      # be blocked from the Internet / outside clients. Examples:&lt;br /&gt;
      # Allow from 192.168.0.1&lt;br /&gt;
      # Allow from 192.168.1.1 192.168.1.2&lt;br /&gt;
      # Allow from 192.168.0.&lt;br /&gt;
 &amp;lt;/Location&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
 ProxyPass /preliminary balancer://oxcluster/preliminary&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Make sure that the balancer is properly configured in the &amp;lt;code&amp;gt;mod_proxy&amp;lt;/code&amp;gt; configuration. Examples on how to do so can be found in our clustering configuration for Open-Xchange AppSuite. Like explained in the example above, please make sure that this location is only available in your internal network, there is no need to expose &amp;lt;code&amp;gt;/preliminary&amp;lt;/code&amp;gt; to the public, it is only used by Guard servers to connect to the OX backend. If you have a load balancer in front of the Apache cluster you should consider blocking access to &amp;lt;code&amp;gt;/preliminary&amp;lt;/code&amp;gt; from WAN to restrict access to the servlet to internal network services only.&lt;br /&gt;
&lt;br /&gt;
Now add the OX Guard &amp;lt;code&amp;gt;BalancerMembers&amp;lt;/code&amp;gt; to the oxguard balancer configuration (also in &amp;lt;code&amp;gt;proxy_http.conf&amp;lt;/code&amp;gt;) to address all your OX Guard nodes in the cluster in this balancer configuration. The configuration has to be applied to all Apache nodes within the cluster.&lt;br /&gt;
&lt;br /&gt;
If the Apache server is a dedicated server &amp;lt;code&amp;gt;/&amp;lt;/code&amp;gt; instance you also have to install the OX Guard UI-Static package on all Apache nodes in the cluster in order to provide static files like images or CSS to the OX Guard client. Example for Debian (the OX Guard repository has to be configured in the package management prior):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ apt-get install open-xchange-guard-ui-static&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Open-Xchange ====&lt;br /&gt;
&lt;br /&gt;
Disable the Open-Xchange IPCheck for session verification. This is required because OX Guard will use the users session cookie to connect to the Open-Xchange REST API, but as a different IP address than the OX Guard server has been used during authentication the request would fail if you don&#039;t disable the IPCheck:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/server.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
and set:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.IPCheck=false&amp;lt;/source&amp;gt;&lt;br /&gt;
The OX Guard UI package has to be installed on all Open-Xchange backend nodes as well, example for Debian (the OX Guard repository has to be configured in the package management prior):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ apt-get install open-xchange-guard-ui&amp;lt;/source&amp;gt;&lt;br /&gt;
Restart the Open-Xchange service afterwards.&lt;br /&gt;
&lt;br /&gt;
==== OX Guard ====&lt;br /&gt;
&lt;br /&gt;
For details in clustering Guard servers, please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCluster OX Guard Clustering]. It is &#039;&#039;&#039;critical&#039;&#039;&#039; that all Guard servers have the same &amp;lt;code&amp;gt;oxguardpass&amp;lt;/code&amp;gt; file. Please see the clustering link for details. Do not run &amp;lt;code&amp;gt;/opt/open-xchange/sbin/guard --init&amp;lt;/code&amp;gt; on more than one server.&lt;br /&gt;
&lt;br /&gt;
After all the services like MySQL, Apache and Open-Xchange have been configured you need to update the OX Guard backend configuration to point to the correct API endpoints. Set the REST API endpoint to an Apache server by setting the following value in &amp;lt;code&amp;gt;/opt/open-xchange/etc/guard-core.properties&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.restApiHostname=apache.example.com&amp;lt;/source&amp;gt;&lt;br /&gt;
Per default Guard will try to connect to port 8009 to this host, but as we configured the REST API to be proxies thorugh the servlet &amp;lt;code&amp;gt;/preliminary&amp;lt;/code&amp;gt; on every Apache we now also need to change the target port for the REST API. You can do so by adding the following line into &amp;lt;code&amp;gt;/opt/open-xchange/etc/guard-core.properties&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.oxBackendPort=80&amp;lt;/source&amp;gt;&lt;br /&gt;
Please also change all settings in regards to MySQL like &amp;lt;code&amp;gt;com.openexchange.guard.configdbHostname&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;com.openexchange.guard.oxguardDatabaseHostname&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;com.openexchange.guard.databaseUsername&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;om.openexchange.guard.databasePassword&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Afterwards restart the OX Guard service and check the log file if the OX Guard backend is able to connect to the configured REST API.&lt;br /&gt;
&lt;br /&gt;
=== Multi Node ===&lt;br /&gt;
&lt;br /&gt;
If you have multiple OX and Guard installations, please see the following documentation [https://oxpedia.org/wiki/index.php?title=AppSuite:OX_Guard_Modular OX Guard Modular Setup].&lt;br /&gt;
&lt;br /&gt;
=== Mail Filter Integration (2.10.4+) ===&lt;br /&gt;
&lt;br /&gt;
To add additional mail filter tests (verify PGP signature, or encrypt incoming), please see&lt;br /&gt;
[[AppSuite:OX_Guard_MailFilter | MailFilter Integration]]&lt;br /&gt;
&lt;br /&gt;
== Support API ==&lt;br /&gt;
&lt;br /&gt;
The OX Guard Support API enables administrative access to various functions for maintaining OX Guard from a client in a role as a support employee. A client has to do a BASIC AUTH authentication in order to access the API. Username and password can be configured in the guard-core.properties file using the following settings:&lt;br /&gt;
&lt;br /&gt;
 # Specify the username and password for accessing the Support API of Guard&lt;br /&gt;
 com.openexchange.guard.supportApiUsername=&lt;br /&gt;
 com.openexchange.guard.supportApiPassword=&lt;br /&gt;
&lt;br /&gt;
In contrast to the rest of the OX Guard requests, the OX Guard support API requests are accessible using: /guardsupport. This distinction allows more flexible configuration since the support API should not always be accessible from everywhere. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Warning&#039;&#039;&#039;: Exposing the support API to the internet could be huge security risk. Only add to Apache if you know what you are doing.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Reset password ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=reset_password&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Performs a password reset and sends a new random generated password to a specified email address by the user or a default address if the user did not specify an email address. (&#039;&#039;Since Guard 2.0&#039;&#039;)&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;email&amp;lt;/code&amp;gt; – The email address of the user to reset the password for&lt;br /&gt;
* &amp;lt;code&amp;gt;default&amp;lt;/code&amp;gt; (optional) – The email address to send the new password to, if the user did not specify a secondary email address&lt;br /&gt;
&lt;br /&gt;
Response:&lt;br /&gt;
PRIMARY if the reset was sent to the primary email address.  SECONDARY if the reset email was sent to the secondary email address that the user specified&lt;br /&gt;
&lt;br /&gt;
=== Expose key ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=expose_key&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Marks a deleted user key temporary as “exposed” and creates a unique URL for downloading the exposed key. Automatic resetting of exposed keys to &amp;amp;quot;not exposed&amp;amp;quot; is scheduled once a day and resets all exposed keys which have been exposed before X hours, where X can be configured using com.openexchange.guard.exposedKeyDurationInHours in the guard.properties files. (&#039;&#039;Since Guard 2.0&#039;&#039;)&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;email&amp;lt;/code&amp;gt; – The email address of the user to expose the deleted keys for&lt;br /&gt;
* &amp;lt;code&amp;gt;cid&amp;lt;/code&amp;gt; – The context id&lt;br /&gt;
&lt;br /&gt;
Response: A URL pointing to the downloadable exposed keys.&lt;br /&gt;
&lt;br /&gt;
=== Delete user ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=delete_user&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deletes all keys related to a certain user. The keys are backed up and can be exposed using the “expose_key” call. (&#039;&#039;Since Guard 2.0&#039;&#039;)&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;user_id&amp;lt;/code&amp;gt; – The user&#039;s id&lt;br /&gt;
* &amp;lt;code&amp;gt;cid&amp;lt;/code&amp;gt; - The context id&lt;br /&gt;
&lt;br /&gt;
=== Upgrade User (Release 2.10 and later) ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=upgrade_guest&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Upgrades a Guest account.  This action copies all of the keys from the Guest account to a full OX account, assuming that user has Guard capabilities.&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;email&amp;lt;/code&amp;gt; - The email address of the Guest user&lt;br /&gt;
* &amp;lt;code&amp;gt;user_id&amp;lt;/code&amp;gt; – The user&#039;s new id&lt;br /&gt;
* &amp;lt;code&amp;gt;cid&amp;lt;/code&amp;gt; - The user&#039;s new context id&lt;br /&gt;
&lt;br /&gt;
== Customisation ==&lt;br /&gt;
&lt;br /&gt;
Guard&#039;s templates are customisable at the user and context level. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCustomization Customisation] for details.&lt;br /&gt;
&lt;br /&gt;
== Entropy ==&lt;br /&gt;
&lt;br /&gt;
Guard requires entropy (randomness) to generate the private/public keys that are used. Depending on the server and it&#039;s environment, this may become a problem. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardEntropy Entropy] for a possible solution.&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:OX_Guard&amp;diff=25597</id>
		<title>AppSuite:OX Guard</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:OX_Guard&amp;diff=25597"/>
		<updated>2020-09-15T09:47:02Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: /* External */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= OX Guard (Version 2.10) =&lt;br /&gt;
&lt;br /&gt;
For previous versions of OX Guard, please click here&lt;br /&gt;
* [[AppSuite:OX_Guard_2-0 | Installation and information of OX Guard 2.0 - 2.2]]&lt;br /&gt;
* [[Appsuite:OX_Guard_2_8 | Installation and information of OX Guard 2.4 - 2.8]]&lt;br /&gt;
&lt;br /&gt;
If upgrading from 2.6 or 2.8, please see&lt;br /&gt;
* [[Appsuite:OX_Guard_Upgrade_2_10|Upgrading to 2.10]]&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
&lt;br /&gt;
OX Guard is a fully integrated security add-on to OX App Suite that provides end users with a flexible email and file encryption solution. OX Guard is a highly scalable, multi server, feature rich solution that is so simple-to-use that end users will actually use it. With a single click a user can take control of their security and send secure emails and share encrypted files. This can be done from any device to both OX App Suite and non-OX App Suite users.&lt;br /&gt;
&lt;br /&gt;
OX Guard uses standard PGP encryption for the encryption of email and files. PGP has been around for a long time, yet has not really caught on with the masses. This is generally blamed on the confusion and complications of managing the keys, understanding trust, PGP format types, and lack of trusted central key repositories. Guard simplifies all of this, making PGP encryption as easy as a one click process, with no keys to keep track of, yet the options of advanced PGP management for those that know how.&lt;br /&gt;
&lt;br /&gt;
This article will guide you through the installation of Guard and describes the basic configuration and software requirements. As it is intended as a quick walk-through it assumes an existing installation of the operating system including a single server App Suite setup as well as average system administration skills. This guide will also show you how to setup a basic installation with none of the typically used distributed environment settings. The objective of this guide is:&lt;br /&gt;
&lt;br /&gt;
* To setup a single server installation&lt;br /&gt;
* To setup a single Guard instance on an existing Open-Xchange installation, no cluster&lt;br /&gt;
* To use the database service on the existing Open-Xchange installation for Guard, no replication&lt;br /&gt;
* To provide a basic configuration setup, no mail server configuration&lt;br /&gt;
&lt;br /&gt;
=== Key Features ===&lt;br /&gt;
&lt;br /&gt;
* Simple security at the touch of a button&lt;br /&gt;
* Provides user based security - Separate from provider&lt;br /&gt;
* Supplementary security to Provider based security - Layered&lt;br /&gt;
* Powerful features yet simple to use and understand&lt;br /&gt;
* Security - Inside and outside of the OX environment&lt;br /&gt;
* Email and Drive integration&lt;br /&gt;
* Uses proven PGP security&lt;br /&gt;
&lt;br /&gt;
=== Availability ===&lt;br /&gt;
&lt;br /&gt;
If an OX App Suite customer would like to evaluate OX Guard integration, the first step is to contact OX Sales. OX Sales will then work on the request and send prices and license/API (for the hosted infrastructure) key details to the customer.&lt;br /&gt;
&lt;br /&gt;
=== Requirements ===&lt;br /&gt;
&lt;br /&gt;
Please review [https://oxpedia.org/wiki/index.php?title=AppSuite:OX_System_Requirements#OX_Guard OX Guard Requirements] for a full list of requirements.&lt;br /&gt;
&lt;br /&gt;
Since OX Guard is a Microservice it can either be added to an existing Open-Xchange installation or it can be deployed on a dedicated environment. The version of Guard installed is dependent on the Appsuite version installed.  Please refer to the version matrix below.&lt;br /&gt;
&lt;br /&gt;
==== Prerequisites ====&lt;br /&gt;
&lt;br /&gt;
* Open-Xchange REST API&lt;br /&gt;
* Grizzly HTTP connector (open-xchange-grizzly)&lt;br /&gt;
* A supported Java Virtual Machine (Java 8)&lt;br /&gt;
* An Open-Xchange App Suite installation (see version Matrix)&lt;br /&gt;
* Please Note: To get access to the latest minor features and bug fixes, you need to have a valid license. The article [https://oxpedia.org/wiki/index.php?title=AppSuite:UpdatingOXPackages Updating OX-Packages] explains how that can be done.&lt;br /&gt;
&lt;br /&gt;
==== Version Matrix ====&lt;br /&gt;
{|&lt;br /&gt;
! style=&amp;quot;text-align:left;&amp;quot;| Core Version&lt;br /&gt;
! Guard Version&lt;br /&gt;
|-&lt;br /&gt;
|7.8.1&lt;br /&gt;
|2.4.0 or 2.4.2&lt;br /&gt;
|-&lt;br /&gt;
|7.8.2&lt;br /&gt;
|2.4.2&lt;br /&gt;
|-&lt;br /&gt;
|7.8.3&lt;br /&gt;
|2.6.0&lt;br /&gt;
|-&lt;br /&gt;
|7.8.4&lt;br /&gt;
|2.8.0&lt;br /&gt;
|-&lt;br /&gt;
|7.10.0&lt;br /&gt;
|2.10.0&lt;br /&gt;
|-&lt;br /&gt;
|7.10.1&lt;br /&gt;
|2.10.1&lt;br /&gt;
|-&lt;br /&gt;
|7.10.2&lt;br /&gt;
|2.10.2&lt;br /&gt;
|-&lt;br /&gt;
|7.10.3&lt;br /&gt;
|2.10.3&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Important Notes ===&lt;br /&gt;
&lt;br /&gt;
==== Customisation ====&lt;br /&gt;
&lt;br /&gt;
OX Guard version supports branding / theming using the configuration cascade, defining a templateID for a user or context. Check the [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCustomization OX Guard Customisation] article for more details.&lt;br /&gt;
&lt;br /&gt;
==== Mail Resolver ====&lt;br /&gt;
&lt;br /&gt;
READ THIS VERY CAREFULLY; BEFORE PROCEEDING WITH GUARD INSTALLATION!&lt;br /&gt;
&lt;br /&gt;
The Guard installation must be able to determine if an email recipient is a local OX user or if it should be a guest account. The default MailResolver uses the context domain name to do this. On many installations, domains may extend across multiple context and multiple database shards. In these cases, the default MailResolver won&#039;t work. In addition, if a custom authentication package is used, the Mail Resolver will likely not work.&lt;br /&gt;
&lt;br /&gt;
Once Guard is installed, please be sure to test the mail resolver using:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;/opt/open-xchange/sbin/guard test email@domain&amp;lt;/source&amp;gt;&lt;br /&gt;
to see if the mail Resolver works.&lt;br /&gt;
&lt;br /&gt;
If the test does not work, you will likely need a custom Mail Resolver. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardMailResolver Mail Resolver] page&lt;br /&gt;
&lt;br /&gt;
This resolver software &#039;&#039;depends heavily on your local deployment&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Download and Installation ==&lt;br /&gt;
&lt;br /&gt;
=== General ===&lt;br /&gt;
&lt;br /&gt;
The installation of the &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; package which is required for Guard and the main &amp;lt;code&amp;gt;open-xchange-guard&amp;lt;/code&amp;gt; package in version 2.4.0 or higher will eventually execute database update tasks if installed and activated. Please take this into account.&lt;br /&gt;
&lt;br /&gt;
There are several components to the Guard service. They can be all installed on the same server as the OX middleware or on a separate server.&lt;br /&gt;
&lt;br /&gt;
The components required for the OX middleware are: &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
The components required for the OX frontend are: &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; and optionally &amp;lt;code&amp;gt;open-xchange-guard-help-en-us&amp;lt;/code&amp;gt; (or preferred language for help files).&lt;br /&gt;
&lt;br /&gt;
The components required for the Guard server &amp;lt;code&amp;gt;open-xchange-guard&amp;lt;/code&amp;gt; and either &amp;lt;code&amp;gt;open-xchange-guard-file-storage&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;open-xchange-guard-s3-storage&amp;lt;/code&amp;gt; depending on what storage you want to use. The examples below make use of the &amp;lt;code&amp;gt;open-xchange-guard-file-storage&amp;lt;/code&amp;gt;. Adjust the commands accordingly to fit your needs. In addition &amp;lt;code&amp;gt;open-xchange&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-core&amp;lt;/code&amp;gt; are required to run OX Guard.&lt;br /&gt;
&lt;br /&gt;
=== Debian Linux 9.0 (Stretch) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 deb https://software.open-xchange.com/products/guard/stable/guard/DebianStretch /&lt;br /&gt;
 deb https://software.open-xchange.com/products/appsuite/stable/backend/DebianStretch /&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== Debian Linux 10.0 (Buster) *Version 2.10.3+ only* ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 deb https://software.open-xchange.com/products/guard/stable/guard/DebianBuster /&lt;br /&gt;
 deb https://software.open-xchange.com/products/appsuite/stable/backend/DebianBuster /&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== RedHat Enterprise Linux 6 or CentOS 6 (valid until v2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/guard/2.10.3/guard/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/7.10.3/backend/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== Redhat Enterprise Linux 7 or CentOS 7 ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/guard/stable/guard/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/stable/backend/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== SUSE Linux Enterprise Server 12 (valid until 2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
Add the package repository using zypper if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ar https://software.open-xchange.com/products/guard/2.10.3/guard/SLE_12 guard-stable-guard&lt;br /&gt;
 $ zypper ar https://software.open-xchange.com/products/appsuite/7.10.3/backend/SLE_12 ox-backend&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&lt;br /&gt;
 $ zypper in open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static&lt;br /&gt;
&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&lt;br /&gt;
 $ zypper in open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== Univention Corporate Server ===&lt;br /&gt;
&lt;br /&gt;
If you have purchased the OX App Suite for UCS, the OX Guard is part of the offering. OX Guard is available in the Univention App Center. Please check the UMC module App Center for the installation of the OX Guard at your already available environment.&lt;br /&gt;
&lt;br /&gt;
Please note: By default, OX Guard generates the link to the secure content for external recipients on the basis of the local fully qualified domain name (FQDN). If the local FQDN is not reachable from the Internet, it has to be specified manually. This can be done by setting a UCR variable, e.g. via the UMC module &amp;amp;quot;Univention Configuration Registry&amp;amp;quot;. The variable has to contain the external FQDN of the OX Guard system:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;oxguard/cfg/guard.properties/com.openexchange.guard.externalEmailURL=HOSTNAME.DOMAINNAME&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Update OX Guard ==&lt;br /&gt;
&lt;br /&gt;
This section contains information about updating a 2.10.0 version (e.g. for patch fixes). Upgrading from prior versions is discussed in different articles.&lt;br /&gt;
&lt;br /&gt;
=== Debian Linux 9.0 (Stretch) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 deb &amp;lt;https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/stable/guard/updates/DebianStretch /&amp;gt;&lt;br /&gt;
 deb &amp;lt;https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/stable/backend/DebianStretch /&amp;lt;/source&amp;gt;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Then run:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get dist-upgrade&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If you want to see, what apt-get is going to do without actually doing it, you can run:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get dist-upgrade -s&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Redhat Enterprise Linux 6 or CentOS 6 (valid until 2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard-updates]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard-updates&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/2.10.3/guard/updates/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/7.10.3/backend/updates/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
and then run:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum upgrade&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Redhat Enterprise Linux 7 or CentOS 7 ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard-updates]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard-updates&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/stable/guard/updates/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/stable/backend/updates/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
and then run:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum upgrade&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== SUSE Linux Enterprise Server 12 (valid until 2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
Add the package repository using &amp;lt;code&amp;gt;zypper&amp;lt;/code&amp;gt; if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ar https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/2.10.3/guard/updates/SLE_12 guard-stable-guard-updates&lt;br /&gt;
 $ zypper ar https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/7.10.3/backend/updates/SLE_12 ox-backend&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
and then run:&lt;br /&gt;
&lt;br /&gt;
 $ zypper dup -r guard-stable-guard-backend-updates&lt;br /&gt;
 $ zypper dup -r guard-stable-guard-ui-updates&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You might need to run:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
to update the repository metadata before running &amp;lt;code&amp;gt;zypper&amp;lt;/code&amp;gt; up.&lt;br /&gt;
&lt;br /&gt;
=== Univention Corporate Server ===&lt;br /&gt;
&lt;br /&gt;
If you have purchased the OX App Suite for UCS, the OX Guard is part of the offering. OX Guard is available in the Univention App Center. Please check the UMC module App Center for the update of the OX Guard.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Configuration ==&lt;br /&gt;
&lt;br /&gt;
The following gives an overview of the most important settings to enable Guard for users on the Open-Xchange installation. Some of those settings have to be modified in order to establish the database and REST API access from the Guard service. All settings relating to the Guard backend component are located in the configuration file &amp;lt;code&amp;gt;guard-core.properties&amp;lt;/code&amp;gt; located in &amp;lt;code&amp;gt;/opt/open-xchange/etc&amp;lt;/code&amp;gt;. The default configuration should be sufficient for a basic &amp;amp;quot;up-and-running&amp;amp;quot; setup (with the exception of defining the database username and password). Please refer to the inline documentation of the configuration file for more advanced options. Additional information can be found in the [https://oxpedia.org/wiki/index.php?title=AppSuite:OX_Guard_Configuration_2_10 Guard Configuration] article.&lt;br /&gt;
&lt;br /&gt;
=== Basic Configuration ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/guard-core.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
Guard database for storing Guard user information, main lookup tables:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.oxguardDatabaseHostname=localhost&amp;lt;/source&amp;gt;&lt;br /&gt;
Guard database that stores keys for guest users. May be the same as above. New guest shards will be created on this database as needed. If not supplied, will use the &amp;lt;code&amp;gt;oxguardDatabaseHostname&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.oxguardShardDatabase=localhost&amp;lt;/source&amp;gt;&lt;br /&gt;
Username and Password for the databases above:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.databaseUsername=openexchange&lt;br /&gt;
com.openexchange.guard.databasePassword=db_password&amp;lt;/source&amp;gt;&lt;br /&gt;
Open-Xchange REST API host:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.restApiHostname=localhost&amp;lt;/source&amp;gt;&lt;br /&gt;
Open-Xchange REST API username and password (need to be defined in the OX backend in the &amp;amp;quot;Configure services&amp;amp;quot; below):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.restApiUsername=apiusername&lt;br /&gt;
com.openexchange.guard.restApiPassword=apipassword&amp;lt;/source&amp;gt;&lt;br /&gt;
External URL for this Open-Xchange installation. This setting will be used to generate the link to the secure content for external recipients:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.externalEmailURL=URL_TO_OX&amp;lt;/source&amp;gt;&lt;br /&gt;
=== Middleware Configuration on OX Guard node ===&lt;br /&gt;
&lt;br /&gt;
If you are installing OX Guard on a node that until yet did not host an Open-Xchange middleware you have to additionally configure some parts of the following properties files:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;configdb.properties&amp;lt;/code&amp;gt;: information about the existing configuration database.&lt;br /&gt;
* &amp;lt;code&amp;gt;server.properties&amp;lt;/code&amp;gt;: information about the connections have to be set.&lt;br /&gt;
* &amp;lt;code&amp;gt;system.properties&amp;lt;/code&amp;gt;: at least &amp;lt;code&amp;gt;SERVER_NAME&amp;lt;/code&amp;gt; should be set.&lt;br /&gt;
&lt;br /&gt;
=== Sevices Configuration ===&lt;br /&gt;
&lt;br /&gt;
==== Apache ====&lt;br /&gt;
&lt;br /&gt;
Configure the &amp;lt;code&amp;gt;mod_proxy_http&amp;lt;/code&amp;gt; module by adding the Guard API.&lt;br /&gt;
&lt;br /&gt;
===== Redhat Enterprise Linux 6 or CentOS 6 =====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /etc/httpd/conf.d/proxy_http.conf&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Debian GNU/Linux 9.0 =====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /etc/apache2/conf-enabled/proxy_http.conf&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;Proxy balancer://oxguard&amp;gt;&lt;br /&gt;
        Order deny,allow&lt;br /&gt;
        Allow from all&lt;br /&gt;
 &lt;br /&gt;
        BalancerMember http://localhost:8009/ timeout=1800 smax=0 ttl=60 retry=60 loadfactor=100 route=OX1&lt;br /&gt;
        ProxySet stickysession=JSESSIONID|jsessionid scolonpathdelim=ON&lt;br /&gt;
       SetEnv proxy-initial-not-pooled&lt;br /&gt;
        SetEnv proxy-sendchunked&lt;br /&gt;
 &amp;lt;/Proxy&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
 ProxyPass /appsuite/api/oxguard balancer://oxguard/oxguard&lt;br /&gt;
 ProxyPass /pks balancer://oxguard/pgp&lt;br /&gt;
 ProxyPass /.well-known/openpgpkey/hu balancer://oxguard/hu&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: The Guard API settings must be inserted &#039;&#039;&#039;&#039;&#039;before&#039;&#039;&#039;&#039;&#039; the existing &amp;lt;code&amp;gt;ProxyPass /appsuite/api&amp;lt;/code&amp;gt; parameter.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Also Note&#039;&#039;&#039;:  If you already have a Proxy balancer for the OX backend with the same URL (say http://localhost:8080) then you don&#039;t need the second BalancerMember entry, and you can just have the ProxyPass address that balancer instead.&lt;br /&gt;
&lt;br /&gt;
After the configuration is done, restart the Apache webserver&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ apachectl restart&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Open-Xchange Middleware Configuration ===&lt;br /&gt;
&lt;br /&gt;
Edit the &amp;lt;code&amp;gt;guard-api.properties&amp;lt;/code&amp;gt; configuration file for the OX backend where the guard-backend-plugin was installed. Please remove comments in front of the following settings to the configuration file &amp;lt;code&amp;gt;guard-api.properties&amp;lt;/code&amp;gt; on the Open-Xchange backend servers:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/guard-api.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;# OX Guard general permission, required to activate Guard in the AppSuite UI.&lt;br /&gt;
com.openexchange.capability.guard=true&lt;br /&gt;
&lt;br /&gt;
# Default theme template id for all users that have no custom template id configured.&lt;br /&gt;
com.openexchange.guard.templateID=0&amp;lt;/source&amp;gt;&lt;br /&gt;
Configure the API username and password that you assigned to Guard in the &amp;lt;code&amp;gt;server.properties&amp;lt;/code&amp;gt; file:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/server.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;# Specify the user name used for HTTP basic auth by internal REST servlet&lt;br /&gt;
com.openexchange.rest.services.basic-auth.login=apiusername&lt;br /&gt;
&lt;br /&gt;
# Specify the password used for HTTP basic auth by internal REST servlet&lt;br /&gt;
com.openexchange.rest.services.basic-auth.password=apipassword&amp;lt;/source&amp;gt;&lt;br /&gt;
Finally, the OX backend needs to know where the Guard server is located. This is used to notify the Guard server of changes in users, and to send emails marked for signature. The URL for the Guard server should include the URL suffix &amp;lt;code&amp;gt;/guardadmin&amp;lt;/code&amp;gt;. In the event of a cluster setup, any Guard server can be referenced here, as it is not session specific, though ideally would have a HTTP load balancer/failover URL:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/guard-api.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;# Specifies the URI to the OX Guard end-point; e.g. http://guard.host.invalid:8081/guardadmin&lt;br /&gt;
# Default is empty&lt;br /&gt;
com.openexchange.guard.endpoint=http://guardserver:8009/guardadmin&amp;lt;/source&amp;gt;&lt;br /&gt;
Restart the OX backend&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /etc/init.d/open-xchange restart&amp;lt;/source&amp;gt;&lt;br /&gt;
==== SELinux ====&lt;br /&gt;
&lt;br /&gt;
Running SELinux prohibits your local Open-Xchange backend service to connect to localhost:8009, which is where the Guard backend service listens to. In order to allow localhost connections to 8009 execute the following:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ setsebool -P httpd_can_network_connect 1&amp;lt;/source&amp;gt;&lt;br /&gt;
=== Generating the &amp;lt;code&amp;gt;oxguardpass&amp;lt;/code&amp;gt; ===&lt;br /&gt;
&lt;br /&gt;
Once the Guard configuration (database and backend configuration) and the service configuration has been applied, the Guard administration script needs to be executed in order to create the master password file in &amp;lt;code&amp;gt;/opt/open-xchange/etc/oxguardpass&amp;lt;/code&amp;gt;. The initiation only needs to be done &#039;&#039;&#039;once&#039;&#039;&#039; for a multi server setup, for details please see the sections &#039;&#039;&#039;Optional&#039;&#039;&#039; and/or &#039;&#039;&#039;Clustering&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: If you run a cluster of OX / Guard nodes, only execute this command on &#039;&#039;&#039;ONE&#039;&#039;&#039; node. Not on all nodes! See [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCluster OX Guard Clustering] for details.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /opt/open-xchange/sbin/guard --init&amp;lt;/source&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: It is important to understand that the master password file located at &amp;lt;code&amp;gt;/opt/open-xchange/etc/oxguardpass&amp;lt;/code&amp;gt; is required to reset user passwords; without them the administrator will not be able to reset user passwords anymore in the future. The file contains the passwords used to encrypt the master database key, as well as passwords used to encrypt protected data in the users table. It must be the same on all Guard servers.&lt;br /&gt;
&lt;br /&gt;
=== Test Setup ===&lt;br /&gt;
&lt;br /&gt;
Not required, but it is a good idea to test the Guard setup before enabling for any users. The test function will verify that Guard has a good connection to the OX backend, and that it can resolve email addresses to users.&lt;br /&gt;
&lt;br /&gt;
To test, use an email address that exists on the OX backend (john@example.com for this example)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;/opt/open-xchange/sbin/guard --test john@example.com&amp;lt;/source&amp;gt;&lt;br /&gt;
Guard should return information from the OX backend regarding the user associated with &amp;amp;quot;john@example.com&amp;amp;quot;. Problems resolving information for the user should be resolved before using Guard. Check Rest API passwords and settings if errors returned.&lt;br /&gt;
&lt;br /&gt;
=== Enabling Guard for Users ===&lt;br /&gt;
&lt;br /&gt;
Guard provides two capabilities for users in the environment as well as a basic &amp;amp;quot;core&amp;amp;quot; level:&lt;br /&gt;
&lt;br /&gt;
* Guard: &amp;lt;code&amp;gt;com.openexchange.capability.guard&amp;lt;/code&amp;gt;&lt;br /&gt;
* Guard Mail: &amp;lt;code&amp;gt;com.openexchange.capability.guard-mail&amp;lt;/code&amp;gt;&lt;br /&gt;
* Guard Drive: &amp;lt;code&amp;gt;com.openexchange.capability.guard-drive&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The &amp;amp;quot;core&amp;amp;quot; Guard enabled a basic read functionality for Guard encrypted emails. We recommend enabling this for all users, as this allows all recipients to read Guard emails sent to them. Great opportunity for upsell. Recipients with only Guard enabled can then do a secure reply to the sender, but they can&#039;t start a new email or add recipients.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Guard Mail&#039;&#039;&#039; and &#039;&#039;&#039;Guard Drive&#039;&#039;&#039; are additional options for users. &amp;amp;quot;Guard Mail&amp;amp;quot; allows users the full functionality of Guard emails. &amp;amp;quot;Guard Drive&amp;amp;quot; allows for encryption and decryption of drive files.&lt;br /&gt;
&lt;br /&gt;
Each of those two Guard components is enabled for all users that have the according capability configured. Please note that users need to have the Drive permission set to use Guard Drive. So the users that have Guard Drive enabled must be a subset of those users with OX Drive permission. Since v7.6.0 we enforce this via the default configuration. Those capabilities can be activated for specific user by using the Open-Xchange provisioning scripts:&lt;br /&gt;
&lt;br /&gt;
==== Guard Mail: ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /opt/open-xchange/sbin/changeuser -c 1 -A oxadmin -P admin_password -u testuser --config/com.openexchange.capability.guard-mail=true&amp;lt;/source&amp;gt;&lt;br /&gt;
==== Guard Drive: ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /opt/open-xchange/sbin/changeuser -c 1 -A oxadmin -P admin_password -u testuser --config/com.openexchange.capability.guard-drive=true&amp;lt;/source&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: Guard Drive requires Guard Mail to be configured for the user as well. In addition, these capabilities may be configured globally by editing the &amp;lt;code&amp;gt;guard-api.properties&amp;lt;/code&amp;gt; file on the OX backend.&lt;br /&gt;
&lt;br /&gt;
=== External Guest recipients: ===&lt;br /&gt;
Starting in Guard 2.10.0, when an encrypted email is sent to a user that does not have Guard, a guest account is created for them in appsuite.  The recipient uses the Guest account to read the encrypted email.  These guest users MUST have guard capabilities.  To do this, guard capability must be added to guest accounts.&lt;br /&gt;
&amp;lt;code&amp;gt;/opt/open-xchange/etc/share.properties&amp;lt;/code&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.share.guestCapabilityMode=static&lt;br /&gt;
com.openexchange.share.staticGuestCapabilities=guard&amp;lt;/source&amp;gt;&lt;br /&gt;
In a distributed system, the Guest accounts should not be considered transient.  Guard servers must be able to verify the guest account exists in the session storage services.&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.share.transientSessions=false&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Guest Storage ===&lt;br /&gt;
When an encrypted email is sent to an external Guest, a copy of the fully encrypted email is stored on the server.  This is used to create an inbox of encrypted emails for the guest.  By entering in a password, the emails can be decrypted and displayed.&lt;br /&gt;
&lt;br /&gt;
How these files are stored depend on which package, open-xchange-guard-file-storage or open-xchange-guard-s3-storage, was installed.&lt;br /&gt;
&lt;br /&gt;
The file retention policy is configured in the guard-core.properties file.&lt;br /&gt;
&lt;br /&gt;
=== Recipient key detection ===&lt;br /&gt;
&lt;br /&gt;
==== Local ====&lt;br /&gt;
&lt;br /&gt;
Guard needs to determine if an email recipients email address is an internal or external (non-ox) user.&lt;br /&gt;
&lt;br /&gt;
To detect if the recipient is an account on the same OX Guard system there is a mechanism needed to map a recipient mail address to the correct local OX context. The default implementation delivered in the product achieves that by looking up the mail domain (@example.com) within the list of context mappings. That is at least not possible in case of ISPs where different users/contexts use the same mail domain. In case your OX system does not use mail domains in context mappings it is required to deploy an OX OSGi bundle implementing the &amp;lt;code&amp;gt;com.openexchange.mailmapping.MailResolver&amp;lt;/code&amp;gt; class or by interfacing Guard with your mail resolver system. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardMailResolver OX Guard Mail Resolver] for details.&lt;br /&gt;
&lt;br /&gt;
==== External ====&lt;br /&gt;
&lt;br /&gt;
Starting with Guard 2.0, Guard will use public PGP Key servers if configured to find PGP Public keys. In addition, Guard will also look up SRV records for PGP Key servers for a recipients domain. This follows the standards [http://tools.ietf.org/html/draft-shaw-openpgp-hkp-00#page-9 OpenPGP Draft].&lt;br /&gt;
&lt;br /&gt;
External PGP servers to use can be configured in the guard.properties file on the Guard servers.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.publicPGPDirectory = hkp://keys.gnupg.net:11371, hkp://pgp.mit.edu:11371&amp;lt;/source&amp;gt;&lt;br /&gt;
If you would like this Guard installation discoverable by other Guard servers, then create an SRV record for each domain (&amp;amp;quot;example.com&amp;amp;quot; in this illustration):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;_hkp._tcp.example.com. 28800 IN    SRV     10 1 80 appsuite.example.com.&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039; PGP Public key servers by default append use the URL server/pks when the record is obtained from an SRV record. The proxy above routes anything with the Apache domain/pks to the OX Guard PGP server.&lt;br /&gt;
&lt;br /&gt;
Guard keys are also discoverable using the webkey service as specified here: https://tools.ietf.org/html/draft-koch-openpgp-webkey-service-02&lt;br /&gt;
This is enabled if you include the &lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;ProxyPass /.well-known/openpgpkey/hu balancer://oxguard/hu&amp;lt;/source&amp;gt;&lt;br /&gt;
in the proxy_http.conf as above.&lt;br /&gt;
Please note that the well-known request is targeted on the domain part of the mail adress. Therefore clients will request for a mail address name@example.com the URI https://example.com/.well-known/openpgpkey/hu/...&lt;br /&gt;
&lt;br /&gt;
That means that there is the likely need that some sort of proxying or rewriting from the webserver providing the domain needs to happen. For example for proxying using Apache 2.4 it would roughly look like this:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
SSLProxyEngine on&lt;br /&gt;
&amp;lt;LocationMatch /.well-known/openpgpkey/&amp;gt;&lt;br /&gt;
    ProxyPass https://ox.example.com/.well-known/openpgpkey/&lt;br /&gt;
&amp;lt;/LocationMatch&amp;gt;&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Clustering ===&lt;br /&gt;
&lt;br /&gt;
You can run multiple OX Guard servers in your environment to ensure high availability or enhance scalability. OX Guard integrates seamlessly into the existing Open-Xchange infrastructure by using the existing interface standards and is therefor transparent to the environment. A couple of things have to be prepared in order to loosely couple OX Guard servers with Open-Xchange servers in a cluster.&lt;br /&gt;
&lt;br /&gt;
==== MySQL ====&lt;br /&gt;
&lt;br /&gt;
The MySQL servers need to be configured in order to allow access to the configdb of Open-Xchange. To do so you need to set the following configuration in the MySQL &amp;lt;code&amp;gt;my.cnf&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;bind = 0.0.0.0&amp;lt;/source&amp;gt;&lt;br /&gt;
This allows the Guard backend to bind to the MySQL host which is configured in the &amp;lt;code&amp;gt;guard-core.properties&amp;lt;/code&amp;gt; file with &amp;lt;code&amp;gt;com.openexchange.guard.configdbHostname&amp;lt;/code&amp;gt;. After the bind for the MySQL instance is configured and the OX Guard backend would be able to connect to the configured host, you have to grant access for the OX Guard service on the MySQL instance to manage the databases. Do so by connecting to the MySQL server via the MySQL client. Authenticate if necessary and execute the following, please note that you have to modify the hostname / IP address of the client who should be able to connect to this database, it should include all possible OX Guard servers:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;sql&amp;quot;&amp;gt;GRANT ALL PRIVILEGES ON *.* TO &#039;openexchange&#039;@&#039;oxguard.example.com&#039; IDENTIFIED BY ‘secret’;&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Apache ====&lt;br /&gt;
&lt;br /&gt;
OX Guard uses the Open-Xchange REST API to store and fetch data from the Open-Xchange databases. The REST API is a servlet running in the Grizzly container. By default it is not exposed as a servlet through Apache and is only accessibly via port 8009. In order to use Apache&#039;s load balancing via &amp;lt;code&amp;gt;mod_proxy&amp;lt;/code&amp;gt; we need to add a servlet called &amp;amp;quot;preliminary&amp;amp;quot; to &amp;lt;code&amp;gt;proxy_http.conf&amp;lt;/code&amp;gt;, example based on a clustered &amp;lt;code&amp;gt;mod_proxy&amp;lt;/code&amp;gt;configuration:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;Location /preliminary&amp;gt;&lt;br /&gt;
      Order Deny,Allow&lt;br /&gt;
      Deny from all&lt;br /&gt;
      # Only allow access from Guard servers within the network. Do not expose this&lt;br /&gt;
      # location outside of your network. In case you use a load balancing service in front&lt;br /&gt;
      # of your Apache infrastructure you should make sure that access to /preliminary will&lt;br /&gt;
      # be blocked from the Internet / outside clients. Examples:&lt;br /&gt;
      # Allow from 192.168.0.1&lt;br /&gt;
      # Allow from 192.168.1.1 192.168.1.2&lt;br /&gt;
      # Allow from 192.168.0.&lt;br /&gt;
 &amp;lt;/Location&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
 ProxyPass /preliminary balancer://oxcluster/preliminary&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Make sure that the balancer is properly configured in the &amp;lt;code&amp;gt;mod_proxy&amp;lt;/code&amp;gt; configuration. Examples on how to do so can be found in our clustering configuration for Open-Xchange AppSuite. Like explained in the example above, please make sure that this location is only available in your internal network, there is no need to expose &amp;lt;code&amp;gt;/preliminary&amp;lt;/code&amp;gt; to the public, it is only used by Guard servers to connect to the OX backend. If you have a load balancer in front of the Apache cluster you should consider blocking access to &amp;lt;code&amp;gt;/preliminary&amp;lt;/code&amp;gt; from WAN to restrict access to the servlet to internal network services only.&lt;br /&gt;
&lt;br /&gt;
Now add the OX Guard &amp;lt;code&amp;gt;BalancerMembers&amp;lt;/code&amp;gt; to the oxguard balancer configuration (also in &amp;lt;code&amp;gt;proxy_http.conf&amp;lt;/code&amp;gt;) to address all your OX Guard nodes in the cluster in this balancer configuration. The configuration has to be applied to all Apache nodes within the cluster.&lt;br /&gt;
&lt;br /&gt;
If the Apache server is a dedicated server &amp;lt;code&amp;gt;/&amp;lt;/code&amp;gt; instance you also have to install the OX Guard UI-Static package on all Apache nodes in the cluster in order to provide static files like images or CSS to the OX Guard client. Example for Debian (the OX Guard repository has to be configured in the package management prior):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ apt-get install open-xchange-guard-ui-static&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Open-Xchange ====&lt;br /&gt;
&lt;br /&gt;
Disable the Open-Xchange IPCheck for session verification. This is required because OX Guard will use the users session cookie to connect to the Open-Xchange REST API, but as a different IP address than the OX Guard server has been used during authentication the request would fail if you don&#039;t disable the IPCheck:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/server.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
and set:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.IPCheck=false&amp;lt;/source&amp;gt;&lt;br /&gt;
The OX Guard UI package has to be installed on all Open-Xchange backend nodes as well, example for Debian (the OX Guard repository has to be configured in the package management prior):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ apt-get install open-xchange-guard-ui&amp;lt;/source&amp;gt;&lt;br /&gt;
Restart the Open-Xchange service afterwards.&lt;br /&gt;
&lt;br /&gt;
==== OX Guard ====&lt;br /&gt;
&lt;br /&gt;
For details in clustering Guard servers, please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCluster OX Guard Clustering]. It is &#039;&#039;&#039;critical&#039;&#039;&#039; that all Guard servers have the same &amp;lt;code&amp;gt;oxguardpass&amp;lt;/code&amp;gt; file. Please see the clustering link for details. Do not run &amp;lt;code&amp;gt;/opt/open-xchange/sbin/guard --init&amp;lt;/code&amp;gt; on more than one server.&lt;br /&gt;
&lt;br /&gt;
After all the services like MySQL, Apache and Open-Xchange have been configured you need to update the OX Guard backend configuration to point to the correct API endpoints. Set the REST API endpoint to an Apache server by setting the following value in &amp;lt;code&amp;gt;/opt/open-xchange/etc/guard-core.properties&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.restApiHostname=apache.example.com&amp;lt;/source&amp;gt;&lt;br /&gt;
Per default Guard will try to connect to port 8009 to this host, but as we configured the REST API to be proxies thorugh the servlet &amp;lt;code&amp;gt;/preliminary&amp;lt;/code&amp;gt; on every Apache we now also need to change the target port for the REST API. You can do so by adding the following line into &amp;lt;code&amp;gt;/opt/open-xchange/etc/guard-core.properties&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.oxBackendPort=80&amp;lt;/source&amp;gt;&lt;br /&gt;
Please also change all settings in regards to MySQL like &amp;lt;code&amp;gt;com.openexchange.guard.configdbHostname&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;com.openexchange.guard.oxguardDatabaseHostname&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;com.openexchange.guard.databaseUsername&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;om.openexchange.guard.databasePassword&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Afterwards restart the OX Guard service and check the log file if the OX Guard backend is able to connect to the configured REST API.&lt;br /&gt;
&lt;br /&gt;
=== Multi Node ===&lt;br /&gt;
&lt;br /&gt;
If you have multiple OX and Guard installations, please see the following documentation [https://oxpedia.org/wiki/index.php?title=AppSuite:OX_Guard_Modular OX Guard Modular Setup].&lt;br /&gt;
&lt;br /&gt;
=== Mail Filter Integration (2.10.4+) ===&lt;br /&gt;
&lt;br /&gt;
To add additional mail filter tests (verify PGP signature, or encrypt incoming), please see&lt;br /&gt;
[[AppSuite:OX_Guard_MailFilter | MailFilter Integration]]&lt;br /&gt;
&lt;br /&gt;
== Support API ==&lt;br /&gt;
&lt;br /&gt;
The OX Guard Support API enables administrative access to various functions for maintaining OX Guard from a client in a role as a support employee. A client has to do a BASIC AUTH authentication in order to access the API. Username and password can be configured in the guard-core.properties file using the following settings:&lt;br /&gt;
&lt;br /&gt;
 # Specify the username and password for accessing the Support API of Guard&lt;br /&gt;
 com.openexchange.guard.supportApiUsername=&lt;br /&gt;
 com.openexchange.guard.supportApiPassword=&lt;br /&gt;
&lt;br /&gt;
In contrast to the rest of the OX Guard requests, the OX Guard support API requests are accessible using: /guardsupport. This distinction allows more flexible configuration since the support API should not always be accessible from everywhere. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Warning&#039;&#039;&#039;: Exposing the support API to the internet could be huge security risk. Only add to Apache if you know what you are doing.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Reset password ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=reset_password&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Performs a password reset and sends a new random generated password to a specified email address by the user or a default address if the user did not specify an email address. (&#039;&#039;Since Guard 2.0&#039;&#039;)&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;email&amp;lt;/code&amp;gt; – The email address of the user to reset the password for&lt;br /&gt;
* &amp;lt;code&amp;gt;default&amp;lt;/code&amp;gt; (optional) – The email address to send the new password to, if the user did not specify a secondary email address&lt;br /&gt;
&lt;br /&gt;
Response:&lt;br /&gt;
PRIMARY if the reset was sent to the primary email address.  SECONDARY if the reset email was sent to the secondary email address that the user specified&lt;br /&gt;
&lt;br /&gt;
=== Expose key ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=expose_key&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Marks a deleted user key temporary as “exposed” and creates a unique URL for downloading the exposed key. Automatic resetting of exposed keys to &amp;amp;quot;not exposed&amp;amp;quot; is scheduled once a day and resets all exposed keys which have been exposed before X hours, where X can be configured using com.openexchange.guard.exposedKeyDurationInHours in the guard.properties files. (&#039;&#039;Since Guard 2.0&#039;&#039;)&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;email&amp;lt;/code&amp;gt; – The email address of the user to expose the deleted keys for&lt;br /&gt;
* &amp;lt;code&amp;gt;cid&amp;lt;/code&amp;gt; – The context id&lt;br /&gt;
&lt;br /&gt;
Response: A URL pointing to the downloadable exposed keys.&lt;br /&gt;
&lt;br /&gt;
=== Delete user ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=delete_user&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deletes all keys related to a certain user. The keys are backed up and can be exposed using the “expose_key” call. (&#039;&#039;Since Guard 2.0&#039;&#039;)&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;user_id&amp;lt;/code&amp;gt; – The user&#039;s id&lt;br /&gt;
* &amp;lt;code&amp;gt;cid&amp;lt;/code&amp;gt; - The context id&lt;br /&gt;
&lt;br /&gt;
=== Upgrade User (Release 2.10 and later) ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=upgrade_guest&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Upgrades a Guest account.  This action copies all of the keys from the Guest account to a full OX account, assuming that user has Guard capabilities.&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;email&amp;lt;/code&amp;gt; - The email address of the Guest user&lt;br /&gt;
* &amp;lt;code&amp;gt;user_id&amp;lt;/code&amp;gt; – The user&#039;s new id&lt;br /&gt;
* &amp;lt;code&amp;gt;cid&amp;lt;/code&amp;gt; - The user&#039;s new context id&lt;br /&gt;
&lt;br /&gt;
== Customisation ==&lt;br /&gt;
&lt;br /&gt;
Guard&#039;s templates are customisable at the user and context level. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCustomization Customisation] for details.&lt;br /&gt;
&lt;br /&gt;
== Entropy ==&lt;br /&gt;
&lt;br /&gt;
Guard requires entropy (randomness) to generate the private/public keys that are used. Depending on the server and it&#039;s environment, this may become a problem. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardEntropy Entropy] for a possible solution.&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:OX_Guard&amp;diff=25594</id>
		<title>AppSuite:OX Guard</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:OX_Guard&amp;diff=25594"/>
		<updated>2020-09-12T08:15:38Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: /* External */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= OX Guard (Version 2.10) =&lt;br /&gt;
&lt;br /&gt;
For previous versions of OX Guard, please click here&lt;br /&gt;
* [[AppSuite:OX_Guard_2-0 | Installation and information of OX Guard 2.0 - 2.2]]&lt;br /&gt;
* [[Appsuite:OX_Guard_2_8 | Installation and information of OX Guard 2.4 - 2.8]]&lt;br /&gt;
&lt;br /&gt;
If upgrading from 2.6 or 2.8, please see&lt;br /&gt;
* [[Appsuite:OX_Guard_Upgrade_2_10|Upgrading to 2.10]]&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
&lt;br /&gt;
OX Guard is a fully integrated security add-on to OX App Suite that provides end users with a flexible email and file encryption solution. OX Guard is a highly scalable, multi server, feature rich solution that is so simple-to-use that end users will actually use it. With a single click a user can take control of their security and send secure emails and share encrypted files. This can be done from any device to both OX App Suite and non-OX App Suite users.&lt;br /&gt;
&lt;br /&gt;
OX Guard uses standard PGP encryption for the encryption of email and files. PGP has been around for a long time, yet has not really caught on with the masses. This is generally blamed on the confusion and complications of managing the keys, understanding trust, PGP format types, and lack of trusted central key repositories. Guard simplifies all of this, making PGP encryption as easy as a one click process, with no keys to keep track of, yet the options of advanced PGP management for those that know how.&lt;br /&gt;
&lt;br /&gt;
This article will guide you through the installation of Guard and describes the basic configuration and software requirements. As it is intended as a quick walk-through it assumes an existing installation of the operating system including a single server App Suite setup as well as average system administration skills. This guide will also show you how to setup a basic installation with none of the typically used distributed environment settings. The objective of this guide is:&lt;br /&gt;
&lt;br /&gt;
* To setup a single server installation&lt;br /&gt;
* To setup a single Guard instance on an existing Open-Xchange installation, no cluster&lt;br /&gt;
* To use the database service on the existing Open-Xchange installation for Guard, no replication&lt;br /&gt;
* To provide a basic configuration setup, no mail server configuration&lt;br /&gt;
&lt;br /&gt;
=== Key Features ===&lt;br /&gt;
&lt;br /&gt;
* Simple security at the touch of a button&lt;br /&gt;
* Provides user based security - Separate from provider&lt;br /&gt;
* Supplementary security to Provider based security - Layered&lt;br /&gt;
* Powerful features yet simple to use and understand&lt;br /&gt;
* Security - Inside and outside of the OX environment&lt;br /&gt;
* Email and Drive integration&lt;br /&gt;
* Uses proven PGP security&lt;br /&gt;
&lt;br /&gt;
=== Availability ===&lt;br /&gt;
&lt;br /&gt;
If an OX App Suite customer would like to evaluate OX Guard integration, the first step is to contact OX Sales. OX Sales will then work on the request and send prices and license/API (for the hosted infrastructure) key details to the customer.&lt;br /&gt;
&lt;br /&gt;
=== Requirements ===&lt;br /&gt;
&lt;br /&gt;
Please review [https://oxpedia.org/wiki/index.php?title=AppSuite:OX_System_Requirements#OX_Guard OX Guard Requirements] for a full list of requirements.&lt;br /&gt;
&lt;br /&gt;
Since OX Guard is a Microservice it can either be added to an existing Open-Xchange installation or it can be deployed on a dedicated environment. The version of Guard installed is dependent on the Appsuite version installed.  Please refer to the version matrix below.&lt;br /&gt;
&lt;br /&gt;
==== Prerequisites ====&lt;br /&gt;
&lt;br /&gt;
* Open-Xchange REST API&lt;br /&gt;
* Grizzly HTTP connector (open-xchange-grizzly)&lt;br /&gt;
* A supported Java Virtual Machine (Java 8)&lt;br /&gt;
* An Open-Xchange App Suite installation (see version Matrix)&lt;br /&gt;
* Please Note: To get access to the latest minor features and bug fixes, you need to have a valid license. The article [https://oxpedia.org/wiki/index.php?title=AppSuite:UpdatingOXPackages Updating OX-Packages] explains how that can be done.&lt;br /&gt;
&lt;br /&gt;
==== Version Matrix ====&lt;br /&gt;
{|&lt;br /&gt;
! style=&amp;quot;text-align:left;&amp;quot;| Core Version&lt;br /&gt;
! Guard Version&lt;br /&gt;
|-&lt;br /&gt;
|7.8.1&lt;br /&gt;
|2.4.0 or 2.4.2&lt;br /&gt;
|-&lt;br /&gt;
|7.8.2&lt;br /&gt;
|2.4.2&lt;br /&gt;
|-&lt;br /&gt;
|7.8.3&lt;br /&gt;
|2.6.0&lt;br /&gt;
|-&lt;br /&gt;
|7.8.4&lt;br /&gt;
|2.8.0&lt;br /&gt;
|-&lt;br /&gt;
|7.10.0&lt;br /&gt;
|2.10.0&lt;br /&gt;
|-&lt;br /&gt;
|7.10.1&lt;br /&gt;
|2.10.1&lt;br /&gt;
|-&lt;br /&gt;
|7.10.2&lt;br /&gt;
|2.10.2&lt;br /&gt;
|-&lt;br /&gt;
|7.10.3&lt;br /&gt;
|2.10.3&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Important Notes ===&lt;br /&gt;
&lt;br /&gt;
==== Customisation ====&lt;br /&gt;
&lt;br /&gt;
OX Guard version supports branding / theming using the configuration cascade, defining a templateID for a user or context. Check the [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCustomization OX Guard Customisation] article for more details.&lt;br /&gt;
&lt;br /&gt;
==== Mail Resolver ====&lt;br /&gt;
&lt;br /&gt;
READ THIS VERY CAREFULLY; BEFORE PROCEEDING WITH GUARD INSTALLATION!&lt;br /&gt;
&lt;br /&gt;
The Guard installation must be able to determine if an email recipient is a local OX user or if it should be a guest account. The default MailResolver uses the context domain name to do this. On many installations, domains may extend across multiple context and multiple database shards. In these cases, the default MailResolver won&#039;t work. In addition, if a custom authentication package is used, the Mail Resolver will likely not work.&lt;br /&gt;
&lt;br /&gt;
Once Guard is installed, please be sure to test the mail resolver using:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;/opt/open-xchange/sbin/guard test email@domain&amp;lt;/source&amp;gt;&lt;br /&gt;
to see if the mail Resolver works.&lt;br /&gt;
&lt;br /&gt;
If the test does not work, you will likely need a custom Mail Resolver. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardMailResolver Mail Resolver] page&lt;br /&gt;
&lt;br /&gt;
This resolver software &#039;&#039;depends heavily on your local deployment&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Download and Installation ==&lt;br /&gt;
&lt;br /&gt;
=== General ===&lt;br /&gt;
&lt;br /&gt;
The installation of the &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; package which is required for Guard and the main &amp;lt;code&amp;gt;open-xchange-guard&amp;lt;/code&amp;gt; package in version 2.4.0 or higher will eventually execute database update tasks if installed and activated. Please take this into account.&lt;br /&gt;
&lt;br /&gt;
There are several components to the Guard service. They can be all installed on the same server as the OX middleware or on a separate server.&lt;br /&gt;
&lt;br /&gt;
The components required for the OX middleware are: &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
The components required for the OX frontend are: &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; and optionally &amp;lt;code&amp;gt;open-xchange-guard-help-en-us&amp;lt;/code&amp;gt; (or preferred language for help files).&lt;br /&gt;
&lt;br /&gt;
The components required for the Guard server &amp;lt;code&amp;gt;open-xchange-guard&amp;lt;/code&amp;gt; and either &amp;lt;code&amp;gt;open-xchange-guard-file-storage&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;open-xchange-guard-s3-storage&amp;lt;/code&amp;gt; depending on what storage you want to use. The examples below make use of the &amp;lt;code&amp;gt;open-xchange-guard-file-storage&amp;lt;/code&amp;gt;. Adjust the commands accordingly to fit your needs. In addition &amp;lt;code&amp;gt;open-xchange&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-core&amp;lt;/code&amp;gt; are required to run OX Guard.&lt;br /&gt;
&lt;br /&gt;
=== Debian Linux 9.0 (Stretch) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 deb https://software.open-xchange.com/products/guard/stable/guard/DebianStretch /&lt;br /&gt;
 deb https://software.open-xchange.com/products/appsuite/stable/backend/DebianStretch /&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== Debian Linux 10.0 (Buster) *Version 2.10.3+ only* ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 deb https://software.open-xchange.com/products/guard/stable/guard/DebianBuster /&lt;br /&gt;
 deb https://software.open-xchange.com/products/appsuite/stable/backend/DebianBuster /&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== RedHat Enterprise Linux 6 or CentOS 6 (valid until v2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/guard/2.10.3/guard/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/7.10.3/backend/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== Redhat Enterprise Linux 7 or CentOS 7 ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/guard/stable/guard/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/stable/backend/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static open-xchange-guard-backend-plugin&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== SUSE Linux Enterprise Server 12 (valid until 2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
Add the package repository using zypper if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ar https://software.open-xchange.com/products/guard/2.10.3/guard/SLE_12 guard-stable-guard&lt;br /&gt;
 $ zypper ar https://software.open-xchange.com/products/appsuite/7.10.3/backend/SLE_12 ox-backend&lt;br /&gt;
&lt;br /&gt;
and then run for a single node installation:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&lt;br /&gt;
 $ zypper in open-xchange-rest open-xchange-guard open-xchange-guard-file-storage open-xchange-guard-ui open-xchange-guard-ui-static&lt;br /&gt;
&lt;br /&gt;
or the following for a distributed installation:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&lt;br /&gt;
 $ zypper in open-xchange-guard open-xchange-guard-file-storage&lt;br /&gt;
&lt;br /&gt;
The packages &amp;lt;code&amp;gt;open-xchange-guard-ui&amp;lt;/code&amp;gt; &amp;lt;code&amp;gt;open-xchange-rest&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; missing in the distributed installation have to be installed on the node running the middleware.  The package &amp;lt;code&amp;gt;open-xchange-guard-ui-static&amp;lt;/code&amp;gt; must be installed in the frontend (apache node).&lt;br /&gt;
&lt;br /&gt;
=== Univention Corporate Server ===&lt;br /&gt;
&lt;br /&gt;
If you have purchased the OX App Suite for UCS, the OX Guard is part of the offering. OX Guard is available in the Univention App Center. Please check the UMC module App Center for the installation of the OX Guard at your already available environment.&lt;br /&gt;
&lt;br /&gt;
Please note: By default, OX Guard generates the link to the secure content for external recipients on the basis of the local fully qualified domain name (FQDN). If the local FQDN is not reachable from the Internet, it has to be specified manually. This can be done by setting a UCR variable, e.g. via the UMC module &amp;amp;quot;Univention Configuration Registry&amp;amp;quot;. The variable has to contain the external FQDN of the OX Guard system:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;oxguard/cfg/guard.properties/com.openexchange.guard.externalEmailURL=HOSTNAME.DOMAINNAME&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Update OX Guard ==&lt;br /&gt;
&lt;br /&gt;
This section contains information about updating a 2.10.0 version (e.g. for patch fixes). Upgrading from prior versions is discussed in different articles.&lt;br /&gt;
&lt;br /&gt;
=== Debian Linux 9.0 (Stretch) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange apt configuration:&lt;br /&gt;
&lt;br /&gt;
 deb &amp;lt;https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/stable/guard/updates/DebianStretch /&amp;gt;&lt;br /&gt;
 deb &amp;lt;https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/stable/backend/DebianStretch /&amp;lt;/source&amp;gt;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Then run:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get dist-upgrade&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If you want to see, what apt-get is going to do without actually doing it, you can run:&lt;br /&gt;
&lt;br /&gt;
 $ apt-get dist-upgrade -s&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Redhat Enterprise Linux 6 or CentOS 6 (valid until 2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard-updates]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard-updates&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/2.10.3/guard/updates/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/7.10.3/backend/updates/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
and then run:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum upgrade&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Redhat Enterprise Linux 7 or CentOS 7 ===&lt;br /&gt;
&lt;br /&gt;
If not already done, add the following repositories to your Open-Xchange yum configuration:&lt;br /&gt;
&lt;br /&gt;
 [open-xchange-guard-stable-guard-updates]&lt;br /&gt;
 name=Open-Xchange-guard-stable-guard-updates&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/stable/guard/updates/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 [ox-backend]&lt;br /&gt;
 name=Open-Xchange-backend&lt;br /&gt;
 baseurl=https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/stable/backend/updates/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
and then run:&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum upgrade&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== SUSE Linux Enterprise Server 12 (valid until 2.10.3) ===&lt;br /&gt;
&lt;br /&gt;
Add the package repository using &amp;lt;code&amp;gt;zypper&amp;lt;/code&amp;gt; if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ar https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/guard/2.10.3/guard/updates/SLE_12 guard-stable-guard-updates&lt;br /&gt;
 $ zypper ar https://LDBUSER:LDBPASSWORD@software.open-xchange.com/products/appsuite/7.10.3/backend/updates/SLE_12 ox-backend&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
and then run:&lt;br /&gt;
&lt;br /&gt;
 $ zypper dup -r guard-stable-guard-backend-updates&lt;br /&gt;
 $ zypper dup -r guard-stable-guard-ui-updates&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You might need to run:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
to update the repository metadata before running &amp;lt;code&amp;gt;zypper&amp;lt;/code&amp;gt; up.&lt;br /&gt;
&lt;br /&gt;
=== Univention Corporate Server ===&lt;br /&gt;
&lt;br /&gt;
If you have purchased the OX App Suite for UCS, the OX Guard is part of the offering. OX Guard is available in the Univention App Center. Please check the UMC module App Center for the update of the OX Guard.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Configuration ==&lt;br /&gt;
&lt;br /&gt;
The following gives an overview of the most important settings to enable Guard for users on the Open-Xchange installation. Some of those settings have to be modified in order to establish the database and REST API access from the Guard service. All settings relating to the Guard backend component are located in the configuration file &amp;lt;code&amp;gt;guard-core.properties&amp;lt;/code&amp;gt; located in &amp;lt;code&amp;gt;/opt/open-xchange/etc&amp;lt;/code&amp;gt;. The default configuration should be sufficient for a basic &amp;amp;quot;up-and-running&amp;amp;quot; setup (with the exception of defining the database username and password). Please refer to the inline documentation of the configuration file for more advanced options. Additional information can be found in the [https://oxpedia.org/wiki/index.php?title=AppSuite:OX_Guard_Configuration_2_10 Guard Configuration] article.&lt;br /&gt;
&lt;br /&gt;
=== Basic Configuration ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/guard-core.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
Guard database for storing Guard user information, main lookup tables:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.oxguardDatabaseHostname=localhost&amp;lt;/source&amp;gt;&lt;br /&gt;
Guard database that stores keys for guest users. May be the same as above. New guest shards will be created on this database as needed. If not supplied, will use the &amp;lt;code&amp;gt;oxguardDatabaseHostname&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.oxguardShardDatabase=localhost&amp;lt;/source&amp;gt;&lt;br /&gt;
Username and Password for the databases above:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.databaseUsername=openexchange&lt;br /&gt;
com.openexchange.guard.databasePassword=db_password&amp;lt;/source&amp;gt;&lt;br /&gt;
Open-Xchange REST API host:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.restApiHostname=localhost&amp;lt;/source&amp;gt;&lt;br /&gt;
Open-Xchange REST API username and password (need to be defined in the OX backend in the &amp;amp;quot;Configure services&amp;amp;quot; below):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.restApiUsername=apiusername&lt;br /&gt;
com.openexchange.guard.restApiPassword=apipassword&amp;lt;/source&amp;gt;&lt;br /&gt;
External URL for this Open-Xchange installation. This setting will be used to generate the link to the secure content for external recipients:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.externalEmailURL=URL_TO_OX&amp;lt;/source&amp;gt;&lt;br /&gt;
=== Middleware Configuration on OX Guard node ===&lt;br /&gt;
&lt;br /&gt;
If you are installing OX Guard on a node that until yet did not host an Open-Xchange middleware you have to additionally configure some parts of the following properties files:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;configdb.properties&amp;lt;/code&amp;gt;: information about the existing configuration database.&lt;br /&gt;
* &amp;lt;code&amp;gt;server.properties&amp;lt;/code&amp;gt;: information about the connections have to be set.&lt;br /&gt;
* &amp;lt;code&amp;gt;system.properties&amp;lt;/code&amp;gt;: at least &amp;lt;code&amp;gt;SERVER_NAME&amp;lt;/code&amp;gt; should be set.&lt;br /&gt;
&lt;br /&gt;
=== Sevices Configuration ===&lt;br /&gt;
&lt;br /&gt;
==== Apache ====&lt;br /&gt;
&lt;br /&gt;
Configure the &amp;lt;code&amp;gt;mod_proxy_http&amp;lt;/code&amp;gt; module by adding the Guard API.&lt;br /&gt;
&lt;br /&gt;
===== Redhat Enterprise Linux 6 or CentOS 6 =====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /etc/httpd/conf.d/proxy_http.conf&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Debian GNU/Linux 9.0 =====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /etc/apache2/conf-enabled/proxy_http.conf&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;Proxy balancer://oxguard&amp;gt;&lt;br /&gt;
        Order deny,allow&lt;br /&gt;
        Allow from all&lt;br /&gt;
 &lt;br /&gt;
        BalancerMember http://localhost:8009/ timeout=1800 smax=0 ttl=60 retry=60 loadfactor=100 route=OX1&lt;br /&gt;
        ProxySet stickysession=JSESSIONID|jsessionid scolonpathdelim=ON&lt;br /&gt;
       SetEnv proxy-initial-not-pooled&lt;br /&gt;
        SetEnv proxy-sendchunked&lt;br /&gt;
 &amp;lt;/Proxy&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
 ProxyPass /appsuite/api/oxguard balancer://oxguard/oxguard&lt;br /&gt;
 ProxyPass /pks balancer://oxguard/pgp&lt;br /&gt;
 ProxyPass /.well-known/openpgpkey/hu balancer://oxguard/hu&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: The Guard API settings must be inserted &#039;&#039;&#039;&#039;&#039;before&#039;&#039;&#039;&#039;&#039; the existing &amp;lt;code&amp;gt;ProxyPass /appsuite/api&amp;lt;/code&amp;gt; parameter.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Also Note&#039;&#039;&#039;:  If you already have a Proxy balancer for the OX backend with the same URL (say http://localhost:8080) then you don&#039;t need the second BalancerMember entry, and you can just have the ProxyPass address that balancer instead.&lt;br /&gt;
&lt;br /&gt;
After the configuration is done, restart the Apache webserver&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ apachectl restart&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Open-Xchange Middleware Configuration ===&lt;br /&gt;
&lt;br /&gt;
Edit the &amp;lt;code&amp;gt;guard-api.properties&amp;lt;/code&amp;gt; configuration file for the OX backend where the guard-backend-plugin was installed. Please remove comments in front of the following settings to the configuration file &amp;lt;code&amp;gt;guard-api.properties&amp;lt;/code&amp;gt; on the Open-Xchange backend servers:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/guard-api.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;# OX Guard general permission, required to activate Guard in the AppSuite UI.&lt;br /&gt;
com.openexchange.capability.guard=true&lt;br /&gt;
&lt;br /&gt;
# Default theme template id for all users that have no custom template id configured.&lt;br /&gt;
com.openexchange.guard.templateID=0&amp;lt;/source&amp;gt;&lt;br /&gt;
Configure the API username and password that you assigned to Guard in the &amp;lt;code&amp;gt;server.properties&amp;lt;/code&amp;gt; file:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/server.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;# Specify the user name used for HTTP basic auth by internal REST servlet&lt;br /&gt;
com.openexchange.rest.services.basic-auth.login=apiusername&lt;br /&gt;
&lt;br /&gt;
# Specify the password used for HTTP basic auth by internal REST servlet&lt;br /&gt;
com.openexchange.rest.services.basic-auth.password=apipassword&amp;lt;/source&amp;gt;&lt;br /&gt;
Finally, the OX backend needs to know where the Guard server is located. This is used to notify the Guard server of changes in users, and to send emails marked for signature. The URL for the Guard server should include the URL suffix &amp;lt;code&amp;gt;/guardadmin&amp;lt;/code&amp;gt;. In the event of a cluster setup, any Guard server can be referenced here, as it is not session specific, though ideally would have a HTTP load balancer/failover URL:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/guard-api.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;# Specifies the URI to the OX Guard end-point; e.g. http://guard.host.invalid:8081/guardadmin&lt;br /&gt;
# Default is empty&lt;br /&gt;
com.openexchange.guard.endpoint=http://guardserver:8009/guardadmin&amp;lt;/source&amp;gt;&lt;br /&gt;
Restart the OX backend&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /etc/init.d/open-xchange restart&amp;lt;/source&amp;gt;&lt;br /&gt;
==== SELinux ====&lt;br /&gt;
&lt;br /&gt;
Running SELinux prohibits your local Open-Xchange backend service to connect to localhost:8009, which is where the Guard backend service listens to. In order to allow localhost connections to 8009 execute the following:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ setsebool -P httpd_can_network_connect 1&amp;lt;/source&amp;gt;&lt;br /&gt;
=== Generating the &amp;lt;code&amp;gt;oxguardpass&amp;lt;/code&amp;gt; ===&lt;br /&gt;
&lt;br /&gt;
Once the Guard configuration (database and backend configuration) and the service configuration has been applied, the Guard administration script needs to be executed in order to create the master password file in &amp;lt;code&amp;gt;/opt/open-xchange/etc/oxguardpass&amp;lt;/code&amp;gt;. The initiation only needs to be done &#039;&#039;&#039;once&#039;&#039;&#039; for a multi server setup, for details please see the sections &#039;&#039;&#039;Optional&#039;&#039;&#039; and/or &#039;&#039;&#039;Clustering&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: If you run a cluster of OX / Guard nodes, only execute this command on &#039;&#039;&#039;ONE&#039;&#039;&#039; node. Not on all nodes! See [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCluster OX Guard Clustering] for details.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /opt/open-xchange/sbin/guard --init&amp;lt;/source&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: It is important to understand that the master password file located at &amp;lt;code&amp;gt;/opt/open-xchange/etc/oxguardpass&amp;lt;/code&amp;gt; is required to reset user passwords; without them the administrator will not be able to reset user passwords anymore in the future. The file contains the passwords used to encrypt the master database key, as well as passwords used to encrypt protected data in the users table. It must be the same on all Guard servers.&lt;br /&gt;
&lt;br /&gt;
=== Test Setup ===&lt;br /&gt;
&lt;br /&gt;
Not required, but it is a good idea to test the Guard setup before enabling for any users. The test function will verify that Guard has a good connection to the OX backend, and that it can resolve email addresses to users.&lt;br /&gt;
&lt;br /&gt;
To test, use an email address that exists on the OX backend (john@example.com for this example)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;/opt/open-xchange/sbin/guard --test john@example.com&amp;lt;/source&amp;gt;&lt;br /&gt;
Guard should return information from the OX backend regarding the user associated with &amp;amp;quot;john@example.com&amp;amp;quot;. Problems resolving information for the user should be resolved before using Guard. Check Rest API passwords and settings if errors returned.&lt;br /&gt;
&lt;br /&gt;
=== Enabling Guard for Users ===&lt;br /&gt;
&lt;br /&gt;
Guard provides two capabilities for users in the environment as well as a basic &amp;amp;quot;core&amp;amp;quot; level:&lt;br /&gt;
&lt;br /&gt;
* Guard: &amp;lt;code&amp;gt;com.openexchange.capability.guard&amp;lt;/code&amp;gt;&lt;br /&gt;
* Guard Mail: &amp;lt;code&amp;gt;com.openexchange.capability.guard-mail&amp;lt;/code&amp;gt;&lt;br /&gt;
* Guard Drive: &amp;lt;code&amp;gt;com.openexchange.capability.guard-drive&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The &amp;amp;quot;core&amp;amp;quot; Guard enabled a basic read functionality for Guard encrypted emails. We recommend enabling this for all users, as this allows all recipients to read Guard emails sent to them. Great opportunity for upsell. Recipients with only Guard enabled can then do a secure reply to the sender, but they can&#039;t start a new email or add recipients.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Guard Mail&#039;&#039;&#039; and &#039;&#039;&#039;Guard Drive&#039;&#039;&#039; are additional options for users. &amp;amp;quot;Guard Mail&amp;amp;quot; allows users the full functionality of Guard emails. &amp;amp;quot;Guard Drive&amp;amp;quot; allows for encryption and decryption of drive files.&lt;br /&gt;
&lt;br /&gt;
Each of those two Guard components is enabled for all users that have the according capability configured. Please note that users need to have the Drive permission set to use Guard Drive. So the users that have Guard Drive enabled must be a subset of those users with OX Drive permission. Since v7.6.0 we enforce this via the default configuration. Those capabilities can be activated for specific user by using the Open-Xchange provisioning scripts:&lt;br /&gt;
&lt;br /&gt;
==== Guard Mail: ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /opt/open-xchange/sbin/changeuser -c 1 -A oxadmin -P admin_password -u testuser --config/com.openexchange.capability.guard-mail=true&amp;lt;/source&amp;gt;&lt;br /&gt;
==== Guard Drive: ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ /opt/open-xchange/sbin/changeuser -c 1 -A oxadmin -P admin_password -u testuser --config/com.openexchange.capability.guard-drive=true&amp;lt;/source&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039;: Guard Drive requires Guard Mail to be configured for the user as well. In addition, these capabilities may be configured globally by editing the &amp;lt;code&amp;gt;guard-api.properties&amp;lt;/code&amp;gt; file on the OX backend.&lt;br /&gt;
&lt;br /&gt;
=== External Guest recipients: ===&lt;br /&gt;
Starting in Guard 2.10.0, when an encrypted email is sent to a user that does not have Guard, a guest account is created for them in appsuite.  The recipient uses the Guest account to read the encrypted email.  These guest users MUST have guard capabilities.  To do this, guard capability must be added to guest accounts.&lt;br /&gt;
&amp;lt;code&amp;gt;/opt/open-xchange/etc/share.properties&amp;lt;/code&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.share.guestCapabilityMode=static&lt;br /&gt;
com.openexchange.share.staticGuestCapabilities=guard&amp;lt;/source&amp;gt;&lt;br /&gt;
In a distributed system, the Guest accounts should not be considered transient.  Guard servers must be able to verify the guest account exists in the session storage services.&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.share.transientSessions=false&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Guest Storage ===&lt;br /&gt;
When an encrypted email is sent to an external Guest, a copy of the fully encrypted email is stored on the server.  This is used to create an inbox of encrypted emails for the guest.  By entering in a password, the emails can be decrypted and displayed.&lt;br /&gt;
&lt;br /&gt;
How these files are stored depend on which package, open-xchange-guard-file-storage or open-xchange-guard-s3-storage, was installed.&lt;br /&gt;
&lt;br /&gt;
The file retention policy is configured in the guard-core.properties file.&lt;br /&gt;
&lt;br /&gt;
=== Recipient key detection ===&lt;br /&gt;
&lt;br /&gt;
==== Local ====&lt;br /&gt;
&lt;br /&gt;
Guard needs to determine if an email recipients email address is an internal or external (non-ox) user.&lt;br /&gt;
&lt;br /&gt;
To detect if the recipient is an account on the same OX Guard system there is a mechanism needed to map a recipient mail address to the correct local OX context. The default implementation delivered in the product achieves that by looking up the mail domain (@example.com) within the list of context mappings. That is at least not possible in case of ISPs where different users/contexts use the same mail domain. In case your OX system does not use mail domains in context mappings it is required to deploy an OX OSGi bundle implementing the &amp;lt;code&amp;gt;com.openexchange.mailmapping.MailResolver&amp;lt;/code&amp;gt; class or by interfacing Guard with your mail resolver system. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardMailResolver OX Guard Mail Resolver] for details.&lt;br /&gt;
&lt;br /&gt;
==== External ====&lt;br /&gt;
&lt;br /&gt;
Starting with Guard 2.0, Guard will use public PGP Key servers if configured to find PGP Public keys. In addition, Guard will also look up SRV records for PGP Key servers for a recipients domain. This follows the standards [http://tools.ietf.org/html/draft-shaw-openpgp-hkp-00#page-9 OpenPGP Draft].&lt;br /&gt;
&lt;br /&gt;
External PGP servers to use can be configured in the guard.properties file on the Guard servers.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.publicPGPDirectory = hkp://keys.gnupg.net:11371, hkp://pgp.mit.edu:11371&amp;lt;/source&amp;gt;&lt;br /&gt;
If you would like this Guard installation discoverable by other Guard servers, then create an SRV record for each domain (&amp;amp;quot;example.com&amp;amp;quot; in this illustration):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;_hkp._tcp.example.com. 28800 IN    SRV     10 1 80 appsuite.example.com.&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Please Note&#039;&#039;&#039; PGP Public key servers by default append use the URL server/pks when the record is obtained from an SRV record. The proxy above routes anything with the Apache domain/pks to the OX Guard PGP server.&lt;br /&gt;
&lt;br /&gt;
Guard keys are also discoverable using the webkey service as specified here: https://tools.ietf.org/html/draft-koch-openpgp-webkey-service-02&lt;br /&gt;
This is enabled if you include the &lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;ProxyPass /.well-known/openpgpkey/hu balancer://oxguard/hu&amp;lt;/source&amp;gt;&lt;br /&gt;
in the proxy_http.conf as above.&lt;br /&gt;
Please note that the well-known request is targeted on the domain part of the mail adress. Therefore clients will request for a mail address name@example.com the URI https://example.com/.well-known/openpgpkey/hu/...&lt;br /&gt;
&lt;br /&gt;
=== Clustering ===&lt;br /&gt;
&lt;br /&gt;
You can run multiple OX Guard servers in your environment to ensure high availability or enhance scalability. OX Guard integrates seamlessly into the existing Open-Xchange infrastructure by using the existing interface standards and is therefor transparent to the environment. A couple of things have to be prepared in order to loosely couple OX Guard servers with Open-Xchange servers in a cluster.&lt;br /&gt;
&lt;br /&gt;
==== MySQL ====&lt;br /&gt;
&lt;br /&gt;
The MySQL servers need to be configured in order to allow access to the configdb of Open-Xchange. To do so you need to set the following configuration in the MySQL &amp;lt;code&amp;gt;my.cnf&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;bind = 0.0.0.0&amp;lt;/source&amp;gt;&lt;br /&gt;
This allows the Guard backend to bind to the MySQL host which is configured in the &amp;lt;code&amp;gt;guard-core.properties&amp;lt;/code&amp;gt; file with &amp;lt;code&amp;gt;com.openexchange.guard.configdbHostname&amp;lt;/code&amp;gt;. After the bind for the MySQL instance is configured and the OX Guard backend would be able to connect to the configured host, you have to grant access for the OX Guard service on the MySQL instance to manage the databases. Do so by connecting to the MySQL server via the MySQL client. Authenticate if necessary and execute the following, please note that you have to modify the hostname / IP address of the client who should be able to connect to this database, it should include all possible OX Guard servers:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;sql&amp;quot;&amp;gt;GRANT ALL PRIVILEGES ON *.* TO &#039;openexchange&#039;@&#039;oxguard.example.com&#039; IDENTIFIED BY ‘secret’;&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Apache ====&lt;br /&gt;
&lt;br /&gt;
OX Guard uses the Open-Xchange REST API to store and fetch data from the Open-Xchange databases. The REST API is a servlet running in the Grizzly container. By default it is not exposed as a servlet through Apache and is only accessibly via port 8009. In order to use Apache&#039;s load balancing via &amp;lt;code&amp;gt;mod_proxy&amp;lt;/code&amp;gt; we need to add a servlet called &amp;amp;quot;preliminary&amp;amp;quot; to &amp;lt;code&amp;gt;proxy_http.conf&amp;lt;/code&amp;gt;, example based on a clustered &amp;lt;code&amp;gt;mod_proxy&amp;lt;/code&amp;gt;configuration:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;Location /preliminary&amp;gt;&lt;br /&gt;
      Order Deny,Allow&lt;br /&gt;
      Deny from all&lt;br /&gt;
      # Only allow access from Guard servers within the network. Do not expose this&lt;br /&gt;
      # location outside of your network. In case you use a load balancing service in front&lt;br /&gt;
      # of your Apache infrastructure you should make sure that access to /preliminary will&lt;br /&gt;
      # be blocked from the Internet / outside clients. Examples:&lt;br /&gt;
      # Allow from 192.168.0.1&lt;br /&gt;
      # Allow from 192.168.1.1 192.168.1.2&lt;br /&gt;
      # Allow from 192.168.0.&lt;br /&gt;
 &amp;lt;/Location&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
 ProxyPass /preliminary balancer://oxcluster/preliminary&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Make sure that the balancer is properly configured in the &amp;lt;code&amp;gt;mod_proxy&amp;lt;/code&amp;gt; configuration. Examples on how to do so can be found in our clustering configuration for Open-Xchange AppSuite. Like explained in the example above, please make sure that this location is only available in your internal network, there is no need to expose &amp;lt;code&amp;gt;/preliminary&amp;lt;/code&amp;gt; to the public, it is only used by Guard servers to connect to the OX backend. If you have a load balancer in front of the Apache cluster you should consider blocking access to &amp;lt;code&amp;gt;/preliminary&amp;lt;/code&amp;gt; from WAN to restrict access to the servlet to internal network services only.&lt;br /&gt;
&lt;br /&gt;
Now add the OX Guard &amp;lt;code&amp;gt;BalancerMembers&amp;lt;/code&amp;gt; to the oxguard balancer configuration (also in &amp;lt;code&amp;gt;proxy_http.conf&amp;lt;/code&amp;gt;) to address all your OX Guard nodes in the cluster in this balancer configuration. The configuration has to be applied to all Apache nodes within the cluster.&lt;br /&gt;
&lt;br /&gt;
If the Apache server is a dedicated server &amp;lt;code&amp;gt;/&amp;lt;/code&amp;gt; instance you also have to install the OX Guard UI-Static package on all Apache nodes in the cluster in order to provide static files like images or CSS to the OX Guard client. Example for Debian (the OX Guard repository has to be configured in the package management prior):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ apt-get install open-xchange-guard-ui-static&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Open-Xchange ====&lt;br /&gt;
&lt;br /&gt;
Disable the Open-Xchange IPCheck for session verification. This is required because OX Guard will use the users session cookie to connect to the Open-Xchange REST API, but as a different IP address than the OX Guard server has been used during authentication the request would fail if you don&#039;t disable the IPCheck:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ vim /opt/open-xchange/etc/server.properties&amp;lt;/source&amp;gt;&lt;br /&gt;
and set:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.IPCheck=false&amp;lt;/source&amp;gt;&lt;br /&gt;
The OX Guard UI package has to be installed on all Open-Xchange backend nodes as well, example for Debian (the OX Guard repository has to be configured in the package management prior):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;$ apt-get install open-xchange-guard-ui&amp;lt;/source&amp;gt;&lt;br /&gt;
Restart the Open-Xchange service afterwards.&lt;br /&gt;
&lt;br /&gt;
==== OX Guard ====&lt;br /&gt;
&lt;br /&gt;
For details in clustering Guard servers, please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCluster OX Guard Clustering]. It is &#039;&#039;&#039;critical&#039;&#039;&#039; that all Guard servers have the same &amp;lt;code&amp;gt;oxguardpass&amp;lt;/code&amp;gt; file. Please see the clustering link for details. Do not run &amp;lt;code&amp;gt;/opt/open-xchange/sbin/guard --init&amp;lt;/code&amp;gt; on more than one server.&lt;br /&gt;
&lt;br /&gt;
After all the services like MySQL, Apache and Open-Xchange have been configured you need to update the OX Guard backend configuration to point to the correct API endpoints. Set the REST API endpoint to an Apache server by setting the following value in &amp;lt;code&amp;gt;/opt/open-xchange/etc/guard-core.properties&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.restApiHostname=apache.example.com&amp;lt;/source&amp;gt;&lt;br /&gt;
Per default Guard will try to connect to port 8009 to this host, but as we configured the REST API to be proxies thorugh the servlet &amp;lt;code&amp;gt;/preliminary&amp;lt;/code&amp;gt; on every Apache we now also need to change the target port for the REST API. You can do so by adding the following line into &amp;lt;code&amp;gt;/opt/open-xchange/etc/guard-core.properties&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;com.openexchange.guard.oxBackendPort=80&amp;lt;/source&amp;gt;&lt;br /&gt;
Please also change all settings in regards to MySQL like &amp;lt;code&amp;gt;com.openexchange.guard.configdbHostname&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;com.openexchange.guard.oxguardDatabaseHostname&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;com.openexchange.guard.databaseUsername&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;om.openexchange.guard.databasePassword&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Afterwards restart the OX Guard service and check the log file if the OX Guard backend is able to connect to the configured REST API.&lt;br /&gt;
&lt;br /&gt;
=== Multi Node ===&lt;br /&gt;
&lt;br /&gt;
If you have multiple OX and Guard installations, please see the following documentation [https://oxpedia.org/wiki/index.php?title=AppSuite:OX_Guard_Modular OX Guard Modular Setup].&lt;br /&gt;
&lt;br /&gt;
=== Mail Filter Integration (2.10.4+) ===&lt;br /&gt;
&lt;br /&gt;
To add additional mail filter tests (verify PGP signature, or encrypt incoming), please see&lt;br /&gt;
[[AppSuite:OX_Guard_MailFilter | MailFilter Integration]]&lt;br /&gt;
&lt;br /&gt;
== Support API ==&lt;br /&gt;
&lt;br /&gt;
The OX Guard Support API enables administrative access to various functions for maintaining OX Guard from a client in a role as a support employee. A client has to do a BASIC AUTH authentication in order to access the API. Username and password can be configured in the guard-core.properties file using the following settings:&lt;br /&gt;
&lt;br /&gt;
 # Specify the username and password for accessing the Support API of Guard&lt;br /&gt;
 com.openexchange.guard.supportApiUsername=&lt;br /&gt;
 com.openexchange.guard.supportApiPassword=&lt;br /&gt;
&lt;br /&gt;
In contrast to the rest of the OX Guard requests, the OX Guard support API requests are accessible using: /guardsupport. This distinction allows more flexible configuration since the support API should not always be accessible from everywhere. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Warning&#039;&#039;&#039;: Exposing the support API to the internet could be huge security risk. Only add to Apache if you know what you are doing.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Reset password ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=reset_password&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Performs a password reset and sends a new random generated password to a specified email address by the user or a default address if the user did not specify an email address. (&#039;&#039;Since Guard 2.0&#039;&#039;)&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;email&amp;lt;/code&amp;gt; – The email address of the user to reset the password for&lt;br /&gt;
* &amp;lt;code&amp;gt;default&amp;lt;/code&amp;gt; (optional) – The email address to send the new password to, if the user did not specify a secondary email address&lt;br /&gt;
&lt;br /&gt;
Response:&lt;br /&gt;
PRIMARY if the reset was sent to the primary email address.  SECONDARY if the reset email was sent to the secondary email address that the user specified&lt;br /&gt;
&lt;br /&gt;
=== Expose key ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=expose_key&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Marks a deleted user key temporary as “exposed” and creates a unique URL for downloading the exposed key. Automatic resetting of exposed keys to &amp;amp;quot;not exposed&amp;amp;quot; is scheduled once a day and resets all exposed keys which have been exposed before X hours, where X can be configured using com.openexchange.guard.exposedKeyDurationInHours in the guard.properties files. (&#039;&#039;Since Guard 2.0&#039;&#039;)&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;email&amp;lt;/code&amp;gt; – The email address of the user to expose the deleted keys for&lt;br /&gt;
* &amp;lt;code&amp;gt;cid&amp;lt;/code&amp;gt; – The context id&lt;br /&gt;
&lt;br /&gt;
Response: A URL pointing to the downloadable exposed keys.&lt;br /&gt;
&lt;br /&gt;
=== Delete user ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=delete_user&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deletes all keys related to a certain user. The keys are backed up and can be exposed using the “expose_key” call. (&#039;&#039;Since Guard 2.0&#039;&#039;)&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;user_id&amp;lt;/code&amp;gt; – The user&#039;s id&lt;br /&gt;
* &amp;lt;code&amp;gt;cid&amp;lt;/code&amp;gt; - The context id&lt;br /&gt;
&lt;br /&gt;
=== Upgrade User (Release 2.10 and later) ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;POST /guardsupport/?action=upgrade_guest&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Upgrades a Guest account.  This action copies all of the keys from the Guest account to a full OX account, assuming that user has Guard capabilities.&lt;br /&gt;
&lt;br /&gt;
Parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;email&amp;lt;/code&amp;gt; - The email address of the Guest user&lt;br /&gt;
* &amp;lt;code&amp;gt;user_id&amp;lt;/code&amp;gt; – The user&#039;s new id&lt;br /&gt;
* &amp;lt;code&amp;gt;cid&amp;lt;/code&amp;gt; - The user&#039;s new context id&lt;br /&gt;
&lt;br /&gt;
== Customisation ==&lt;br /&gt;
&lt;br /&gt;
Guard&#039;s templates are customisable at the user and context level. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardCustomization Customisation] for details.&lt;br /&gt;
&lt;br /&gt;
== Entropy ==&lt;br /&gt;
&lt;br /&gt;
Guard requires entropy (randomness) to generate the private/public keys that are used. Depending on the server and it&#039;s environment, this may become a problem. Please see [https://oxpedia.org/wiki/index.php?title=AppSuite:GuardEntropy Entropy] for a possible solution.&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:OX_Guard_MailFilter&amp;diff=25534</id>
		<title>AppSuite:OX Guard MailFilter</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:OX_Guard_MailFilter&amp;diff=25534"/>
		<updated>2020-08-05T21:56:37Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= OX Guard MailFilter Integration =&lt;br /&gt;
&lt;br /&gt;
It is possible to add the Sieve test “PGP Signature” as well as the action “encrypt incoming” to the mailfilter functionality of Appsuite.  This utilizes the sieve  Extprograms plugin to call Guard through an api to either verify signatures or return the email encrypted.&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
&lt;br /&gt;
The user creates either the filter test “PGP Signature” or action “Encrypt email”.  This creates a sieve rule that calls an external script with the user&#039;s ID and Context.  Only pre-configured scripts can be called, there isn’t any ability for someone to create their own external scripts to be called.&lt;br /&gt;
&lt;br /&gt;
Incoming emails then go through the Sieve filter, which then calls the external script with the user&#039;s ID and Context as parameters.&lt;br /&gt;
&lt;br /&gt;
The external script calls the Guard server through an api call.  Response is returned to the script.  Either marked as signed, or the encrypted content of the email is returned.&lt;br /&gt;
&lt;br /&gt;
== Setup: ==&lt;br /&gt;
&lt;br /&gt;
Dovecot sieve extension ExtPrograms must be enabled.  This adds three different capabilities to sieve vnd.dovecot.pipe, vnd.dovecot.filter, and vnd.dovecot.exectue (pipe is not required for these scripts), but they are disabled by default.  “Filter” and “execute” must be enabled for users, and then the directories containing the scripts must be configured.&lt;br /&gt;
&lt;br /&gt;
Example configuration:&lt;br /&gt;
&lt;br /&gt;
=== 90-sieve.conf ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;plugin {  &lt;br /&gt;
    sieve = file:~/sieve;active=~/.dovecot.sieve  &lt;br /&gt;
    sieve_default = /var/lib/dovecot/sieve/default.sieve  &lt;br /&gt;
    sieve_plugins = sieve_extprograms  &lt;br /&gt;
    sieve_extensions = +vnd.dovecot.filter +vnd.dovecot.execute  &lt;br /&gt;
    # The directory contains the scripts that are available for the filter and execute  &lt;br /&gt;
    # commands.  &lt;br /&gt;
     sieve_filter_bin_dir = /usr/lib/dovecot/sieve-filter  &lt;br /&gt;
     sieve_execute_bin_dir = /usr/lib/dovecot/sieve-execute  &lt;br /&gt;
}&amp;lt;/pre&amp;gt;&lt;br /&gt;
Of course, the sieve protocol must be enabled and managesieve must be already working.&lt;br /&gt;
&lt;br /&gt;
=== Scripts ===&lt;br /&gt;
&lt;br /&gt;
There are currently two scripts, one to test the email signatures, another to encrypt the email.  Add/create scripts in the following location (assuming the above configuration).  Replace the username/password rest:secret with the REST username and password configured with Guard.&lt;br /&gt;
&lt;br /&gt;
/usr/lib/dovecot/sieve-filter/guard.sh&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;#!/bin/bash  &lt;br /&gt;
GUARD=&amp;amp;quot;${GUARD_SERVER:-localhost:8009}&amp;amp;quot;&lt;br /&gt;
&lt;br /&gt;
## Send the stdin to guard using curl, store result&lt;br /&gt;
&lt;br /&gt;
encrypted=$(curl -s -X POST -F file=@- &amp;amp;quot;http://${GUARD}/oxguard/pgpmail?action=encrypt_mime&amp;amp;amp;user=${1}&amp;amp;amp;context=${2}&amp;amp;amp;respondWithJSON=true&amp;amp;quot; --user rest:secret )&lt;br /&gt;
&lt;br /&gt;
## Check for errors and basic sanity check&lt;br /&gt;
&lt;br /&gt;
if [[ $encrypted == \{\&amp;amp;quot;error* ]] ;  &lt;br /&gt;
then  &lt;br /&gt;
  logger &amp;amp;quot;Guard sieve encrypter error: $encrypted&amp;amp;quot;  &lt;br /&gt;
  ## Error, exit  &lt;br /&gt;
  exit 1  &lt;br /&gt;
fi&lt;br /&gt;
&lt;br /&gt;
## Return the encrypted text. Preserve /r&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;amp;quot;$encrypted&amp;amp;quot;&amp;lt;/pre&amp;gt;&lt;br /&gt;
/usr/lib/dovecot/sieve-execute/guard-sig.sh&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;#!/bin/bash  &lt;br /&gt;
GUARD=&amp;amp;quot;${GUARD_SERVER:-localhost:8009}&amp;amp;quot;&lt;br /&gt;
&lt;br /&gt;
## Send the stdin to guard using curl, store result&lt;br /&gt;
&lt;br /&gt;
verified=$(curl -s -X POST -F file=@- &amp;amp;quot;http://${GUARD}/oxguard/pgpmail?action=verify&amp;amp;amp;user=${1}&amp;amp;amp;context=${2}&amp;amp;amp;simple=true&amp;amp;amp;respondWithJSON=true&amp;amp;quot; --user rest:secret )  &lt;br /&gt;
logger $verified  &lt;br /&gt;
&lt;br /&gt;
## Check if returns true&lt;br /&gt;
&lt;br /&gt;
if [[ $verified == &amp;amp;quot;{\&amp;amp;quot;data\&amp;amp;quot;:true}&amp;amp;quot; ]] ;  &lt;br /&gt;
then  &lt;br /&gt;
  exit 0  &lt;br /&gt;
fi  &lt;br /&gt;
if [[ $verified == \{\&amp;amp;quot;error* ]] ;  &lt;br /&gt;
then  &lt;br /&gt;
  logger &amp;amp;quot;Guard sieve signature error: $verified&amp;amp;quot;  &lt;br /&gt;
fi  &lt;br /&gt;
exit 1&amp;lt;/pre&amp;gt;&lt;br /&gt;
There is no requirement that these scripts are in different directories.  Dovecot requires that scripts are not world writable.  In addition, as these scripts contain the rest username/password, recommend changing the owner to vmail and restricting permissions to 700&lt;br /&gt;
&lt;br /&gt;
== Middleware Packages ==&lt;br /&gt;
&lt;br /&gt;
On the middleware nodes the &amp;lt;code&amp;gt;open-xchange-guard-backend-mailfilter&amp;lt;/code&amp;gt; package needs to be installed.  This should be on the same nodes as the &amp;lt;code&amp;gt;open-xchange-guard-backend-plugin&amp;lt;/code&amp;gt; package is installed.&lt;br /&gt;
&lt;br /&gt;
=== Debian ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
  apt-get install open-xchange-guard-backend-mailfilter&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Redhat ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
  yum install open-xchange-guard-backend-mailfilter&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Configuration ==&lt;br /&gt;
&lt;br /&gt;
The guard mailfilter functionality must be enabled on the middleware.  Recommend adding the configuration to guard-api.properties on the middleware servers:&lt;br /&gt;
&lt;br /&gt;
com.openexchange.mail.filter.guard.sieveEnabled=true&lt;br /&gt;
&lt;br /&gt;
The script names may be configured differently, but default to the following:&lt;br /&gt;
&lt;br /&gt;
com.openexchange.mail.filter.guard.guardEncryptScript=guard.sh&lt;br /&gt;
&lt;br /&gt;
com.openexchange.mail.filter.guard..guardSignatureScript=guard-sig.sh&lt;br /&gt;
&lt;br /&gt;
== MailFilter User Interface ==&lt;br /&gt;
&lt;br /&gt;
Assuming the user has guard-mail and mailfilter capabilities, they will now be able to add the configured test and actions for Guard.&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:Multifactor&amp;diff=25328</id>
		<title>AppSuite:Multifactor</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:Multifactor&amp;diff=25328"/>
		<updated>2020-05-11T14:10:53Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
= Multifactor Authentication (since 7.10.2) =&lt;br /&gt;
&lt;br /&gt;
This documentation has been moved.&lt;br /&gt;
&lt;br /&gt;
For 7.10.2&lt;br /&gt;
&lt;br /&gt;
https://documentation.open-xchange.com/7.10.2/middleware/security_and_encryption/multifactor_authentication.html&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For 7.10.3&lt;br /&gt;
&lt;br /&gt;
https://documentation.open-xchange.com/7.10.3/middleware/security_and_encryption/multifactor_authentication.html&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:Multifactor&amp;diff=25327</id>
		<title>AppSuite:Multifactor</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:Multifactor&amp;diff=25327"/>
		<updated>2020-05-11T14:03:21Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
= Multifactor Authentication (since 7.10.2) =&lt;br /&gt;
&lt;br /&gt;
Appsuite version 7.10.2 provides methods for users to require secondary, additional methods of authentication before creating a valid Appsuite session.  These methods may include SMS messages, Time based authenticator methods, U2F compatible devices/keyfobs, and other custom methods.&lt;br /&gt;
&lt;br /&gt;
== Enabling Multifactor ==&lt;br /&gt;
&lt;br /&gt;
The open-xchange-multifactor package is required for the core of multifactor authentication. For some methods (such as SMS), additional packages will be required.&lt;br /&gt;
&lt;br /&gt;
With SMS, for example, you must also install a provider, such as open-xchange-sms-sipgate.&lt;br /&gt;
&lt;br /&gt;
Then, multifactor must be enabled as a capability.  This can be done in the multifactor.properties file, or as a cascade value&lt;br /&gt;
&lt;br /&gt;
 com.openexchange.capability.multifactor=true&lt;br /&gt;
&lt;br /&gt;
== Enabling SMS ==&lt;br /&gt;
&lt;br /&gt;
First, the SMS provider must be installed and configured.  Most will require a configured username and password, or AUTH_TOKEN.  Install the needed package and configure.&lt;br /&gt;
&lt;br /&gt;
At that point, you should enable SMS in the multifactor.properties file&lt;br /&gt;
&lt;br /&gt;
 com.openexchange.multifactor.sms.available=true&lt;br /&gt;
&lt;br /&gt;
The following properties are also available&lt;br /&gt;
&lt;br /&gt;
* com.openexchange.multifactor.sms.tokenLength   (default is 8 characters)&lt;br /&gt;
* com.openexchange.multifactor.sms.tokenLifetime (Number of minutes until challenge expires)&lt;br /&gt;
* com.openexchange.multifactor.maxTokenAmount (Maximum number of challenges before locked out)&lt;br /&gt;
&lt;br /&gt;
== Enabling TOTP ==&lt;br /&gt;
&lt;br /&gt;
TOTP is Time-based One Time Password.  This works with several apps available in mobile stores, such as Google Authenticator.&lt;br /&gt;
&lt;br /&gt;
To enable, just set in the multifactor.properties file&lt;br /&gt;
&lt;br /&gt;
 com.openexchange.multifactor.totp.available=true&lt;br /&gt;
&lt;br /&gt;
== Enabling Backup String ==&lt;br /&gt;
&lt;br /&gt;
This is a method to allow a user to log into their account if they lose their primary multifactor authentication device (say losing their phone or U2F token).  It is a long string that they can copy, download, or print to use to unlock the account in the event of loss&lt;br /&gt;
&lt;br /&gt;
To enable, set in the multifactor.properties file&lt;br /&gt;
&lt;br /&gt;
 com.openexchange.multifactor.backupString.available=true&lt;br /&gt;
&lt;br /&gt;
== Enabling U2F ==&lt;br /&gt;
&lt;br /&gt;
U2F is supported in Google Chrome, as well as Firefox (though requires user changing advanced settings).  &lt;br /&gt;
&lt;br /&gt;
In multifactor.properties, enable U2F&lt;br /&gt;
&lt;br /&gt;
 com.openexchange.multifactor.U2F.available=true&lt;br /&gt;
&lt;br /&gt;
Then, the domain that the user will be using must be specified.  This will be used with the requests to the U2F device, and must mach the website.  This configuration is config-cascade aware&lt;br /&gt;
&lt;br /&gt;
 com.openexchange.multifactor.U2F.appId=https://yourdomain&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Login Page ==&lt;br /&gt;
&lt;br /&gt;
By default, the UI will change from the login page, draw the customized toolbar, then display a prompt for the multifactor authentication.&lt;br /&gt;
&lt;br /&gt;
If you would prefer to have your login screen, or a different second factor screen used as the background, then you can configure in the as-config.yml&lt;br /&gt;
&lt;br /&gt;
For example:&lt;br /&gt;
&lt;br /&gt;
 default:&lt;br /&gt;
     host: all&lt;br /&gt;
     signinTheme: default&lt;br /&gt;
     multifactorBackground: pages/secondFactor&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:Available_Translations&amp;diff=25279</id>
		<title>AppSuite:Available Translations</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:Available_Translations&amp;diff=25279"/>
		<updated>2020-03-17T08:30:41Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Open-Xchange Server Translations for OX App Suite =&lt;br /&gt;
&lt;br /&gt;
=== Available Language Translations ===&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;3&amp;quot; cellspacing=&amp;quot;0&amp;quot;&lt;br /&gt;
!align=&amp;quot;left&amp;quot; |Language&lt;br /&gt;
!align=&amp;quot;left&amp;quot; |Status&lt;br /&gt;
!align=&amp;quot;left&amp;quot; |Documentation&lt;br /&gt;
!align=&amp;quot;left&amp;quot; |Contributor&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_us.png]] US English&lt;br /&gt;
| Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange &lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_gb.png]] British English&lt;br /&gt;
| Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange &lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_de.png]] German&lt;br /&gt;
| Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_fr.png]] French&lt;br /&gt;
| Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_cn.png]] Canadian French&lt;br /&gt;
|Supported&lt;br /&gt;
| &lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_es.png]] Spanish &lt;br /&gt;
|Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_mx.png]] Mexican Spanish &lt;br /&gt;
|Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_nl.png]] Dutch &lt;br /&gt;
| Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_pl.png]] Polish&lt;br /&gt;
| Supported&lt;br /&gt;
|Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:japanese.jpeg]] Japanese&lt;br /&gt;
|Supported&lt;br /&gt;
|Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_it.png]] Italian&lt;br /&gt;
|Supported&lt;br /&gt;
|Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:china.jpg]] Simplified Chinese&lt;br /&gt;
|Supported&lt;br /&gt;
|Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:china.jpg]] Traditional Chinese&lt;br /&gt;
|Supported&lt;br /&gt;
|Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:ungarn.jpg]] Hungarian&lt;br /&gt;
|Supported&lt;br /&gt;
| &lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Slovakia.jpg]] Slovak&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Czech.jpg]] Czech&lt;br /&gt;
|Supported&lt;br /&gt;
| &lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:latvia.jpg]] Latvian&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
|Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
|[[Image:Flag_romania.png]] Romanian&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:brazil.png|17px]] Brazilian Portuguese&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Flag_se.png|17px]] Swedish&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Flag_dk.png|17px]] Danish&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Russian.png|17px]] Russian&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[File:flag_fin.png|17px]] Finnish&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[File:flag_Tur.png|17px]] Turkish&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Any other languages which may be provided by installation packages are not supported and might even have a bad UI/UX impact when installed. Please use at your own risk!&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
[[Category: OX7]]&lt;br /&gt;
[[Category: AppSuite]]&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:Available_Translations&amp;diff=25278</id>
		<title>AppSuite:Available Translations</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:Available_Translations&amp;diff=25278"/>
		<updated>2020-03-17T08:30:18Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Open-Xchange Server Translations for OX App Suite =&lt;br /&gt;
&lt;br /&gt;
=== Available Language Translations ===&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;3&amp;quot; cellspacing=&amp;quot;0&amp;quot;&lt;br /&gt;
!align=&amp;quot;left&amp;quot; |Language&lt;br /&gt;
!align=&amp;quot;left&amp;quot; |Status&lt;br /&gt;
!align=&amp;quot;left&amp;quot; |Documentation&lt;br /&gt;
!align=&amp;quot;left&amp;quot; |Contributor&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_us.png]] US English&lt;br /&gt;
| Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange &lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_gb.png]] British English&lt;br /&gt;
| Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange &lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_de.png]] German&lt;br /&gt;
| Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_fr.png]] French&lt;br /&gt;
| Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_cn.png]] Canadian French&lt;br /&gt;
|Supported&lt;br /&gt;
| &lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_es.png]] Spanish &lt;br /&gt;
|Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_mx.png]] Mexican Spanish &lt;br /&gt;
|Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_nl.png]] Dutch &lt;br /&gt;
| Supported&lt;br /&gt;
| Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_pl.png]] Polish&lt;br /&gt;
| Supported&lt;br /&gt;
|Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:japanese.jpeg]] Japanese&lt;br /&gt;
|Supported&lt;br /&gt;
|Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Flag_it.png]] Italian&lt;br /&gt;
|Supported&lt;br /&gt;
|Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:china.jpg]] Simplified Chinese&lt;br /&gt;
|Supported&lt;br /&gt;
|Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:china.jpg]] Traditional Chinese&lt;br /&gt;
|Supported&lt;br /&gt;
|Online Help/Manual&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:ungarn.jpg]] Hungarian&lt;br /&gt;
|Supported&lt;br /&gt;
| &lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Slovakia.jpg]] Slovak&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:Czech.jpg]] Czech&lt;br /&gt;
|Supported&lt;br /&gt;
| &lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:latvia.jpg]] Latvian&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
|Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
|[[Image:Flag_romania.png]] Romanian&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[Image:brazil.png|17px]] Brazilian Portuguese&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Flag_se.png|17px]] Swedish&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Flag_dk.png|17px]] Danish&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Russian.png|17px]] Russian&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[File:flag_fin.png|17px]] Finnish&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|-&lt;br /&gt;
| [[File:flag_Tur.png|17px]] Turkish&lt;br /&gt;
| Supported&lt;br /&gt;
|&lt;br /&gt;
| Open-Xchange&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Any other languages which may be provided by installation packages are not supported and might even have a bad UI/UX impact when installed. Please use at your own risk!&lt;br /&gt;
&lt;br /&gt;
[[Category: OX7]]&lt;br /&gt;
[[Category: AppSuite]]&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:Capabilities&amp;diff=25260</id>
		<title>AppSuite:Capabilities</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:Capabilities&amp;diff=25260"/>
		<updated>2020-02-26T15:55:58Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Synopsis:&#039;&#039;&#039; How to use capabilities so that your new AppSuite plugin can be enabled or disabled.&lt;br /&gt;
&lt;br /&gt;
__TOC__&lt;br /&gt;
&lt;br /&gt;
== What are capabilities? == &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Usecase&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
You write a new UI app or plugin (chat module, for example) and in addition, you want to make sure that only a specific set of users or contexts within the system are allowed to use it. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Example:&#039;&#039; Your chat app should only be available after a user has bought it in your online shop. To do so, you will need to implement the capabilities logic within your UI app or plugin and restrict it to a user or context marked accordingly (called &amp;quot;premium&amp;quot; in further examples).&lt;br /&gt;
&lt;br /&gt;
== Set a capability ==&lt;br /&gt;
&lt;br /&gt;
First, disable it for everyone as default (or enable it for everyone, depending on what your aim is). &lt;br /&gt;
&lt;br /&gt;
In &amp;lt;tt&amp;gt;/opt/open-xchange/etc/[myproduct].properties&amp;lt;/tt&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
  com.openexchange.capability.[myproduct]=false # off for everyone&lt;br /&gt;
&lt;br /&gt;
Then restart the OX Application Server and afterwards use the general OX AppSuite commandline tools to enable the capability/capabilities. &lt;br /&gt;
&lt;br /&gt;
The commandline tools used in the following examples are located in: &lt;br /&gt;
&lt;br /&gt;
  /opt/open-xchange/sbin&lt;br /&gt;
&lt;br /&gt;
In this example, only for a specific user:&lt;br /&gt;
&lt;br /&gt;
  changeuser ... --config/com.openexchange.capability.[myproduct]=true&lt;br /&gt;
&lt;br /&gt;
...or for a full context:&lt;br /&gt;
  changecontext -c ... --config/com.openexchange.capability.[myproduct]=true&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
...or set the capability to a context set:&lt;br /&gt;
&lt;br /&gt;
  changecontext -c ... --taxonomy/types=premium&lt;br /&gt;
&lt;br /&gt;
To get the capability/capabilities working for context sets (like above), you also need to edit the contextSet files in:&lt;br /&gt;
&lt;br /&gt;
  &amp;lt;tt&amp;gt;/opt/open-xchange/etc/contextSets/premium.yml&amp;lt;/tt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
And add the corresponding capability/capabilities:&lt;br /&gt;
&lt;br /&gt;
  premium:&lt;br /&gt;
     com.openexchange.capability.[myproduct]: true&lt;br /&gt;
     withTags: premium&lt;br /&gt;
&lt;br /&gt;
Then restart the OX Application Server!&lt;br /&gt;
&lt;br /&gt;
== Query capabilities via the HTTP API ==&lt;br /&gt;
&lt;br /&gt;
Query:&lt;br /&gt;
  GET /appsuite/api/capabilities?action=all&amp;amp;session=991fd40f635b45...&lt;br /&gt;
Response:&lt;br /&gt;
  {&amp;quot;data&amp;quot;:[{&amp;quot;id&amp;quot;:&amp;quot;oauth&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;webmail&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;document_preview&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;printing&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;spreadsheet&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;gab&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;multiple_mail_accounts&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;publication&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;rss_bookmarks&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;linkedin&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;filestore&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;ical&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;rt&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;olox20&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;forum&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;active_sync&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;conflict_handling&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;rss_portal&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;oxupdater&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;infostore&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;contacts&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;collect_email_addresses&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;drive&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;rss&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;pinboard_write_access&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;mobility&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;calendar&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;participants_dialog&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;edit_public_folders&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;text&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;groupware&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;msisdn&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;carddav&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;tasks&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;portal&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;mailfilter&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;read_create_shared_folders&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;vcard&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;pim&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;caldav&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;projects&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;usm&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;webdav&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;dev&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;delegate_tasks&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;freebusy&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;subscription&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;linkedinPlus&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;autologin&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;webdav_xml&amp;quot;,&amp;quot;attributes&amp;quot;:{}},{&amp;quot;id&amp;quot;:&amp;quot;twitter&amp;quot;,&amp;quot;attributes&amp;quot;:{}}]}&lt;br /&gt;
&lt;br /&gt;
Here &amp;lt;tt&amp;gt;id&amp;lt;/tt&amp;gt; is the name of the capability.&lt;br /&gt;
&lt;br /&gt;
Note that the LinkedIn support was removed since 7.10.0&lt;br /&gt;
&lt;br /&gt;
== Query capabilities in the UI ==&lt;br /&gt;
  require([&#039;io.ox/core/capabilities&#039;], function (cap) { if cap.has(&#039;[myproduct]&#039; { ... } );&lt;br /&gt;
&lt;br /&gt;
To just list all:&lt;br /&gt;
&lt;br /&gt;
  _(ox.serverConfig.capabilities).pluck(&amp;quot;id&amp;quot;).sort();&lt;br /&gt;
&lt;br /&gt;
== Require the capabilities in your UI manifest file ==&lt;br /&gt;
  {&lt;br /&gt;
     namespace: ...&lt;br /&gt;
     requires: &#039;[myproduct]&#039;&lt;br /&gt;
  }&lt;br /&gt;
&lt;br /&gt;
Now your plugin will only be loaded if the capability &#039;[myproduct]&#039; is set for a specific user, context, context set.&lt;br /&gt;
&lt;br /&gt;
== Testing the capabilities ==&lt;br /&gt;
&lt;br /&gt;
* For testing purposes use an URL parameter to test capabilities. &lt;br /&gt;
&lt;br /&gt;
Add the following parameter to your AppSuite URL in the browser to activate:&lt;br /&gt;
&lt;br /&gt;
  &amp;amp;cap=[myproduct]&lt;br /&gt;
&lt;br /&gt;
or use &lt;br /&gt;
&lt;br /&gt;
  &amp;amp;disableFeature=[myproduct]&lt;br /&gt;
&lt;br /&gt;
to disable a certain capability. &lt;br /&gt;
&lt;br /&gt;
In general, after adding those URL parameters, you need to reload the UI to temporarly test/enable the set capability.&lt;br /&gt;
&lt;br /&gt;
== Further informations == &lt;br /&gt;
* See the dedicated wiki page of the [[ConfigCascade]] mechanism for more details.&lt;br /&gt;
* If you want to know about existing capabilities and the way they are used for upsell, see [[AppSuite:Upsell#Capabilities_and_Upsell_triggers]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: AppSuite]]&lt;br /&gt;
[[Category: Upsell]]&lt;br /&gt;
&lt;br /&gt;
[[Category: Developer]]&lt;br /&gt;
[[Category: Custom development]]&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=OX_as_a_Service_Provisioning_using_SOAP&amp;diff=25242</id>
		<title>OX as a Service Provisioning using SOAP</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=OX_as_a_Service_Provisioning_using_SOAP&amp;diff=25242"/>
		<updated>2020-02-04T11:26:53Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Tutorial: Provision OX as a Service using SOAP =&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
&lt;br /&gt;
[[OX_as_a_Service_Guide|OX as a Service]] is using the same code everybody can download and install using our&lt;br /&gt;
various guides. Since it is a hosted service using a reseller model, the provisioning api is using the [[Reseller_Bundle|Reseller Bundle]]&lt;br /&gt;
to extend the usual two administrative layers by an additional one.&lt;br /&gt;
&lt;br /&gt;
Open-Xchange does also not contain a mail server in general, but requires one in order to act like a mail client. OX as a Service&lt;br /&gt;
is using [https://www.open-xchange.com/portfolio/ox-dovecot-pro/ OX Dovecot Pro] as mail server and thus extends the usual Open-Xchange provisioning capabilities by mechanisms&lt;br /&gt;
to manage some email specific settings.&lt;br /&gt;
&lt;br /&gt;
== Open-Xchange concept of Contexts ==&lt;br /&gt;
&lt;br /&gt;
In order to provision users and groups into Open-Xchange, it is important to understand, that Open-Xchange is designed&lt;br /&gt;
for shared hosting environments in a way that it has to serve multiple tenants, customers, domains, or however you want to&lt;br /&gt;
name it. In Open-Xchange, we call that a &#039;&#039;&#039;Context&#039;&#039;&#039;. A context is a sealed container for users and groups. Users in a&lt;br /&gt;
context can not see users of other contexts, nor can they share data with users of other contexts (with the exception of&lt;br /&gt;
Open-Xchange publish and subscribe functionality).&lt;br /&gt;
&lt;br /&gt;
A usual scenario is to have a company, a family or in general one end customer in a context. One can also say, a context&lt;br /&gt;
is a domain, and usually that makes sense, since a company has one domain. However, Open-Xchange contexts are not limited&lt;br /&gt;
to one domain only.&lt;br /&gt;
&lt;br /&gt;
== Open-Xchange concept of provisioning ==&lt;br /&gt;
&lt;br /&gt;
A plain Open-Xchange installation consists of two administrative levels.&lt;br /&gt;
&lt;br /&gt;
# root level, usually we call that oxadminmaster&lt;br /&gt;
# context level&lt;br /&gt;
&lt;br /&gt;
=== oxadminmaster / root ===&lt;br /&gt;
&lt;br /&gt;
The root, or oxadminmaster account is used to&lt;br /&gt;
&lt;br /&gt;
* add, remove and configure filestores attached to Open-Xchange&lt;br /&gt;
* add, remove and configure databases attached to Open-Xchange&lt;br /&gt;
* add, remove and configure contexts&lt;br /&gt;
&lt;br /&gt;
and change parameters like add/remove domains, change per context filesystem quota, etc.&lt;br /&gt;
&lt;br /&gt;
Depending on the OX configuration, it is not able to add or remove users and groups, nor any other data within a context!&lt;br /&gt;
&lt;br /&gt;
=== Context admin ===&lt;br /&gt;
&lt;br /&gt;
The context admin is like an ordinary Open-Xchange user, except that it can add, remove and edit&lt;br /&gt;
users and groups within Open-Xchange using the provisioning API.&lt;br /&gt;
In addition, it inherits shared data of users, that are deleted.&lt;br /&gt;
&#039;&#039;&#039;In OX as a Service, however, the context admin cannot read, send or receive mail.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== OX as a Service concept of provisioning ==&lt;br /&gt;
&lt;br /&gt;
As written before, plain Open-Xchange only has one root account. In a reseller scenario, that would&lt;br /&gt;
mean if we want resellers to be able to create contexts for their customers, we would have to hand out our&lt;br /&gt;
root account. Since that is not desirable, we added another layer via the [[Reseller_Bundle|Reseller Bundle]] as&lt;br /&gt;
mentioned earlier.&lt;br /&gt;
&lt;br /&gt;
# root level, usually we call that oxadminmaster&lt;br /&gt;
# subadmin level / brand level&lt;br /&gt;
# context level&lt;br /&gt;
&lt;br /&gt;
root and context level don&#039;t change, except that context level can be [[Reseller_Bundle#Restrictions|restricted]].&lt;br /&gt;
&lt;br /&gt;
The subadmin account can only add, remove or configure contexts. Depending on the configuration of the&lt;br /&gt;
OX as a Service tenant, it can or can NOT add, remove and configure users within contexts.&lt;br /&gt;
Contexts created by a subadmin account can not be seen by other subadmin accounts.&lt;br /&gt;
&lt;br /&gt;
=== What is a brand? ===&lt;br /&gt;
&lt;br /&gt;
A brand is a customers subadmin login to the OXaaS SOAP provisioning API.&lt;br /&gt;
&lt;br /&gt;
== OX as a Service specifics ==&lt;br /&gt;
&lt;br /&gt;
=== Shared domains, explicit domains and ordinary domains ===&lt;br /&gt;
&lt;br /&gt;
==== Ordinary domains ====&lt;br /&gt;
&lt;br /&gt;
In order to create a user in Open-Xchange, you have to set an email address for that user.&lt;br /&gt;
This will directly lead into a domain to be created into OXaaS bound to that user and its context,&lt;br /&gt;
if that domain does not already exists and is owned by a different context.&lt;br /&gt;
&lt;br /&gt;
==== Shared domains ====&lt;br /&gt;
&lt;br /&gt;
If you want to share domains between all contexts, you have to use shared domains.&lt;br /&gt;
Shared domains must be created in advance using the &amp;lt;tt&amp;gt;createSharedDomain&amp;lt;/tt&amp;gt; method (see [[#OXaaS_specific_methods|OXaaS specific methods]])&lt;br /&gt;
or using the [https://documentation.open-xchange.com/components/cloudplugins/1.9.1/#tag/Shared-Domains REST API] (needs recent version).&lt;br /&gt;
&lt;br /&gt;
==== Explicit domains ====&lt;br /&gt;
&lt;br /&gt;
Recent versions support another type of domain called explicit domains. These domains must be explicitly added to contexts using the [https://documentation.open-xchange.com/components/cloudplugins/1.9.1/#tag/Explicit-Domains REST API] (needs recent version). You can add the same explicit domain to one or multiple contexts. If a context already contains an ordinary domain of the same name, it will be transformed into an explicit domain.&lt;br /&gt;
&lt;br /&gt;
Note that the explicit domain feature is not available by default, it must be activated for each customer, individually.&lt;br /&gt;
&lt;br /&gt;
You can use the &amp;lt;tt&amp;gt;existsMailAlias&amp;lt;/tt&amp;gt; method to check for the existence of an alias before you create it.&lt;br /&gt;
&lt;br /&gt;
=== Catchall accounts ===&lt;br /&gt;
&lt;br /&gt;
If the feature is enabled in your contract, you can create catchall mail aliases bound to users&lt;br /&gt;
within contexts.&lt;br /&gt;
&lt;br /&gt;
=== User permissions ===&lt;br /&gt;
&lt;br /&gt;
See [[OX_as_a_Service_Provisioning_using_SOAP#Set_OXaaS_permissions|OXaaS permission]] description below.&lt;br /&gt;
&lt;br /&gt;
=== User name/login uniqueness ===&lt;br /&gt;
&lt;br /&gt;
Due to the architecture of OXaaS, a login/username must be unique across all created contexts. That means it is not&lt;br /&gt;
possible to create two &amp;quot;oxadmin&amp;quot; accounts. This limitation applies per brand.&lt;br /&gt;
&lt;br /&gt;
=== Display name uniqueness ===&lt;br /&gt;
&lt;br /&gt;
In contrary to the login/name of users, display names must only be unique within each context.&lt;br /&gt;
That is because it is used e.g. in the shared folder list of e.g. calendar, drive, contacts in OX.&lt;br /&gt;
Also it is used as folder name when mounting OX via WEBDAV.&lt;br /&gt;
&lt;br /&gt;
It is no problem, however, to have one &amp;quot;Steve Smith&amp;quot; in one context, and another &amp;quot;Steve Smith” in another context.&lt;br /&gt;
&lt;br /&gt;
=== No email for &amp;quot;oxadmin&amp;quot; ===&lt;br /&gt;
&lt;br /&gt;
The architecture of OX as a Service does not allow the context admin to have email.&lt;br /&gt;
&lt;br /&gt;
== Provisioning ==&lt;br /&gt;
&lt;br /&gt;
=== OXaaS specific methods ===&lt;br /&gt;
&lt;br /&gt;
==== SOAP API ====&lt;br /&gt;
&lt;br /&gt;
The following SOAP methods are specific to OXaaS and are NOT part of the general Open-Xchange provisioning API.&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+ OXaaS specific SOAP calls and its authentication requirements&lt;br /&gt;
! Method&lt;br /&gt;
! Functionality&lt;br /&gt;
! Authentication&lt;br /&gt;
|-&lt;br /&gt;
! getQuotaUsage&lt;br /&gt;
| get the overall mail quota usage of all users within the given context&lt;br /&gt;
| Subadmin&lt;br /&gt;
|-&lt;br /&gt;
! createSharedDomain&lt;br /&gt;
| create a shared domain&lt;br /&gt;
| Subadmin&lt;br /&gt;
|-&lt;br /&gt;
! existsLogin&lt;br /&gt;
| check whether user login already exists. Note: a users login must be unique within all users for your subadmin account and NOT only per context!&lt;br /&gt;
| Subadmin&lt;br /&gt;
|-&lt;br /&gt;
! existsMailAlias&lt;br /&gt;
| check whether given mail alias already exists&lt;br /&gt;
| Subadmin&lt;br /&gt;
|-&lt;br /&gt;
! createDomainCatchall&lt;br /&gt;
| create a domain catchall&lt;br /&gt;
| Subadmin&lt;br /&gt;
|-&lt;br /&gt;
! getQuotaUsagePerUser&lt;br /&gt;
| get mail quota usage of the individual user within the given context&lt;br /&gt;
| Subadmin&lt;br /&gt;
|-&lt;br /&gt;
! listDomainCatchalls&lt;br /&gt;
| list all existing domain catchalls&lt;br /&gt;
| Subadmin&lt;br /&gt;
|-&lt;br /&gt;
! setMailQuota&lt;br /&gt;
| set the mail quota of the individual user within the context&lt;br /&gt;
| Context Admin&lt;br /&gt;
|-&lt;br /&gt;
! deleteDomainCatchall&lt;br /&gt;
| delete the given domain catchall&lt;br /&gt;
| Subadmin&lt;br /&gt;
|-&lt;br /&gt;
! getPermissions&lt;br /&gt;
| list given users permissions&lt;br /&gt;
| Subadmin&lt;br /&gt;
|-&lt;br /&gt;
! enablePermissions&lt;br /&gt;
| enable provided permissions for given user&lt;br /&gt;
| Subadmin&lt;br /&gt;
|-&lt;br /&gt;
! disablePermissions&lt;br /&gt;
| enable provided permissions for given user&lt;br /&gt;
| Subadmin&lt;br /&gt;
|-&lt;br /&gt;
! setExpiryDate&lt;br /&gt;
| store expiry date for the given user&lt;br /&gt;
| Context Admin&lt;br /&gt;
|-&lt;br /&gt;
! getExpiryDate&lt;br /&gt;
| get expiry date stored for user&lt;br /&gt;
| Context Admin&lt;br /&gt;
|-&lt;br /&gt;
! deleteExpiryDate&lt;br /&gt;
| delete the expiry date stored in the given user&lt;br /&gt;
| Context Admin&lt;br /&gt;
|-&lt;br /&gt;
! getExpiredUsers &lt;br /&gt;
| retrieve list of expired users&lt;br /&gt;
| Subadmin&lt;br /&gt;
|-&lt;br /&gt;
! getMailQuota&lt;br /&gt;
| get the mail quota of the individual user within the context&lt;br /&gt;
| Subadmin&lt;br /&gt;
|-&lt;br /&gt;
! setPasswordHash&lt;br /&gt;
| directly store provided pwHash into userPassword attribute of matching ldap entry. Note: Input will be validated against valid mechanisms.&lt;br /&gt;
| Context Admin&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The WSDL source file for these methods contain documentation for each of the calls and parameters.&lt;br /&gt;
You can download it here: http://software.open-xchange.com/products/appsuite/doc/oxasservice/OXaaSService.wsdl&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note that the mail quota usage and max values are the combined values of drive and mail quota in case the system has [https://documentation.open-xchange.com/latest/middleware/miscellaneous/quota.html#unified-quota unified quota] enabled.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==== REST API ====&lt;br /&gt;
&lt;br /&gt;
There&#039;s a growing number of REST APIs to access OXaaS, see https://documentation.open-xchange.com/, section &#039;&#039;Cloud Plugins API&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== OX Core Provisioning API ===&lt;br /&gt;
&lt;br /&gt;
The core provisioning API consists of four namespaces:&lt;br /&gt;
&lt;br /&gt;
# Context management&lt;br /&gt;
# User management&lt;br /&gt;
# Group management&lt;br /&gt;
# Resource management&lt;br /&gt;
&lt;br /&gt;
Some of these namespaces share the same data structures such as &amp;lt;tt&amp;gt;Credentials&amp;lt;/tt&amp;gt;, &amp;lt;tt&amp;gt;Context&amp;lt;/tt&amp;gt; and &amp;lt;tt&amp;gt;User&amp;lt;/tt&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:provisioning-core.png|1000 px]]&lt;br /&gt;
&lt;br /&gt;
=== Reference implementation ===&lt;br /&gt;
&lt;br /&gt;
The reference implementation of the European OX as a Service system can be found in the {{APSPackage|name=OX as a Service}} APS package&lt;br /&gt;
for [http://www.odin.com/products/automation/ Odin Service Automation].&lt;br /&gt;
&lt;br /&gt;
=== Workflow ===&lt;br /&gt;
&lt;br /&gt;
==== Subadmin credentials ====&lt;br /&gt;
&lt;br /&gt;
The first requirement is to get subadmin credentials for your company. Please follow the steps&lt;br /&gt;
[[OX_as_a_Service_Guide#How_to_become_a_customer.3F|documented here]] to get such an account.&lt;br /&gt;
&lt;br /&gt;
Together with the login and password you will also retrieve the provisioning URL to be used by&lt;br /&gt;
all SOAP requests. In addition, it is required that you give us a list of ip addresses or network(s)&lt;br /&gt;
that should be allowed to access the provisioning system.&lt;br /&gt;
&lt;br /&gt;
==== WSDL files ====&lt;br /&gt;
&lt;br /&gt;
Just point your browser to the provisioning URL you got from us. You will find some services listed there.&lt;br /&gt;
You will need the following services from that list:&lt;br /&gt;
&lt;br /&gt;
; https://hostname/webservices/OXaaSService?wsdl: OX as a Service specific functions&lt;br /&gt;
; https://hostname/webservices/OXResellerContextService?wsdl: Context management&lt;br /&gt;
; https://hostname/webservices/OXResellerUserService?wsdl: User management&lt;br /&gt;
&lt;br /&gt;
and optionally&lt;br /&gt;
&lt;br /&gt;
; https://hostname/webservices/OXResellerGroupService?wsdl: Group management&lt;br /&gt;
; https://hostname/webservices/OXResellerResourceService?wsdl: Resource management&lt;br /&gt;
&lt;br /&gt;
==== SOAP API documentation ====&lt;br /&gt;
&lt;br /&gt;
The general SOAP API documentation can be found at this URL:&lt;br /&gt;
http://software.open-xchange.com/products/appsuite/doc/SOAP/admin/OX-Admin-SOAP.html&lt;br /&gt;
&lt;br /&gt;
That document contains links to the Javadoc documentation for the RMI api, but&lt;br /&gt;
that is more or less the same as the SOAP API.&lt;br /&gt;
&lt;br /&gt;
In addition, there&#039;s the general, non OXaaS specific [[Open-Xchange_Provisioning_using_SOAP|wiki page]].&lt;br /&gt;
&lt;br /&gt;
==== Create a context ====&lt;br /&gt;
&lt;br /&gt;
Once you have the credentials in place, you are ready to create your first context.&lt;br /&gt;
&lt;br /&gt;
Creating a context requires to create the first user in that context, that is the context admin, see above.&lt;br /&gt;
&lt;br /&gt;
Mandatory settings for a context are&lt;br /&gt;
&lt;br /&gt;
; name: name of the context&lt;br /&gt;
; quota: file quota in MB for that context (&#039;&#039;&#039;Note:&#039;&#039;&#039; that is file, not mail!)&lt;br /&gt;
; taxonomy: must be set to the login of your subadmin account, see below&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Important:&#039;&#039;&#039; In OXaaS, the name of the context must always start with your subadmin login with an underscore appended. E.g. when&lt;br /&gt;
your subadmin login is &amp;lt;tt&amp;gt;johndoe&amp;lt;/tt&amp;gt;, the all your context names must start with &amp;lt;tt&amp;gt;johndoe_&amp;lt;/tt&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
Optional settings&lt;br /&gt;
&lt;br /&gt;
; mainColor: io.ox/dynamic-theme//mainColor&lt;br /&gt;
; linkColor: io.ox/dynamic-theme//linkColor&lt;br /&gt;
; for further theme parameters, check https://documentation.open-xchange.com/latest/ui/theming/dynamic-theming.html&lt;br /&gt;
&lt;br /&gt;
; id: A numerical id bound to the context. When you create a context, this id will be generated. You will need that later when you manage users. The id can be looked up via the context name.&lt;br /&gt;
&lt;br /&gt;
===== userAttributes =====&lt;br /&gt;
&lt;br /&gt;
The settings brandtaxonomy and the other optional settings except id are part of the userAttributes SOAP field.&lt;br /&gt;
All other settings can easily be set via simple SOAP settings. userAttributes is a hash that contains some settings&lt;br /&gt;
that are not available in all setups of Open-Xchange. It allows to extend Open-Xchange functionality dynamically like&lt;br /&gt;
done in OXaaS.&lt;br /&gt;
&lt;br /&gt;
The hash looks like this:&lt;br /&gt;
&lt;br /&gt;
 userAttributes =&amp;gt; entries =&amp;gt; EntryArray&lt;br /&gt;
 &lt;br /&gt;
 with EntryArray :=&lt;br /&gt;
 &lt;br /&gt;
 [&lt;br /&gt;
   { key   =&amp;gt; &amp;quot;somekey&amp;quot;&lt;br /&gt;
     value =&amp;gt; somevalue },&lt;br /&gt;
   { key   =&amp;gt; &amp;quot;someotherkey&amp;quot;&lt;br /&gt;
     value =&amp;gt; someothervalue },&lt;br /&gt;
   ...&lt;br /&gt;
 ]&lt;br /&gt;
 &lt;br /&gt;
 somevalue can be an array again, e.g.:&lt;br /&gt;
 &lt;br /&gt;
 somevalue =&amp;gt; entries =&amp;gt; EntryArray&lt;br /&gt;
 &lt;br /&gt;
 with EntryArray :=&lt;br /&gt;
 &lt;br /&gt;
 [&lt;br /&gt;
   { key   =&amp;gt; &amp;quot;somekey&amp;quot;&lt;br /&gt;
     value =&amp;gt; somevalue },&lt;br /&gt;
   { key   =&amp;gt; &amp;quot;someotherkey&amp;quot;&lt;br /&gt;
     value =&amp;gt; someothervalue },&lt;br /&gt;
   ...&lt;br /&gt;
 ]&lt;br /&gt;
 &lt;br /&gt;
 and so on&lt;br /&gt;
&lt;br /&gt;
Example dump using perls &amp;lt;code&amp;gt;Data::Dumper&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;perl&amp;quot;&amp;gt;&lt;br /&gt;
          &#039;userAttributes&#039; =&amp;gt; {&lt;br /&gt;
                              &#039;entries&#039; =&amp;gt; [&lt;br /&gt;
                                           {&lt;br /&gt;
                                             &#039;value&#039; =&amp;gt; {&lt;br /&gt;
                                                        &#039;entries&#039; =&amp;gt; [&lt;br /&gt;
                                                                     {&lt;br /&gt;
                                                                       &#039;value&#039; =&amp;gt; &#039;#0000ff&#039;,&lt;br /&gt;
                                                                       &#039;key&#039; =&amp;gt; &#039;io.ox/dynamic-theme//topbarHover&#039;&lt;br /&gt;
                                                                     },&lt;br /&gt;
                                                                     {&lt;br /&gt;
                                                                       &#039;value&#039; =&amp;gt; &#039;#ff0000&#039;,&lt;br /&gt;
                                                                       &#039;key&#039; =&amp;gt; &#039;io.ox/dynamic-theme//linkColor&#039;&lt;br /&gt;
                                                                     },&lt;br /&gt;
                                                                     {&lt;br /&gt;
                                                                       &#039;value&#039; =&amp;gt; &#039;#00ff00&#039;,&lt;br /&gt;
                                                                       &#039;key&#039; =&amp;gt; &#039;io.ox/dynamic-theme//mainColor&#039;&lt;br /&gt;
                                                                     },&lt;br /&gt;
                                                                     {&lt;br /&gt;
                                                                       &#039;value&#039; =&amp;gt; &#039;true&#039;,&lt;br /&gt;
                                                                       &#039;key&#039; =&amp;gt; &#039;com.openexchange.capability.dynamic-theme&#039;&lt;br /&gt;
                                                                     }                                                                   ]&lt;br /&gt;
                                                      },&lt;br /&gt;
                                             &#039;key&#039; =&amp;gt; &#039;config&#039;&lt;br /&gt;
                                           },&lt;br /&gt;
                                           {&lt;br /&gt;
                                             &#039;value&#039; =&amp;gt; {&lt;br /&gt;
                                                        &#039;entries&#039; =&amp;gt; {&lt;br /&gt;
                                                                     &#039;value&#039; =&amp;gt; &#039;johndoe&#039;,&lt;br /&gt;
                                                                     &#039;key&#039; =&amp;gt; &#039;types&#039;&lt;br /&gt;
                                                                   }&lt;br /&gt;
                                                      },&lt;br /&gt;
                                             &#039;key&#039; =&amp;gt; &#039;taxonomy&#039;&lt;br /&gt;
                                           }&lt;br /&gt;
                                         ]&lt;br /&gt;
                            },&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===== Admin User =====&lt;br /&gt;
&lt;br /&gt;
; name: login name of the context admin&lt;br /&gt;
; password: password&lt;br /&gt;
; email: email address of the context admin&lt;br /&gt;
; displayname: displayname (usually surname givenname)&lt;br /&gt;
; surname: surname&lt;br /&gt;
; givenname: given name&lt;br /&gt;
; lang: language, e.g. en_GB, en_US, de_DE, ...&lt;br /&gt;
; timezone: Java timezone such as Europe/Berlin,&lt;br /&gt;
&lt;br /&gt;
====== Timezones ======&lt;br /&gt;
&lt;br /&gt;
To get a list of all available timezones, you can run this short Java program:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;java&amp;quot;&amp;gt;&lt;br /&gt;
import java.util.TimeZone;&lt;br /&gt;
&lt;br /&gt;
public class AllTimeZones {&lt;br /&gt;
    public static void main(String[] args) {&lt;br /&gt;
        for(final String zone : TimeZone.getAvailableIDs() ) {&lt;br /&gt;
            System.out.println(zone);&lt;br /&gt;
        }&lt;br /&gt;
    }&lt;br /&gt;
&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====== Languages ======&lt;br /&gt;
&lt;br /&gt;
This is the list of currently supported languages in OXaaS:&lt;br /&gt;
&lt;br /&gt;
 ja_JP&lt;br /&gt;
 de_DE&lt;br /&gt;
 es_ES&lt;br /&gt;
 es_MX&lt;br /&gt;
 fr_FR&lt;br /&gt;
 it_IT&lt;br /&gt;
 nl_NL&lt;br /&gt;
 pl_PL&lt;br /&gt;
 zh_TW&lt;br /&gt;
 en_US&lt;br /&gt;
 en_GB&lt;br /&gt;
&lt;br /&gt;
==== Create users ====&lt;br /&gt;
&lt;br /&gt;
Creating users requires the following parameters&lt;br /&gt;
&lt;br /&gt;
; name: login name of the context admin&lt;br /&gt;
; password: password&lt;br /&gt;
; email: email address of the context admin&lt;br /&gt;
; displayname: displayname (usually surname givenname)&lt;br /&gt;
; surname: surname&lt;br /&gt;
; givenname: given name&lt;br /&gt;
; lang: language, e.g. en_GB, en_US, de_DE, ...&lt;br /&gt;
; timezone: Java timezone such as Europe/Berlin,&lt;br /&gt;
; moduleaccess: the module access combination name&lt;br /&gt;
; mailquota: the mail quota of the user in MB&lt;br /&gt;
&lt;br /&gt;
Timezones and languages like documented earlier.&lt;br /&gt;
&lt;br /&gt;
Valid values for moduleaccess are:&lt;br /&gt;
&lt;br /&gt;
* webmail_plus&lt;br /&gt;
* groupware_standard&lt;br /&gt;
* groupware_advanced&lt;br /&gt;
* groupware_premium&lt;br /&gt;
&lt;br /&gt;
Other settings are not supported.&lt;br /&gt;
&lt;br /&gt;
===== userAttributes =====&lt;br /&gt;
&lt;br /&gt;
It might be required you have to set some specific attributes per user like the Edition Type as&lt;br /&gt;
done by the OXaaS APS package.&lt;br /&gt;
&lt;br /&gt;
There&#039;s a choice of 7 different edition types:&lt;br /&gt;
&lt;br /&gt;
; webmail: bound to webmail_plus&lt;br /&gt;
; basic: bound to groupware_standard&lt;br /&gt;
; advanced: bound to groupware_advanced&lt;br /&gt;
; pro: bound to groupware_premium&lt;br /&gt;
; pro_m: bound to groupware_premium&lt;br /&gt;
; pro_l: bound to groupware_premium&lt;br /&gt;
; pro_xl: bound to groupware_premium&lt;br /&gt;
&lt;br /&gt;
which can be set within each users oxaas_edition_type within a tree oxaas:&lt;br /&gt;
&lt;br /&gt;
 &#039;userAttributes&#039; =&amp;gt; {&lt;br /&gt;
                     &#039;entries&#039; =&amp;gt; {&lt;br /&gt;
                                  &#039;key&#039; =&amp;gt; &#039;oxaas&#039;,&lt;br /&gt;
                                  &#039;value&#039; =&amp;gt; {&lt;br /&gt;
                                             &#039;entries&#039; =&amp;gt; {&lt;br /&gt;
                                                          &#039;key&#039; =&amp;gt; &#039;oxaas_edition_type&#039;,&lt;br /&gt;
                                                          &#039;value&#039; =&amp;gt; &#039;pro_l&#039;&lt;br /&gt;
                                                          }&lt;br /&gt;
                                             }&lt;br /&gt;
                                 }&lt;br /&gt;
                     }&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
see [[#Standalone_example:_createOXaaSUser|createuser example script]]&lt;br /&gt;
&lt;br /&gt;
===== Create the user in Open-Xchange =====&lt;br /&gt;
&lt;br /&gt;
* Use the name and password of the context admin user of the context you created earlier and define&lt;br /&gt;
a Credentials object.&lt;br /&gt;
* Find the numerical id of the context e.g. in using &amp;lt;code&amp;gt;OXResellerContextService-&amp;gt;getData(name=&amp;quot;contextname&amp;quot;)&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Use the &amp;lt;code&amp;gt;OXResellerUserService-&amp;gt;createByModuleAccessName&amp;lt;/code&amp;gt; to create users.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; Although there are three create methods in the SOAP user service API, you have to use the method &amp;lt;code&amp;gt;createByModuleAccessName&amp;lt;/code&amp;gt;&lt;br /&gt;
and specify one of the names listed above.&lt;br /&gt;
&lt;br /&gt;
===== Set mail quota =====&lt;br /&gt;
&lt;br /&gt;
* Use the name and password of the context admin user of the context you created earlier and define&lt;br /&gt;
a Credentials object.&lt;br /&gt;
* Find the numerical id of the context e.g. in using &amp;lt;code&amp;gt;OXResellerContextService-&amp;gt;getData(name=&amp;quot;contextname&amp;quot;)&amp;lt;/code&amp;gt;&lt;br /&gt;
* Find the numerical id of the user either by using &amp;lt;code&amp;gt;OXResellerUserService-&amp;gt;getData(name=&amp;quot;username&amp;quot;)&amp;lt;/code&amp;gt; or use/store the return value of &amp;lt;code&amp;gt;OXResellerUserService-&amp;gt;createByModuleAccessName&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Use the &amp;lt;code&amp;gt;OXaaSService-&amp;gt;setMailQuota&amp;lt;/code&amp;gt; call to set the mail quota for the user created above.&lt;br /&gt;
&lt;br /&gt;
===== Set OXaaS permissions =====&lt;br /&gt;
&lt;br /&gt;
====== Explanation ======&lt;br /&gt;
&lt;br /&gt;
The OXaaS permissions allow to enable or disable a certain set of features.&lt;br /&gt;
Currently, the following permissions are available:&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+ OXaaS permissions&lt;br /&gt;
! Permission&lt;br /&gt;
! Description&lt;br /&gt;
|-&lt;br /&gt;
! SEND&lt;br /&gt;
| User is allowed to send mail&lt;br /&gt;
|-&lt;br /&gt;
! RECEIVE&lt;br /&gt;
| User is allowed to receive mail&lt;br /&gt;
|-&lt;br /&gt;
! MAILLOGIN&lt;br /&gt;
| User can login using IMAP from external; webmail is not affected&lt;br /&gt;
|-&lt;br /&gt;
! WEBLOGIN&lt;br /&gt;
| User can login to OX webmail.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The permission names are case insensitive.&lt;br /&gt;
The WEBLOGIN permission is the same as the [http://software.open-xchange.com/products/appsuite/doc/RMI/admin-core/com/openexchange/admin/rmi/dataobjects/User.html#setMailenabled%28java.lang.Boolean%29 &amp;lt;tt&amp;gt;Mailenabled&amp;lt;/tt&amp;gt;] permission in the user data of the Open-Xchange core api. The permission&lt;br /&gt;
OXaaS api provides another way to enable/disable it.&lt;br /&gt;
&lt;br /&gt;
* Use the name and password of the context admin user of the context you created earlier and define&lt;br /&gt;
a Credentials object.&lt;br /&gt;
* Find the numerical id of the context e.g. in using &amp;lt;code&amp;gt;OXResellerContextService-&amp;gt;getData(name=&amp;quot;contextname&amp;quot;)&amp;lt;/code&amp;gt;&lt;br /&gt;
* Find the numerical id of the user either by using &amp;lt;code&amp;gt;OXResellerUserService-&amp;gt;getData(name=&amp;quot;username&amp;quot;)&amp;lt;/code&amp;gt; or use/store the return value of &amp;lt;code&amp;gt;OXResellerUserService-&amp;gt;createByModuleAccessName&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Use one of &amp;lt;code&amp;gt;OXaaSService-&amp;gt;enablePermissions&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;OXaaSService-&amp;gt;disablePermissions&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;OXaaSService-&amp;gt;getPermissions&amp;lt;/code&amp;gt;&lt;br /&gt;
to change or retrieve permissions. Permissions must always be provided as an array of 1 or more permissions.&lt;br /&gt;
&lt;br /&gt;
=== SOAP provisioning feature matrix ===&lt;br /&gt;
&lt;br /&gt;
(WIP)&lt;br /&gt;
&lt;br /&gt;
The table below shows what method(s) to use and what to set in order to configure the different feature sets.&lt;br /&gt;
&lt;br /&gt;
The value in the row &#039;&#039;Module Access Name&#039;&#039; must be given as a parameter to &amp;lt;code&amp;gt;OXResellerUserService-&amp;gt;changeByModuleAccessName&amp;lt;/code&amp;gt;&lt;br /&gt;
or &amp;lt;code&amp;gt;OXResellerUserService-&amp;gt;createByModuleAccessName&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
The values in the row &#039;&#039;Capabilities&#039;&#039; must be given as parameters to the &amp;lt;code&amp;gt;userAttributes&amp;lt;/code&amp;gt; member of the &amp;lt;code&amp;gt;User&amp;lt;/code&amp;gt; object that&lt;br /&gt;
should be changed and then passed to &amp;lt;code&amp;gt;OXResellerUserService-&amp;gt;change&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;OXResellerUserService-&amp;gt;createByModuleAccessName&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note: &amp;lt;code&amp;gt;OXResellerUserService-&amp;gt;changeByModuleAccessName&amp;lt;/code&amp;gt; does NOT change these capabilities!&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+ Provisioning Feature Matrix&lt;br /&gt;
! Feature&lt;br /&gt;
! Module Access Name&lt;br /&gt;
! Capabilities &#039;&#039;(mandatory values in bold, others are optional)&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
! Web Mail&lt;br /&gt;
| webmail_plus&lt;br /&gt;
| &amp;lt;tt&amp;gt;com.openexchange.capability.drive = &#039;&#039;&#039;false&#039;&#039;&#039;&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.document_preview = &#039;&#039;&#039;false&#039;&#039;&#039;&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.spreadsheet = &#039;&#039;&#039;false&#039;&#039;&#039;&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.text = &#039;&#039;&#039;false&#039;&#039;&#039;&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.presenter = &#039;&#039;&#039;false&#039;&#039;&#039;&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.remote_presenter = &#039;&#039;&#039;false&#039;&#039;&#039;&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.guard = &#039;&#039;&#039;false&#039;&#039;&#039;&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.guard-mail = &#039;&#039;&#039;false&#039;&#039;&#039;&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.guard-drive = &#039;&#039;&#039;false&#039;&#039;&#039;&amp;lt;/tt&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
! Basic&lt;br /&gt;
| &amp;lt;tt&amp;gt;groupware_standard&amp;lt;/tt&amp;gt;&lt;br /&gt;
| &amp;lt;tt&amp;gt;com.openexchange.capability.drive = &#039;&#039;&#039;true&#039;&#039;&#039;&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.document_preview = true/false&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.spreadsheet = true/false&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.text = true/false&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.presenter = true/false&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.remote_presenter = true/false&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.guard = true/false&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.guard-mail = true/false&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.guard-drive = true/false&amp;lt;/tt&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
! Advanced&lt;br /&gt;
| &amp;lt;tt&amp;gt;groupware_advanced&amp;lt;/tt&amp;gt;&lt;br /&gt;
| &amp;lt;tt&amp;gt;com.openexchange.capability.drive = &#039;&#039;&#039;true&#039;&#039;&#039;&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.document_preview = true/false&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.spreadsheet = true/false&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.text = true/false&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.presenter = true/false&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.remote_presenter = true/false&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.guard = true/false&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.guard-mail = true/false&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.guard-drive = true/false&amp;lt;/tt&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
! Pro&lt;br /&gt;
| &amp;lt;tt&amp;gt;groupware_premium&amp;lt;/tt&amp;gt;&lt;br /&gt;
| &amp;lt;tt&amp;gt;com.openexchange.capability.drive = &#039;&#039;&#039;true&#039;&#039;&#039;&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.document_preview = &#039;&#039;&#039;true&#039;&#039;&#039;&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.spreadsheet = &#039;&#039;&#039;true&#039;&#039;&#039;&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.text = &#039;&#039;&#039;true&#039;&#039;&#039;&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.presenter = &#039;&#039;&#039;true&#039;&#039;&#039;&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.remote_presenter = &#039;&#039;&#039;true&#039;&#039;&#039;&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.guard = true/false&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.guard-mail = true/false&amp;lt;/tt&amp;gt;&amp;lt;br&amp;gt;&amp;lt;tt&amp;gt;com.openexchange.capability.guard-drive = true/false&amp;lt;/tt&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== List of available capabilities (incomplete) ===&lt;br /&gt;
&lt;br /&gt;
These features are controlled by the [[ConfigCascade]].&lt;br /&gt;
&lt;br /&gt;
For drive and documents the following settings are responsible:&lt;br /&gt;
&lt;br /&gt;
; OX Drive :&lt;br /&gt;
&amp;lt;tt&amp;gt;com.openexchange.capability.drive = true/false&amp;lt;/tt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
; OX Docs :&lt;br /&gt;
&amp;lt;tt&amp;gt;com.openexchange.capability.document_preview = true/false&amp;lt;/tt&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;tt&amp;gt;com.openexchange.capability.spreadsheet = true/false&amp;lt;/tt&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;tt&amp;gt;com.openexchange.capability.text = true/false&amp;lt;/tt&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;tt&amp;gt;com.openexchange.capability.presentation = true/false&amp;lt;/tt&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;tt&amp;gt;com.openexchange.capability.remote_presenter = true/false&amp;lt;/tt&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;tt&amp;gt;com.openexchange.capability.guard-docs = true/false&amp;lt;/tt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
; OX Guard :&lt;br /&gt;
&amp;lt;tt&amp;gt;com.openexchange.capability.guard = true/false&amp;lt;/tt&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;tt&amp;gt;com.openexchange.capability.guard-mail = true/false&amp;lt;/tt&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;tt&amp;gt;com.openexchange.capability.guard-drive = true/false&amp;lt;/tt&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Using [[OX_as_a_Service_Provisioning_using_SOAP#Standalone_example:_createOXaaSContext|this perl example]]:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
e.g. this&lt;br /&gt;
&lt;br /&gt;
       logouturl =&amp;gt; {&lt;br /&gt;
               setting =&amp;gt; &amp;quot;io.ox/core//customLocations/logout&amp;quot;,&lt;br /&gt;
               value   =&amp;gt; &amp;quot;logouturl&amp;quot;&lt;br /&gt;
       }&lt;br /&gt;
&lt;br /&gt;
is setting the ConfigCascade setting &amp;lt;tt&amp;gt;io.ox/core//customLocations/logout&amp;lt;/tt&amp;gt; to the string “logouturl&amp;quot;&lt;br /&gt;
&lt;br /&gt;
  io.ox/core//customLocations/logout = &amp;quot;logouturl&amp;quot;&lt;br /&gt;
&lt;br /&gt;
adding&lt;br /&gt;
&lt;br /&gt;
       oxdrive =&amp;gt; {&lt;br /&gt;
               setting =&amp;gt; &amp;quot;com.openexchange.capability.drive&amp;quot;,&lt;br /&gt;
               value   =&amp;gt; &amp;quot;true&amp;quot;&lt;br /&gt;
       }&lt;br /&gt;
&lt;br /&gt;
in that example would turn on drive.&lt;br /&gt;
&lt;br /&gt;
== Code Examples ==&lt;br /&gt;
&lt;br /&gt;
=== Java ===&lt;br /&gt;
&lt;br /&gt;
==== Generating the SOAP client ====&lt;br /&gt;
&lt;br /&gt;
Since Open-Xchange is using [http://cxf.apache.org/ Apache CXF] for SOAP, we recommend to use the &amp;lt;tt&amp;gt;wsdl2java&amp;lt;/tt&amp;gt;&lt;br /&gt;
code generator from that package.&lt;br /&gt;
&lt;br /&gt;
The Open-Xchange SOAP services are divided into multiple parts, which makes the code generation a little&lt;br /&gt;
complex.&lt;br /&gt;
&lt;br /&gt;
In OXaaS we need at least three services in order to create contexts and users:&lt;br /&gt;
&lt;br /&gt;
* OXResellerContextService&lt;br /&gt;
* OXResellerUserService&lt;br /&gt;
* OXaaSService&lt;br /&gt;
&lt;br /&gt;
The shell script below generates the stubs of these three services into the directory defined in the &amp;lt;tt&amp;gt;CODEBASE&amp;lt;/tt&amp;gt;&lt;br /&gt;
variable. In addition, you have to set &amp;lt;tt&amp;gt;WSDLURL&amp;lt;/tt&amp;gt; to point it to the provisioning URL you will get from us as&lt;br /&gt;
mentioned [[#Subadmin_credentials|earlier]].&lt;br /&gt;
&lt;br /&gt;
Note: when running against a DEV container without valid SSL certs (e.g. self-signed SSL certs), it is required to add the servers cert into your java keystore first:&lt;br /&gt;
&lt;br /&gt;
# Get the cert e.g. by &amp;lt;code&amp;gt;openssl s_client -connect my.oxaas.webservices.host.net:443&amp;lt;/code&amp;gt; (the part between BEGIN CERTIFICATE and END CERTIFICATE) or by exporting from a web browser. Put it in a file named for example &amp;lt;code&amp;gt;my.oxaas.webservices.host.net.crt&amp;lt;/code&amp;gt;.&lt;br /&gt;
# Import it in a custom TrustStore. Assign a password; in this example we assume &amp;quot;secret&amp;quot;: &amp;lt;code&amp;gt;keytool -import -trustcacerts -alias my.oxaas.webservices.host.net -keystore my.oxaas.webservices.host.net.jks -file my.oxaas.webservices.host.net.crt -storetype JKS&amp;lt;/code&amp;gt;&lt;br /&gt;
# Supply it to the JVM by patching the CXF wsdl2java script (e.g. &amp;lt;code&amp;gt;/opt/apache-cxf-3.1.14/bin/wsdl2java&amp;lt;/code&amp;gt;) and add the following arguments: &amp;lt;code&amp;gt;-Djavax.net.ssl.trustStore=my.oxaas.webservices.host.net.jks -Djavax.net.ssl.trustStorePassword=secret -Djavax.net.ssl.trustStoreType=JKS&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Copy&amp;amp;paste the shell script below into a file and run it using the &amp;lt;tt&amp;gt;bash&amp;lt;/tt&amp;gt; shell. &amp;lt;b&amp;gt;Warning:&amp;lt;/b&amp;gt; the script assumes the CODEBASE target lives in its own dedicated ecplise project, and executes a &amp;lt;code&amp;gt;rm -rf $CODEBASE&amp;lt;/code&amp;gt; for a clean start. For other usecases (shared eclipse project, etc), please adjust to your needs / be careful!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# 1. download apache-cxf tarball, extract it and &amp;quot;cd&amp;quot; into the directory, e.g.&lt;br /&gt;
#    tar zxvpf apache-cxf-3.1.10.tar.gz; cd apache-cxf-3.1.10&lt;br /&gt;
#    NOTE: cxf versions 3.0 do NOT work ootb with java-1.8!&lt;br /&gt;
# 2. change variables CODEBASE, JAVA_HOME and WSDLURL&lt;br /&gt;
# 3. run this script &amp;quot;bash oxaas-wsdl2java&amp;quot;&lt;br /&gt;
export JAVA_HOME=&amp;quot;/usr/lib/jvm/java-1.8.0-openjdk-amd64/&amp;quot;&lt;br /&gt;
CODEBASE=&amp;quot;/home/oxgit/workspace/OXaaSJClient/src&amp;quot;&lt;br /&gt;
WSDLURL=&amp;quot;https://youroxaashost/webservices&amp;quot;&lt;br /&gt;
&lt;br /&gt;
rm -rf $CODEBASE&lt;br /&gt;
frontend=jaxws21&lt;br /&gt;
dbinding=jaxb&lt;br /&gt;
&lt;br /&gt;
JAXBTMP=/tmp/jaxb$$.xml&lt;br /&gt;
rm -f $JAXBTMP&lt;br /&gt;
cat&amp;lt;&amp;lt;EOF &amp;gt; $JAXBTMP&lt;br /&gt;
&amp;lt;jaxb:bindings version=&amp;quot;2.1&amp;quot;&lt;br /&gt;
xmlns:jaxb=&amp;quot;http://java.sun.com/xml/ns/jaxb&amp;quot;&lt;br /&gt;
xmlns:xjc=&amp;quot;http://java.sun.com/xml/ns/jaxb/xjc&amp;quot;&lt;br /&gt;
xmlns:xs=&amp;quot;http://www.w3.org/2001/XMLSchema&amp;quot;&amp;gt;&lt;br /&gt;
   &amp;lt;jaxb:globalBindings generateElementProperty=&amp;quot;false&amp;quot;/&amp;gt;&lt;br /&gt;
&amp;lt;/jaxb:bindings&amp;gt;&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
pname=&amp;quot;com.openexchange.oxaas.context&amp;quot;&lt;br /&gt;
bin/wsdl2java -databinding $dbinding -frontend $frontend -client -impl -d $CODEBASE -keep -b $JAXBTMP \&lt;br /&gt;
-p &amp;quot;http://soap.reseller.admin.openexchange.com=${pname}&amp;quot; \&lt;br /&gt;
-p &amp;quot;http://dataobjects.rmi.reseller.admin.openexchange.com/xsd=${pname}.reseller.rmi.dataobjects&amp;quot; \&lt;br /&gt;
-p &amp;quot;http://dataobjects.soap.reseller.admin.openexchange.com/xsd=${pname}.reseller.soap.dataobjects&amp;quot; \&lt;br /&gt;
-p &amp;quot;http://dataobjects.soap.admin.openexchange.com/xsd=${pname}.soap.dataobjects&amp;quot; \&lt;br /&gt;
-p &amp;quot;http://dataobjects.rmi.admin.openexchange.com/xsd=${pname}.rmi.dataobjects&amp;quot; \&lt;br /&gt;
-p &amp;quot;http://exceptions.rmi.admin.openexchange.com/xsd=${pname}.rmi.exceptions&amp;quot; \&lt;br /&gt;
-p &amp;quot;http://rmi.java/xsd=${pname}.java.rmi&amp;quot; \&lt;br /&gt;
-p &amp;quot;http://io.java/xsd=${pname}.java.io&amp;quot; \&lt;br /&gt;
${WSDLURL}/OXResellerContextService?wsdl&lt;br /&gt;
&lt;br /&gt;
pname=&amp;quot;com.openexchange.oxaas.user&amp;quot;&lt;br /&gt;
bin/wsdl2java -databinding $dbinding -frontend $frontend -client -impl -d $CODEBASE -keep -b $JAXBTMP \&lt;br /&gt;
-p &amp;quot;http://soap.reseller.admin.openexchange.com=${pname}&amp;quot; \&lt;br /&gt;
-p &amp;quot;http://dataobjects.rmi.reseller.admin.openexchange.com/xsd=${pname}.reseller.rmi.dataobjects&amp;quot; \&lt;br /&gt;
-p &amp;quot;http://dataobjects.soap.reseller.admin.openexchange.com/xsd=${pname}.reseller.soap.dataobjects&amp;quot; \&lt;br /&gt;
-p &amp;quot;http://dataobjects.soap.admin.openexchange.com/xsd=${pname}.soap.dataobjects&amp;quot; \&lt;br /&gt;
-p &amp;quot;http://dataobjects.rmi.admin.openexchange.com/xsd=${pname}.rmi.dataobjects&amp;quot; \&lt;br /&gt;
-p &amp;quot;http://exceptions.rmi.admin.openexchange.com/xsd=${pname}.rmi.exceptions&amp;quot; \&lt;br /&gt;
-p &amp;quot;http://rmi.java/xsd=${pname}.java.rmi&amp;quot; \&lt;br /&gt;
-p &amp;quot;http://io.java/xsd=${pname}.java.io&amp;quot; \&lt;br /&gt;
${WSDLURL}/OXResellerUserService?wsdl&lt;br /&gt;
&lt;br /&gt;
pname=&amp;quot;com.openexchange.oxaas.extra&amp;quot;&lt;br /&gt;
bin/wsdl2java -databinding $dbinding -frontend $frontend -client -impl -d $CODEBASE -keep -b $JAXBTMP \&lt;br /&gt;
-p &amp;quot;http://soap.oxaas.admin.openexchange.com/=${pname}&amp;quot; \&lt;br /&gt;
${WSDLURL}/OXaaSService?wsdl&lt;br /&gt;
&lt;br /&gt;
rm -f $JAXBTMP&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
When you generate the code into an existing eclipse project, you should have three main packages as shown in&lt;br /&gt;
the image below&lt;br /&gt;
&lt;br /&gt;
[[File:OXaaSSOAPClientEclipse.png]]&lt;br /&gt;
&lt;br /&gt;
==== Example Client ====&lt;br /&gt;
&lt;br /&gt;
In the following example, the context creation and the user creation is separated into different&lt;br /&gt;
programs.&lt;br /&gt;
&lt;br /&gt;
To summarize some essential requirements from the example below:&lt;br /&gt;
&lt;br /&gt;
* The name of each context you create must start with your subadmin name followed by an underscore &amp;lt;tt&amp;gt;_&amp;lt;/tt&amp;gt;&lt;br /&gt;
* You must set the userAttribute &amp;lt;tt&amp;gt;taxonomy&amp;lt;/tt&amp;gt; at least&lt;br /&gt;
* The context admin user must get the &amp;lt;tt&amp;gt;groupware_premium&amp;lt;/tt&amp;gt; access permission&lt;br /&gt;
&lt;br /&gt;
===== Build / run instructions =====&lt;br /&gt;
&lt;br /&gt;
====== Eclipse ======&lt;br /&gt;
&lt;br /&gt;
We assume, you have created the Java client stub(s) as documented above and have it as a separate eclipse project. The individual clients given below are assumed to live in a different ecplise project which references the Java client stubs in their classpath.&lt;br /&gt;
&lt;br /&gt;
====== Command Line ======&lt;br /&gt;
&lt;br /&gt;
For maximum simplicity let&#039;s assume you use the source files given below without the &amp;lt;code&amp;gt;package&amp;lt;/code&amp;gt; statement. Put them in an &amp;lt;code&amp;gt;examples/&amp;lt;/code&amp;gt; subdirectory.&lt;br /&gt;
&lt;br /&gt;
Let&#039;s assume furthermore you created the Java client stubs in a different directory, e.g. &amp;lt;code&amp;gt;codebase/&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Change into that directory to compile all the Java stub files&lt;br /&gt;
&lt;br /&gt;
 cd codebase/&lt;br /&gt;
 find . -name \*.java  | xargs javac&lt;br /&gt;
&lt;br /&gt;
Back in the working directory where the source files given below are created, you can compile / run them like&lt;br /&gt;
&lt;br /&gt;
 cd ../examples/&lt;br /&gt;
 javac -cp ../codebase MyContextClientExample.java&lt;br /&gt;
 java -cp .:../codebase MyContextClientExample&lt;br /&gt;
&lt;br /&gt;
====== SSL-related hints ======&lt;br /&gt;
&lt;br /&gt;
When working against a dev machine with self-signed certs, the same certificate trust related options are required as explained above for the &amp;lt;code&amp;gt;wsdl2java&amp;lt;/code&amp;gt; script (with the same TrustStore and password):&lt;br /&gt;
&lt;br /&gt;
 -Djavax.net.ssl.trustStore=my.oxaas.webservices.host.net.jks -Djavax.net.ssl.trustStorePassword=secret -Djavax.net.ssl.trustStoreType=JKS&lt;br /&gt;
&lt;br /&gt;
It might be additionally helpful to enable SSL debug output: &amp;lt;code&amp;gt;-Djavax.net.debug=ssl&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As of now (2017-11) there is a flaw in the generated WSDL that it references HTTP SOAP addresses even when using HTTPS. This results in client programs trying to access the API via plain HTTP even after a successful SSL handshake and fetching the WSDL via HTTPS. This is bad as SOAP frames travel the network with credentials included in plain text.&lt;br /&gt;
&lt;br /&gt;
A possible workaround for the time being is to forcefully rewrite the protocol part of the different port urls into https with something like:&lt;br /&gt;
&lt;br /&gt;
After initializing the contextport using ...&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;java&amp;quot;&amp;gt;&lt;br /&gt;
OXResellerContextServicePortType contextport = contextservice.getOXResellerContextServiceHttpSoap11Endpoint();  &lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
... add the following code:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;java&amp;quot;&amp;gt;&lt;br /&gt;
// insert in your imports section:&lt;br /&gt;
// import javax.xml.ws.BindingProvider;&lt;br /&gt;
((BindingProvider)contextport).getRequestContext().put(&lt;br /&gt;
    BindingProvider.ENDPOINT_ADDRESS_PROPERTY,&lt;br /&gt;
    ((String)((BindingProvider)contextport).getRequestContext()&lt;br /&gt;
        .get(BindingProvider.ENDPOINT_ADDRESS_PROPERTY))&lt;br /&gt;
        .replaceAll(&amp;quot;^http:&amp;quot;, &amp;quot;https:&amp;quot;));&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Similar adjustments are required for &amp;lt;code&amp;gt;userport&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;oxaasport&amp;lt;/code&amp;gt;, where they occur.&lt;br /&gt;
&lt;br /&gt;
===== Context creation =====&lt;br /&gt;
&lt;br /&gt;
The example below shows how to create a context in OXaaS.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;java&amp;quot;&amp;gt;&lt;br /&gt;
package com.openexchange.oxaas.myclient;&lt;br /&gt;
&lt;br /&gt;
import java.io.IOException;&lt;br /&gt;
import java.util.List;&lt;br /&gt;
import javax.xml.namespace.QName;&lt;br /&gt;
import com.openexchange.oxaas.context.ContextExistsExceptionException;&lt;br /&gt;
import com.openexchange.oxaas.context.DatabaseUpdateExceptionException;&lt;br /&gt;
import com.openexchange.oxaas.context.Delete;&lt;br /&gt;
import com.openexchange.oxaas.context.DuplicateExtensionExceptionException;&lt;br /&gt;
import com.openexchange.oxaas.context.InvalidCredentialsExceptionException;&lt;br /&gt;
import com.openexchange.oxaas.context.InvalidDataExceptionException;&lt;br /&gt;
import com.openexchange.oxaas.context.NoSuchContextExceptionException;&lt;br /&gt;
import com.openexchange.oxaas.context.OXResellerContextService;&lt;br /&gt;
import com.openexchange.oxaas.context.OXResellerContextServicePortType;&lt;br /&gt;
import com.openexchange.oxaas.context.RemoteExceptionException;&lt;br /&gt;
import com.openexchange.oxaas.context.StorageExceptionException;&lt;br /&gt;
import com.openexchange.oxaas.context.reseller.soap.dataobjects.ResellerContext;&lt;br /&gt;
import com.openexchange.oxaas.context.rmi.dataobjects.Credentials;&lt;br /&gt;
import com.openexchange.oxaas.context.soap.dataobjects.Entry;&lt;br /&gt;
import com.openexchange.oxaas.context.soap.dataobjects.SOAPMapEntry;&lt;br /&gt;
import com.openexchange.oxaas.context.soap.dataobjects.SOAPStringMap;&lt;br /&gt;
import com.openexchange.oxaas.context.soap.dataobjects.SOAPStringMapMap;&lt;br /&gt;
import com.openexchange.oxaas.context.soap.dataobjects.User;&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
 * Example SOAP client for OXaaS OXResellerContextService&lt;br /&gt;
 * &lt;br /&gt;
 * Create a context&lt;br /&gt;
 * &lt;br /&gt;
 */&lt;br /&gt;
public class MyContextClientExample {&lt;br /&gt;
&lt;br /&gt;
    private static final QName SERVICE_NAME = new QName(&amp;quot;http://soap.reseller.admin.openexchange.com&amp;quot;, &amp;quot;OXResellerContextService&amp;quot;);&lt;br /&gt;
&lt;br /&gt;
    public static void main(String[] args) {&lt;br /&gt;
        final String subadminname = &amp;quot;mysubadmin&amp;quot;;&lt;br /&gt;
        final String subadminpw   = &amp;quot;secret&amp;quot;;&lt;br /&gt;
        final String ctxname      = subadminname + &amp;quot;_myctx&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
        Credentials creds = new Credentials();&lt;br /&gt;
        ResellerContext ctx = new ResellerContext();&lt;br /&gt;
        User oxadmin = new User();&lt;br /&gt;
&lt;br /&gt;
        OXResellerContextService contextservice = new OXResellerContextService(OXResellerContextService.WSDL_LOCATION, SERVICE_NAME);&lt;br /&gt;
        OXResellerContextServicePortType contextport = contextservice.getOXResellerContextServiceHttpSoap11Endpoint();  &lt;br /&gt;
&lt;br /&gt;
        creds.setLogin(subadminname);&lt;br /&gt;
        creds.setPassword(subadminpw);&lt;br /&gt;
&lt;br /&gt;
        SOAPMapEntry taxonomy = new SOAPMapEntry();&lt;br /&gt;
        taxonomy.setKey(&amp;quot;taxonomy&amp;quot;);&lt;br /&gt;
        SOAPStringMap taxtypeval = new SOAPStringMap();&lt;br /&gt;
        Entry taxtypeent = new Entry();&lt;br /&gt;
        taxtypeent.setKey(&amp;quot;types&amp;quot;);&lt;br /&gt;
        taxtypeent.setValue(subadminname);&lt;br /&gt;
        taxtypeval.getEntries().add(taxtypeent);&lt;br /&gt;
        taxonomy.setValue(taxtypeval);&lt;br /&gt;
&lt;br /&gt;
        SOAPMapEntry config = new SOAPMapEntry();&lt;br /&gt;
        config.setKey(&amp;quot;config&amp;quot;);&lt;br /&gt;
        SOAPStringMap configEntries = new SOAPStringMap();&lt;br /&gt;
&lt;br /&gt;
        Entry topbarHover = new Entry();&lt;br /&gt;
        topbarHover.setKey(&amp;quot;io.ox/dynamic-theme//topbarHover&amp;quot;);&lt;br /&gt;
        topbarHover.setValue(&amp;quot;#0000ff&amp;quot;);&lt;br /&gt;
&lt;br /&gt;
        Entry mainColor = new Entry();&lt;br /&gt;
        mainColor.setKey(&amp;quot;io.ox/dynamic-theme//mainColor&amp;quot;);&lt;br /&gt;
        mainColor.setValue(&amp;quot;#ff0000&amp;quot;);&lt;br /&gt;
&lt;br /&gt;
        Entry linkColor = new Entry();&lt;br /&gt;
        linkColor.setKey(&amp;quot;io.ox/dynamic-theme//linkColor&amp;quot;);&lt;br /&gt;
        linkColor.setValue(&amp;quot;#00ff00&amp;quot;);&lt;br /&gt;
&lt;br /&gt;
        Entry dynThemeCapa = new Entry();&lt;br /&gt;
        dynThemeCapa.setKey(&amp;quot;com.openexchange.capability.dynamic-theme&amp;quot;);&lt;br /&gt;
        dynThemeCapa.setValue(&amp;quot;true&amp;quot;);&lt;br /&gt;
&lt;br /&gt;
        configEntries.getEntries().add(topbarHover);&lt;br /&gt;
        configEntries.getEntries().add(mainColor);&lt;br /&gt;
        configEntries.getEntries().add(linkColor);&lt;br /&gt;
        configEntries.getEntries().add(dynThemeCapa);&lt;br /&gt;
        config.setValue(configEntries);&lt;br /&gt;
&lt;br /&gt;
        SOAPStringMapMap userattrs = new SOAPStringMapMap();&lt;br /&gt;
        userattrs.getEntries().add(taxonomy);&lt;br /&gt;
        userattrs.getEntries().add(config);&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
        ctx.setName(ctxname);&lt;br /&gt;
        ctx.setMaxQuota(10000l);&lt;br /&gt;
        ctx.setUserAttributes(userattrs);&lt;br /&gt;
&lt;br /&gt;
        final String adminEmail = &amp;quot;oxadmin@example.com&amp;quot;;&lt;br /&gt;
        final String ctxadmname = &amp;quot;oxadmin&amp;quot;;&lt;br /&gt;
        final String ctxadmpw   = &amp;quot;secret&amp;quot;;&lt;br /&gt;
        oxadmin.setName(ctxadmname);&lt;br /&gt;
        oxadmin.setPassword(ctxadmpw);&lt;br /&gt;
        oxadmin.setDisplayName(&amp;quot;OX Admin&amp;quot;);&lt;br /&gt;
        oxadmin.setSurName(&amp;quot;OX&amp;quot;);&lt;br /&gt;
        oxadmin.setGivenName(&amp;quot;Admin&amp;quot;);&lt;br /&gt;
        oxadmin.setPrimaryEmail(adminEmail);&lt;br /&gt;
        oxadmin.setEmail1(adminEmail);&lt;br /&gt;
        oxadmin.setDefaultSenderAddress(adminEmail);&lt;br /&gt;
        oxadmin.setLanguage(&amp;quot;en_US&amp;quot;);&lt;br /&gt;
        oxadmin.setTimezone(&amp;quot;Europe/Berlin&amp;quot;);&lt;br /&gt;
&lt;br /&gt;
        try {&lt;br /&gt;
            ResellerContext ret = contextport.createModuleAccessByName(ctx, oxadmin, &amp;quot;groupware_premium&amp;quot;, creds, null);&lt;br /&gt;
            System.out.println(&amp;quot;created context with id=&amp;quot; + ret.getId());&lt;br /&gt;
&lt;br /&gt;
            System.out.println(&amp;quot;existing contexts:&amp;quot;);&lt;br /&gt;
            List&amp;lt;ResellerContext&amp;gt; allctxs = contextport.listAll(creds);&lt;br /&gt;
            for(final ResellerContext c : allctxs) {&lt;br /&gt;
                System.out.println(c.getName() + &amp;quot; with id=&amp;quot; + c.getId());&lt;br /&gt;
            }&lt;br /&gt;
&lt;br /&gt;
            System.in.read();&lt;br /&gt;
&lt;br /&gt;
            System.out.println(&amp;quot;deleting created context again&amp;quot;);&lt;br /&gt;
            Delete del = new Delete();&lt;br /&gt;
            del.setAuth(creds);&lt;br /&gt;
            del.setCtx(ctx);&lt;br /&gt;
            contextport.delete(del);&lt;br /&gt;
        } catch (InvalidDataExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (ContextExistsExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (DuplicateExtensionExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (InvalidCredentialsExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (RemoteExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (StorageExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (IOException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (NoSuchContextExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (DatabaseUpdateExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        }&lt;br /&gt;
    }&lt;br /&gt;
&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===== User creation =====&lt;br /&gt;
&lt;br /&gt;
The client below utilizes all SOAP services we have created so far.&lt;br /&gt;
&lt;br /&gt;
The essential parts of the code are&lt;br /&gt;
&lt;br /&gt;
* use OXResellerContextService to find out the ID of the context you want to create users&lt;br /&gt;
* create users using OXResellerUserService&lt;br /&gt;
* use one of the moduleaccess values as documented [[#Create_users|earlier]]&lt;br /&gt;
* use setMailQuota from OXaaSService to set each users mail quota individually&lt;br /&gt;
* use existsLogin from OXaaSService to check in advance of a login already exists&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;java&amp;quot;&amp;gt;&lt;br /&gt;
package com.openexchange.oxaas.myclient;&lt;br /&gt;
&lt;br /&gt;
import java.io.IOException;&lt;br /&gt;
import javax.xml.namespace.QName;&lt;br /&gt;
import com.openexchange.oxaas.context.OXResellerContextService;&lt;br /&gt;
import com.openexchange.oxaas.context.OXResellerContextServicePortType;&lt;br /&gt;
import com.openexchange.oxaas.extra.ExistsLoginFaultException;&lt;br /&gt;
import com.openexchange.oxaas.extra.OXaaSService;&lt;br /&gt;
import com.openexchange.oxaas.extra.OXaaSService_Service;&lt;br /&gt;
import com.openexchange.oxaas.extra.SetMailQuotaFaultException;&lt;br /&gt;
import com.openexchange.oxaas.user.DatabaseUpdateExceptionException;&lt;br /&gt;
import com.openexchange.oxaas.user.Delete;&lt;br /&gt;
import com.openexchange.oxaas.user.DuplicateExtensionExceptionException;&lt;br /&gt;
import com.openexchange.oxaas.user.InvalidCredentialsExceptionException;&lt;br /&gt;
import com.openexchange.oxaas.user.InvalidDataExceptionException;&lt;br /&gt;
import com.openexchange.oxaas.user.NoSuchContextExceptionException;&lt;br /&gt;
import com.openexchange.oxaas.user.NoSuchUserExceptionException;&lt;br /&gt;
import com.openexchange.oxaas.user.OXResellerUserService;&lt;br /&gt;
import com.openexchange.oxaas.user.OXResellerUserServicePortType;&lt;br /&gt;
import com.openexchange.oxaas.user.RemoteExceptionException;&lt;br /&gt;
import com.openexchange.oxaas.user.StorageExceptionException;&lt;br /&gt;
import com.openexchange.oxaas.user.reseller.soap.dataobjects.ResellerContext;&lt;br /&gt;
import com.openexchange.oxaas.user.rmi.dataobjects.Credentials;&lt;br /&gt;
import com.openexchange.oxaas.user.soap.dataobjects.User;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
 * Example SOAP client for OXaaS OXResellerUserService&lt;br /&gt;
 * &lt;br /&gt;
 * Create users in a context&lt;br /&gt;
 * &lt;br /&gt;
 */&lt;br /&gt;
public class MyUserClientExample {&lt;br /&gt;
&lt;br /&gt;
    private static final QName USER_SERVICE_NAME = new QName(&amp;quot;http://soap.reseller.admin.openexchange.com&amp;quot;, &amp;quot;OXResellerUserService&amp;quot;);&lt;br /&gt;
    private static final QName CONTEXT_SERVICE_NAME = new QName(&amp;quot;http://soap.reseller.admin.openexchange.com&amp;quot;, &amp;quot;OXResellerContextService&amp;quot;);&lt;br /&gt;
    private static final QName OXAAS_SERVICE_NAME = new QName(&amp;quot;http://soap.oxaas.admin.openexchange.com/&amp;quot;, &amp;quot;OXaaSService&amp;quot;);&lt;br /&gt;
&lt;br /&gt;
    public static void main(String[] args) {&lt;br /&gt;
        final String subadminname = &amp;quot;mysubadmin&amp;quot;;&lt;br /&gt;
        final String subadminpw   = &amp;quot;secret&amp;quot;;&lt;br /&gt;
        final String ctxadmname   = &amp;quot;oxadmin&amp;quot;;&lt;br /&gt;
        final String ctxadmpw     = &amp;quot;secret&amp;quot;;&lt;br /&gt;
        final String ctxname      = subadminname + &amp;quot;_myctx&amp;quot;;&lt;br /&gt;
        &lt;br /&gt;
        Credentials creds = new Credentials();&lt;br /&gt;
        ResellerContext ctx = new ResellerContext();&lt;br /&gt;
        User auser = new User();&lt;br /&gt;
&lt;br /&gt;
        OXResellerUserService userservice = new OXResellerUserService(OXResellerUserService.WSDL_LOCATION, USER_SERVICE_NAME);&lt;br /&gt;
        OXResellerUserServicePortType userport = userservice.getOXResellerUserServiceHttpSoap12Endpoint();&lt;br /&gt;
        OXResellerContextService contextservice = new OXResellerContextService(OXResellerContextService.WSDL_LOCATION, CONTEXT_SERVICE_NAME);&lt;br /&gt;
        OXResellerContextServicePortType contextport = contextservice.getOXResellerContextServiceHttpSoap11Endpoint();&lt;br /&gt;
        OXaaSService_Service oxaasservice = new OXaaSService_Service(OXaaSService_Service.WSDL_LOCATION, OXAAS_SERVICE_NAME);&lt;br /&gt;
        OXaaSService oxaasport = oxaasservice.getOXaaSServiceSOAP();  &lt;br /&gt;
        &lt;br /&gt;
        &lt;br /&gt;
        // We need to use the ResellerContextService SOAP client stub to retrieve the context id&lt;br /&gt;
        com.openexchange.oxaas.context.rmi.dataobjects.Credentials ctxCreds = new com.openexchange.oxaas.context.rmi.dataobjects.Credentials();&lt;br /&gt;
        com.openexchange.oxaas.context.reseller.soap.dataobjects.ResellerContext ctxCtx = new com.openexchange.oxaas.context.reseller.soap.dataobjects.ResellerContext();&lt;br /&gt;
        ctxCreds.setLogin(subadminname);&lt;br /&gt;
        ctxCreds.setPassword(subadminpw);&lt;br /&gt;
        ctxCtx.setName(ctxname);&lt;br /&gt;
&lt;br /&gt;
        creds.setLogin(ctxadmname);&lt;br /&gt;
        creds.setPassword(ctxadmpw);&lt;br /&gt;
&lt;br /&gt;
        final String userEmail = &amp;quot;auser@example.com&amp;quot;;&lt;br /&gt;
        auser.setName(&amp;quot;auser&amp;quot;);&lt;br /&gt;
        auser.setPassword(&amp;quot;secret&amp;quot;);&lt;br /&gt;
        auser.setDisplayName(&amp;quot;My User&amp;quot;);&lt;br /&gt;
        auser.setSurName(&amp;quot;My&amp;quot;);&lt;br /&gt;
        auser.setGivenName(&amp;quot;User&amp;quot;);&lt;br /&gt;
        auser.setPrimaryEmail(userEmail);&lt;br /&gt;
        auser.setEmail1(userEmail);&lt;br /&gt;
        auser.setDefaultSenderAddress(userEmail);&lt;br /&gt;
        auser.setLanguage(&amp;quot;en_US&amp;quot;);&lt;br /&gt;
        auser.setTimezone(&amp;quot;Europe/Berlin&amp;quot;);&lt;br /&gt;
&lt;br /&gt;
        try {&lt;br /&gt;
            // we only have the name of the context, so we need to retrieve its id, first using ResellerContextService&lt;br /&gt;
            com.openexchange.oxaas.context.reseller.soap.dataobjects.ResellerContext ctxRet = contextport.getData(ctxCtx, ctxCreds);&lt;br /&gt;
            ctx.setId(ctxRet.getId());&lt;br /&gt;
&lt;br /&gt;
            // create the user via OXResellerUserService&lt;br /&gt;
            User ret = userport.createByModuleAccessName(ctx, auser, &amp;quot;groupware_premium&amp;quot;, creds);&lt;br /&gt;
            System.out.println(&amp;quot;created user with id=&amp;quot; + ret.getId());&lt;br /&gt;
            &lt;br /&gt;
            // set mail quota for that user using OXaaSService&lt;br /&gt;
            com.openexchange.oxaas.extra.Credentials oxaasCtxCreds = new com.openexchange.oxaas.extra.Credentials();&lt;br /&gt;
            oxaasCtxCreds.setLogin(ctxadmname);&lt;br /&gt;
            oxaasCtxCreds.setPassword(ctxadmpw);&lt;br /&gt;
            oxaasport.setMailQuota(ctxRet.getId(), ret.getId(), 1000l, oxaasCtxCreds);&lt;br /&gt;
            &lt;br /&gt;
            // check whether the login for the user has been created within my subadmin namespace&lt;br /&gt;
            // NOTE: this check should be used beforehand usually: check whether login exists and then create it if not&lt;br /&gt;
            com.openexchange.oxaas.extra.Credentials oxaasAdminCreds = new com.openexchange.oxaas.extra.Credentials();&lt;br /&gt;
            oxaasAdminCreds.setLogin(subadminname);&lt;br /&gt;
            oxaasAdminCreds.setPassword(subadminpw);&lt;br /&gt;
            if( oxaasport.existsLogin(&amp;quot;auser&amp;quot;, oxaasAdminCreds) ) {&lt;br /&gt;
                System.out.println(&amp;quot;all ok, user login has been created&amp;quot;);&lt;br /&gt;
            }&lt;br /&gt;
            &lt;br /&gt;
            System.in.read();&lt;br /&gt;
            &lt;br /&gt;
            System.out.println(&amp;quot;deleting created user again&amp;quot;);&lt;br /&gt;
            Delete del = new Delete();&lt;br /&gt;
            del.setAuth(creds);&lt;br /&gt;
            del.setCtx(ctx);&lt;br /&gt;
            del.setUser(ret);&lt;br /&gt;
            userport.delete(del);&lt;br /&gt;
        } catch (InvalidDataExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (NoSuchContextExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (DuplicateExtensionExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (DatabaseUpdateExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (InvalidCredentialsExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (RemoteExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (StorageExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (NoSuchUserExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (IOException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (com.openexchange.oxaas.context.InvalidDataExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (com.openexchange.oxaas.context.NoSuchContextExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (com.openexchange.oxaas.context.DuplicateExtensionExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (com.openexchange.oxaas.context.InvalidCredentialsExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (com.openexchange.oxaas.context.RemoteExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (com.openexchange.oxaas.context.StorageExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (SetMailQuotaFaultException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (ExistsLoginFaultException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        }&lt;br /&gt;
    }&lt;br /&gt;
&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===== Email (alias) management =====&lt;br /&gt;
&lt;br /&gt;
The next example shows how to manage email aliases and shared domains.&lt;br /&gt;
The essential information is:&lt;br /&gt;
&lt;br /&gt;
* if you want to change the email address of a user, you have to add the new address to the list of aliases&lt;br /&gt;
* when you want to change individual settings of a user, only send the changed settings&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;java&amp;quot;&amp;gt;&lt;br /&gt;
package com.openexchange.oxaas.myclient;&lt;br /&gt;
&lt;br /&gt;
import java.util.List;&lt;br /&gt;
import javax.xml.namespace.QName;&lt;br /&gt;
import com.openexchange.oxaas.context.OXResellerContextService;&lt;br /&gt;
import com.openexchange.oxaas.context.OXResellerContextServicePortType;&lt;br /&gt;
import com.openexchange.oxaas.extra.CreateSharedDomainFaultException;&lt;br /&gt;
import com.openexchange.oxaas.extra.OXaaSService;&lt;br /&gt;
import com.openexchange.oxaas.extra.OXaaSService_Service;&lt;br /&gt;
import com.openexchange.oxaas.user.Change;&lt;br /&gt;
import com.openexchange.oxaas.user.DatabaseUpdateExceptionException;&lt;br /&gt;
import com.openexchange.oxaas.user.DuplicateExtensionExceptionException;&lt;br /&gt;
import com.openexchange.oxaas.user.InvalidCredentialsExceptionException;&lt;br /&gt;
import com.openexchange.oxaas.user.InvalidDataExceptionException;&lt;br /&gt;
import com.openexchange.oxaas.user.NoSuchContextExceptionException;&lt;br /&gt;
import com.openexchange.oxaas.user.NoSuchUserExceptionException;&lt;br /&gt;
import com.openexchange.oxaas.user.OXResellerUserService;&lt;br /&gt;
import com.openexchange.oxaas.user.OXResellerUserServicePortType;&lt;br /&gt;
import com.openexchange.oxaas.user.RemoteExceptionException;&lt;br /&gt;
import com.openexchange.oxaas.user.StorageExceptionException;&lt;br /&gt;
import com.openexchange.oxaas.user.reseller.soap.dataobjects.ResellerContext;&lt;br /&gt;
import com.openexchange.oxaas.user.rmi.dataobjects.Credentials;&lt;br /&gt;
import com.openexchange.oxaas.user.soap.dataobjects.User;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
 * Example SOAP client for OXaaS OXResellerUserService&lt;br /&gt;
 * &lt;br /&gt;
 * Create users in a context&lt;br /&gt;
 * &lt;br /&gt;
 */&lt;br /&gt;
public class OXaaSAliasManagement {&lt;br /&gt;
&lt;br /&gt;
    private static final QName USER_SERVICE_NAME = new QName(&amp;quot;http://soap.reseller.admin.openexchange.com&amp;quot;, &amp;quot;OXResellerUserService&amp;quot;);&lt;br /&gt;
    private static final QName CONTEXT_SERVICE_NAME = new QName(&amp;quot;http://soap.reseller.admin.openexchange.com&amp;quot;, &amp;quot;OXResellerContextService&amp;quot;);&lt;br /&gt;
    private static final QName OXAAS_SERVICE_NAME = new QName(&amp;quot;http://soap.oxaas.admin.openexchange.com/&amp;quot;, &amp;quot;OXaaSService&amp;quot;);&lt;br /&gt;
&lt;br /&gt;
    public static void main(String[] args) {&lt;br /&gt;
        final String subadminname = &amp;quot;mysubadmin&amp;quot;;&lt;br /&gt;
        final String subadminpw   = &amp;quot;secret&amp;quot;;&lt;br /&gt;
        final String ctxadmname   = &amp;quot;oxadmin&amp;quot;;&lt;br /&gt;
        final String ctxadmpw     = &amp;quot;secret&amp;quot;;&lt;br /&gt;
        final String userlogin    = &amp;quot;auser&amp;quot;;&lt;br /&gt;
        final String ctxname      = subadminname + &amp;quot;_myctx&amp;quot;;&lt;br /&gt;
        &lt;br /&gt;
        Credentials creds = new Credentials();&lt;br /&gt;
        ResellerContext ctx = new ResellerContext();&lt;br /&gt;
&lt;br /&gt;
        OXResellerUserService userservice = new OXResellerUserService(OXResellerUserService.WSDL_LOCATION, USER_SERVICE_NAME);&lt;br /&gt;
        OXResellerUserServicePortType userport = userservice.getOXResellerUserServiceHttpSoap12Endpoint();&lt;br /&gt;
        OXResellerContextService contextservice = new OXResellerContextService(OXResellerContextService.WSDL_LOCATION, CONTEXT_SERVICE_NAME);&lt;br /&gt;
        OXResellerContextServicePortType contextport = contextservice.getOXResellerContextServiceHttpSoap11Endpoint();&lt;br /&gt;
        OXaaSService_Service oxaasservice = new OXaaSService_Service(OXaaSService_Service.WSDL_LOCATION, OXAAS_SERVICE_NAME);&lt;br /&gt;
        OXaaSService oxaasport = oxaasservice.getOXaaSServiceSOAP();  &lt;br /&gt;
        &lt;br /&gt;
        &lt;br /&gt;
        // We need to use the ResellerContextService SOAP client stub to retrieve the context id&lt;br /&gt;
        com.openexchange.oxaas.context.rmi.dataobjects.Credentials ctxCreds = new com.openexchange.oxaas.context.rmi.dataobjects.Credentials();&lt;br /&gt;
        com.openexchange.oxaas.context.reseller.soap.dataobjects.ResellerContext ctxCtx = new com.openexchange.oxaas.context.reseller.soap.dataobjects.ResellerContext();&lt;br /&gt;
        ctxCreds.setLogin(subadminname);&lt;br /&gt;
        ctxCreds.setPassword(subadminpw);&lt;br /&gt;
        ctxCtx.setName(ctxname);&lt;br /&gt;
&lt;br /&gt;
        creds.setLogin(ctxadmname);&lt;br /&gt;
        creds.setPassword(ctxadmpw);&lt;br /&gt;
&lt;br /&gt;
        try {&lt;br /&gt;
            // we only have the name of the context, so we need to retrieve its id, first using ResellerContextService&lt;br /&gt;
            com.openexchange.oxaas.context.reseller.soap.dataobjects.ResellerContext ctxRet = contextport.getData(ctxCtx, ctxCreds);&lt;br /&gt;
            ctx.setId(ctxRet.getId());&lt;br /&gt;
&lt;br /&gt;
            /*&lt;br /&gt;
             * now we want to add an alias to the user &amp;quot;auser&amp;quot;&lt;br /&gt;
             */&lt;br /&gt;
            User auser = new User();&lt;br /&gt;
            auser.setName(userlogin);&lt;br /&gt;
            User ret = userport.getData(ctx, auser, creds);&lt;br /&gt;
            List&amp;lt;String&amp;gt; aliases = ret.getAliases();&lt;br /&gt;
            // list all mail aliases of that user&lt;br /&gt;
            System.out.println(&amp;quot;User has the following alias(es):&amp;quot; + aliases);&lt;br /&gt;
            // now add another one&lt;br /&gt;
            aliases.add(&amp;quot;sales@example.com&amp;quot;);&lt;br /&gt;
&lt;br /&gt;
            // we also want to add an alias within a shared domain&lt;br /&gt;
            com.openexchange.oxaas.extra.Credentials oxaasCtxCreds = new com.openexchange.oxaas.extra.Credentials();&lt;br /&gt;
            oxaasCtxCreds.setLogin(subadminname);&lt;br /&gt;
            oxaasCtxCreds.setPassword(subadminpw);&lt;br /&gt;
            /*&lt;br /&gt;
             * Note: we can run this method as often as we want, it will ONLY return an error in case we want to add a shared domain&lt;br /&gt;
             * that is already bound to another subadmin/customer&lt;br /&gt;
             */&lt;br /&gt;
            oxaasport.createSharedDomain(&amp;quot;shared.net&amp;quot;, oxaasCtxCreds);&lt;br /&gt;
            aliases.add(&amp;quot;me@shared.net&amp;quot;);&lt;br /&gt;
            &lt;br /&gt;
            // store changes&lt;br /&gt;
            // we need to created a clean user instance since we cannot just store back the returned user&lt;br /&gt;
            User changeduser = new User();&lt;br /&gt;
            changeduser.setId(ret.getId());&lt;br /&gt;
            changeduser.getAliases().addAll(aliases);&lt;br /&gt;
            Change change = new Change();&lt;br /&gt;
            change.setAuth(creds);&lt;br /&gt;
            change.setCtx(ctx);&lt;br /&gt;
            change.setUsrdata(changeduser);&lt;br /&gt;
            userport.change(change);&lt;br /&gt;
            &lt;br /&gt;
            // control the result&lt;br /&gt;
            ret = userport.getData(ctx, auser, creds);&lt;br /&gt;
            aliases = ret.getAliases();&lt;br /&gt;
            // list all mail aliases of that user&lt;br /&gt;
            System.out.println(&amp;quot;User has the following alias(es):&amp;quot; + aliases);&lt;br /&gt;
            &lt;br /&gt;
            /*&lt;br /&gt;
             * now changing the users email address:&lt;br /&gt;
             * to do that, we have to do the following:&lt;br /&gt;
             * 1. add the new email address to the aliases, if not yet present&lt;br /&gt;
             * 2. change the email address in email1, defaultsenderaddress and primarymail&lt;br /&gt;
             * &lt;br /&gt;
             */&lt;br /&gt;
            String newaddress = &amp;quot;boss@mydomain.com&amp;quot;; // introduce another domain, not shared&lt;br /&gt;
            changeduser = new User();&lt;br /&gt;
            changeduser.setId(ret.getId());&lt;br /&gt;
            changeduser.setEmail1(newaddress);&lt;br /&gt;
            //reuse change from above&lt;br /&gt;
            change.setUsrdata(changeduser);&lt;br /&gt;
            try {&lt;br /&gt;
                // this will throw an error since the new address is not in the aliases&lt;br /&gt;
                userport.change(change);&lt;br /&gt;
            } catch (Exception e) {&lt;br /&gt;
                System.out.println(&amp;quot;ERROR: &amp;quot; + e.getMessage());&lt;br /&gt;
            }&lt;br /&gt;
&lt;br /&gt;
            // now add the new address to the aliases and try again&lt;br /&gt;
            aliases = ret.getAliases();&lt;br /&gt;
            aliases.add(newaddress);&lt;br /&gt;
            changeduser.getAliases().addAll(aliases);&lt;br /&gt;
            userport.change(change);&lt;br /&gt;
&lt;br /&gt;
            // control the result&lt;br /&gt;
            ret = userport.getData(ctx, auser, creds);&lt;br /&gt;
            aliases = ret.getAliases();&lt;br /&gt;
            // list all mail aliases of that user&lt;br /&gt;
            System.out.println(&amp;quot;User has the following alias(es):&amp;quot; + aliases);&lt;br /&gt;
        } catch (com.openexchange.oxaas.context.InvalidDataExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (com.openexchange.oxaas.context.NoSuchContextExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (com.openexchange.oxaas.context.DuplicateExtensionExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (com.openexchange.oxaas.context.InvalidCredentialsExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (com.openexchange.oxaas.context.RemoteExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (com.openexchange.oxaas.context.StorageExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (InvalidDataExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (NoSuchContextExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (DuplicateExtensionExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (DatabaseUpdateExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (InvalidCredentialsExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (RemoteExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (NoSuchUserExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (StorageExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (CreateSharedDomainFaultException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        }&lt;br /&gt;
    }&lt;br /&gt;
&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===== Catchall account management =====&lt;br /&gt;
&lt;br /&gt;
The next example shows how to manage catchall accounts.&lt;br /&gt;
Please take into account that this is not necessarily enabled for your account.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;java&amp;quot;&amp;gt;&lt;br /&gt;
package com.openexchange.oxaas.myclient;&lt;br /&gt;
&lt;br /&gt;
import javax.xml.namespace.QName;&lt;br /&gt;
import com.openexchange.oxaas.context.OXResellerContextService;&lt;br /&gt;
import com.openexchange.oxaas.context.OXResellerContextServicePortType;&lt;br /&gt;
import com.openexchange.oxaas.extra.CreateDomainCatchallFaultException;&lt;br /&gt;
import com.openexchange.oxaas.extra.DeleteDomainCatchallFaultException;&lt;br /&gt;
import com.openexchange.oxaas.extra.DomainCatchall;&lt;br /&gt;
import com.openexchange.oxaas.extra.ListDomainCatchallsFaultException;&lt;br /&gt;
import com.openexchange.oxaas.extra.OXaaSService;&lt;br /&gt;
import com.openexchange.oxaas.extra.OXaaSService_Service;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
 * Example SOAP client for OXaaS OXResellerUserService&lt;br /&gt;
 * &lt;br /&gt;
 * Create users in a context&lt;br /&gt;
 * &lt;br /&gt;
 */&lt;br /&gt;
public class OXaaSCatchAllManagement {&lt;br /&gt;
&lt;br /&gt;
    private static final QName CONTEXT_SERVICE_NAME = new QName(&amp;quot;http://soap.reseller.admin.openexchange.com&amp;quot;, &amp;quot;OXResellerContextService&amp;quot;);&lt;br /&gt;
    private static final QName OXAAS_SERVICE_NAME = new QName(&amp;quot;http://soap.oxaas.admin.openexchange.com/&amp;quot;, &amp;quot;OXaaSService&amp;quot;);&lt;br /&gt;
&lt;br /&gt;
    public static void main(String[] args) {&lt;br /&gt;
        final String subadminname = &amp;quot;mysubadmin&amp;quot;;&lt;br /&gt;
        final String subadminpw   = &amp;quot;secret&amp;quot;;&lt;br /&gt;
        final String userlogin    = &amp;quot;auser&amp;quot;;&lt;br /&gt;
        final String ctxname      = subadminname + &amp;quot;_myctx&amp;quot;;&lt;br /&gt;
        &lt;br /&gt;
        OXResellerContextService contextservice = new OXResellerContextService(OXResellerContextService.WSDL_LOCATION, CONTEXT_SERVICE_NAME);&lt;br /&gt;
        OXResellerContextServicePortType contextport = contextservice.getOXResellerContextServiceHttpSoap11Endpoint();&lt;br /&gt;
        OXaaSService_Service oxaasservice = new OXaaSService_Service(OXaaSService_Service.WSDL_LOCATION, OXAAS_SERVICE_NAME);&lt;br /&gt;
        OXaaSService oxaasport = oxaasservice.getOXaaSServiceSOAP();  &lt;br /&gt;
        &lt;br /&gt;
        &lt;br /&gt;
        // We need to use the ResellerContextService SOAP client stub to retrieve the context id&lt;br /&gt;
        com.openexchange.oxaas.context.rmi.dataobjects.Credentials ctxCreds = new com.openexchange.oxaas.context.rmi.dataobjects.Credentials();&lt;br /&gt;
        com.openexchange.oxaas.context.reseller.soap.dataobjects.ResellerContext ctxCtx = new com.openexchange.oxaas.context.reseller.soap.dataobjects.ResellerContext();&lt;br /&gt;
        ctxCreds.setLogin(subadminname);&lt;br /&gt;
        ctxCreds.setPassword(subadminpw);&lt;br /&gt;
        ctxCtx.setName(ctxname);&lt;br /&gt;
&lt;br /&gt;
        try {&lt;br /&gt;
            // we only have the name of the context, so we need to retrieve its id, first using ResellerContextService&lt;br /&gt;
            com.openexchange.oxaas.context.reseller.soap.dataobjects.ResellerContext ctxRet = contextport.getData(ctxCtx, ctxCreds);&lt;br /&gt;
&lt;br /&gt;
            com.openexchange.oxaas.extra.Credentials oxaasCtxCreds = new com.openexchange.oxaas.extra.Credentials();&lt;br /&gt;
            oxaasCtxCreds.setLogin(subadminname);&lt;br /&gt;
            oxaasCtxCreds.setPassword(subadminpw);&lt;br /&gt;
            &lt;br /&gt;
            /*&lt;br /&gt;
             * Note: this will throw an error&lt;br /&gt;
             * oxaas_catchall_domain capability not available for context XXX, user YYY in brand ZZZ&lt;br /&gt;
             * unless you have domain catchall in your contract&lt;br /&gt;
             */&lt;br /&gt;
            oxaasport.createDomainCatchall(ctxRet.getId(), &amp;quot;example.com&amp;quot;, userlogin, oxaasCtxCreds);&lt;br /&gt;
            &lt;br /&gt;
            for(final DomainCatchall dc : oxaasport.listDomainCatchalls(ctxRet.getId(), oxaasCtxCreds) ) {&lt;br /&gt;
                System.out.println(&amp;quot;Catchall account for domain &amp;quot; + dc.getDomain() + &amp;quot; is &amp;quot; + dc.getLogin());&lt;br /&gt;
            }&lt;br /&gt;
            &lt;br /&gt;
            // cleanup&lt;br /&gt;
            oxaasport.deleteDomainCatchall(ctxRet.getId(), &amp;quot;example.com&amp;quot;, userlogin, oxaasCtxCreds);&lt;br /&gt;
        } catch (com.openexchange.oxaas.context.InvalidDataExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (com.openexchange.oxaas.context.NoSuchContextExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (com.openexchange.oxaas.context.DuplicateExtensionExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (com.openexchange.oxaas.context.InvalidCredentialsExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (com.openexchange.oxaas.context.RemoteExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (com.openexchange.oxaas.context.StorageExceptionException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (ListDomainCatchallsFaultException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (DeleteDomainCatchallFaultException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        } catch (CreateDomainCatchallFaultException e) {&lt;br /&gt;
            e.printStackTrace();&lt;br /&gt;
        }&lt;br /&gt;
    }&lt;br /&gt;
&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Perl ===&lt;br /&gt;
&lt;br /&gt;
==== Standalone example: createOXaaSContext ====&lt;br /&gt;
&lt;br /&gt;
http://software.open-xchange.com/products/appsuite/doc/oxasservice/createOXaaSContext.pl&lt;br /&gt;
&lt;br /&gt;
==== Standalone example: createOXaaSUser ====&lt;br /&gt;
&lt;br /&gt;
http://software.open-xchange.com/products/appsuite/doc/oxasservice/createOXaaSUser.pl&lt;br /&gt;
&lt;br /&gt;
==== Standalone example: changeOXaaSUserPermissions ====&lt;br /&gt;
&lt;br /&gt;
http://software.open-xchange.com/products/appsuite/doc/oxasservice/changeOXaaSUserPermissions.pl&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== OXaas APS(1.2) package ====&lt;br /&gt;
&lt;br /&gt;
Just download the APS package as mentioned [[#Reference_implementation|here]]. When you extract the zip file, you will find&lt;br /&gt;
the perl code within the directory &amp;lt;tt&amp;gt;scripts&amp;lt;/tt&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
;OXSOAP.pm: SOAP Wrapper functions&lt;br /&gt;
;configure-alias.pl: Mail alias management&lt;br /&gt;
;configure-catchall.pl: Catchall mail alias management&lt;br /&gt;
;configure-mbox.pl: User management&lt;br /&gt;
;configure.pl: Context management&lt;br /&gt;
;verify-account.pl: check for login existence (existsLogin)&lt;br /&gt;
;verify-catchall.pl: check for catchall existence&lt;br /&gt;
;verify-shared.pl: shared mail alias checks&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=Caldav_carddav_Bundles&amp;diff=25230</id>
		<title>Caldav carddav Bundles</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=Caldav_carddav_Bundles&amp;diff=25230"/>
		<updated>2020-01-24T22:30:38Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: added opensync&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This article is valid until the version 7.10.2 of the Open Xchange Server. For newer versions please visit https://documentation.open-xchange.com/latest/middleware/miscellaneous/caldav_carddav.html&lt;br /&gt;
&lt;br /&gt;
= Installation and Configuration of the CalDAV- and CardDAV-bundles =&lt;br /&gt;
&lt;br /&gt;
The Open-Xchange server can be accessed via it&#039;s CalDAV- and CardDAV-interfaces to allow the synchronization of Calendar- and Contact-data with external applications like the Mac OS Calendar and Address Book clients.&lt;br /&gt;
&lt;br /&gt;
CalDAV and CardDAV are standard protocols for the exchange of calendar data and address data respectively. The CalDAV interface publishes all the user&#039;s calendar folders via CalDAV so the user can subscribe to them in a client application. Similarly, the CardDAV interface publishes the user&#039;s contact folders. Depending on the used client, the user can either subscribe one or more folders, or access all available data in an aggregated way. &lt;br /&gt;
&lt;br /&gt;
== User Guide and Client Configuration ==&lt;br /&gt;
Please find further information regarding the client configuration at [[CalDAVClients]] and [[CardDAVClients]].&lt;br /&gt;
&lt;br /&gt;
== Webserver Configuration ==&lt;br /&gt;
In order to redirect DAV requests to the appropiate servlets, the webserver&#039;s configuration may need to be adjusted using one of the following alternatives. Please be aware that for a working Mavericks auto configuration setup you need to have SSL enabled on the server. The non-SSL variant described below only works if you use the advanced CalDAV configuration in Mac OS X Mavericks and enter the path by hand. If you just want to enter the hostname, SSL is required. The same applies to iOS7 where SSL is always required.&lt;br /&gt;
&lt;br /&gt;
=== Alternative 1: Apache vhost (recommended) ===&lt;br /&gt;
Please edit your site configuration file for OX so that &#039;&#039;&#039; the existing OX configuration as well as the CalDAV/CardDAV configuration are placed inside their own virtual hosts sections.&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Please add the following entries before your existing &amp;lt;code&amp;gt;VirtualHost&amp;lt;/code&amp;gt; entry. This is an &amp;lt;b&amp;gt;example&amp;lt;/b&amp;gt; where &amp;lt;code&amp;gt;MYSERVER.TLD&amp;lt;/code&amp;gt; is the domain-name of the ox-server:&lt;br /&gt;
&lt;br /&gt;
 # NameVirtualHost directive no longer has any effect since Apache &amp;gt;=2.4&lt;br /&gt;
 # uncomment only for Apache Versions &amp;lt;2.4&lt;br /&gt;
 #NameVirtualHost *:80&lt;br /&gt;
 &amp;lt;VirtualHost *:80&amp;gt;&lt;br /&gt;
        ServerName dav.&amp;lt;MYSERVER.TLD&amp;gt;&lt;br /&gt;
        ErrorLog /tmp/dav.err.log&lt;br /&gt;
        TransferLog /tmp/dav.access.log&lt;br /&gt;
 &lt;br /&gt;
       &amp;lt;Proxy balancer://oxserver-sync&amp;gt;&lt;br /&gt;
         Order deny,allow&lt;br /&gt;
         Allow from all&lt;br /&gt;
 &lt;br /&gt;
         # for grizzly http service&lt;br /&gt;
         BalancerMember http://localhost:8009 timeout=100 smax=0 ttl=60 retry=60 loadfactor=50 route=OX1&lt;br /&gt;
         # uncomment this entry if you have a clustered setup and want to use the other nodes too&lt;br /&gt;
         #BalancerMember http://&amp;lt;ip-of-other-host&amp;gt;:8009 timeout=100 smax=0 ttl=60 retry=60 loadfactor=50 route=OX2&lt;br /&gt;
         SetEnv proxy-initial-not-pooled&lt;br /&gt;
         SetEnv proxy-sendchunked&lt;br /&gt;
       &amp;lt;/Proxy&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
       ProxyPass / balancer://oxserver-sync/servlet/dav/&lt;br /&gt;
 &lt;br /&gt;
 &amp;lt;/VirtualHost&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If you use this method, you have to make sure that &amp;lt;code&amp;gt;dav.&amp;lt;MYSERVER.TLD&amp;gt;&amp;lt;/code&amp;gt; is reachable, your DNS configuration needs an entry for this name. Take care of the the dav.* logfiles, the example writes them without logrotation to &amp;lt;code&amp;gt;/tmp&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Please note the &amp;lt;code&amp;gt;NameVirtualHost&amp;lt;/code&amp;gt; directive is needed to be able to specify multiple virtual hosts for the same IP. The differentiation is only done by the given &amp;lt;code&amp;gt;ServerName&amp;lt;/code&amp;gt;. This implies that you need two server names, so the virtual host entry for the existing ox site configuration needs to be also enriched by a &amp;lt;code&amp;gt;ServerName&amp;lt;/code&amp;gt; if not already present. If you access the system without one of the given &amp;lt;code&amp;gt;ServerName&amp;lt;/code&amp;gt;s so e.g. via the IP the system will pick the corresponding one by order (in this case the DAV part first. If you want it to work differently please change the order accordingly.&lt;br /&gt;
&lt;br /&gt;
=== Alternative 2: Apache useragent detection ===&lt;br /&gt;
For environments where it is inconvenient to setup a vhost there is the possibility to redirect to relevant servlets another way: Via useragent detection. This is not recommended for the following reason: Per definition this is a whitelist-approach and any client sending a useragent-string not explicitly listed in the configuration will not be able to connect . Useragent-strings may also change between different versions of an application or may even be actively changed into something non-standard.&lt;br /&gt;
&lt;br /&gt;
   $ vi &amp;lt;your-ox-site-configuration-file&amp;gt;&lt;br /&gt;
&lt;br /&gt;
  RewriteEngine On&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      Calendar           [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      Reminders          [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      DataAccess         [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      DAVKit             [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      DAVx5              [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      OpenSync           [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      &amp;quot;DAVdroid&amp;quot;         [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      Lightning          [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      Adresboek          [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      dataaccessd        [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      Preferences        [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      Adressbuch         [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      AddressBook        [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      Address\ Book      [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      CalendarStore      [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      CalendarAgent      [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      CalDAV%20Sync%20Adapter [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      accountsd          [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      &amp;quot;eM Client&amp;quot;        [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      &amp;quot;OX Sync&amp;quot;          [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      CalDav             [OR]&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      CoreDAV&lt;br /&gt;
  RewriteCond %{HTTP_USER_AGENT}      &amp;quot;!Open-Xchange Calendar Feed Client&amp;quot;&lt;br /&gt;
  RewriteRule (.*)                  http://localhost:8009/servlet/dav$1     [P] # for grizzly http service&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; The address book app on OSX 10.6 uses a localized user-agent string. If you&#039;re expecting clients with non-english language settings, you need to add the translated user-agent string to these rewrite rules. For example: &amp;quot;Adressbuch&amp;quot; for german OSX clients.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; Depending on the specific configuration, such a global definition of the rewrite rules might not be appropriate. However, the rules may also be defined inside a &amp;lt;code&amp;gt;Directory&amp;lt;/code&amp;gt; context. More details are available at http://httpd.apache.org/docs/current/mod/mod_rewrite.html#rewriterule.&lt;br /&gt;
&lt;br /&gt;
== Autodiscovery ==&lt;br /&gt;
&lt;br /&gt;
By providing some DNS service name registrations for your domain and adding an additional rewrite-rule to the webserver&#039;s configuration, it&#039;s possible for some clients to automatically discover the account settings by just providing the user&#039;s e-mail address and password. The procedure is specified in [http://tools.ietf.org/html/rfc6764 RFC 6764]. &lt;br /&gt;
&lt;br /&gt;
The following example illustrates the DNS entries where MYSERVER.TLD would be the domain name of the ox-server, both for CalDAV and CardDAV via HTTP and HTTPS on the virtual host dav.MYSERVER.TLD:&lt;br /&gt;
&lt;br /&gt;
 _caldavs._tcp.MYSERVER.TLD.      10800 IN SRV      10 1 443 dav.MYSERVER.TLD.&lt;br /&gt;
 _caldav._tcp.MYSERVER.TLD.       10800 IN SRV      10 1  80 dav.MYSERVER.TLD.&lt;br /&gt;
 _carddavs._tcp.MYSERVER.TLD.     10800 IN SRV      10 1 443 dav.MYSERVER.TLD.&lt;br /&gt;
 _carddav._tcp.MYSERVER.TLD.      10800 IN SRV      10 1  80 dav.MYSERVER.TLD.&lt;br /&gt;
&lt;br /&gt;
Additionally, a rewrite-rule similar to the following example should be added to the webserver configuration of the virtual host to enable the bootstrapping process. The rewrite target must be the root of your DAV server.&lt;br /&gt;
The well-known aliases should be added for your DAV vhost and on the vhost serving the host matching the mail domain:&lt;br /&gt;
&lt;br /&gt;
 RewriteEngine On&lt;br /&gt;
 RewriteCond %{REQUEST_URI} ^/\.well-known/caldav   [OR]&lt;br /&gt;
 RewriteCond %{REQUEST_URI} ^/\.well-known/carddav&lt;br /&gt;
 RewriteRule (.*) / [L,R]&lt;br /&gt;
&lt;br /&gt;
In the case of not serving the DAV service on the vhost root additionally some DNS TXT records are recommended:&lt;br /&gt;
&lt;br /&gt;
 _caldavs._tcp.MYSERVER.TLD.      10800 IN TXT   path=/servlet/dav&lt;br /&gt;
 _caldav._tcp.MYSERVER.TLD.       10800 IN TXT   path=/servlet/dav&lt;br /&gt;
 _carddavs._tcp.MYSERVER.TLD.     10800 IN TXT   path=/servlet/dav&lt;br /&gt;
 _carddav._tcp.MYSERVER.TLD.      10800 IN TXT   path=/servlet/dav&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Installation on OX App Suite ==&lt;br /&gt;
&lt;br /&gt;
=== Debian GNU/Linux 9.0===&lt;br /&gt;
&lt;br /&gt;
Add the following entry to /etc/apt/sources.list.d/open-xchange.list if not already present:&lt;br /&gt;
&lt;br /&gt;
 deb https://software.open-xchange.com/products/appsuite/stable/backend/DebianStretch/ /&lt;br /&gt;
&lt;br /&gt;
 # if you have a valid maintenance subscription, please uncomment the &lt;br /&gt;
 # following and add the ldb account data to the url so that the most recent&lt;br /&gt;
 # packages get installed&lt;br /&gt;
 # deb https://[CUSTOMERID:PASSWORD]@software.open-xchange.com/products/appsuite/stable/backend/updates/DebianStretch/ /&lt;br /&gt;
&lt;br /&gt;
and run&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-dav&lt;br /&gt;
&lt;br /&gt;
=== Debian GNU/Linux 10.0===&lt;br /&gt;
&lt;br /&gt;
Add the following entry to /etc/apt/sources.list.d/open-xchange.list if not already present:&lt;br /&gt;
&lt;br /&gt;
 deb https://software.open-xchange.com/products/appsuite/stable/backend/DebianBuster/ /&lt;br /&gt;
&lt;br /&gt;
 # if you have a valid maintenance subscription, please uncomment the &lt;br /&gt;
 # following and add the ldb account data to the url so that the most recent&lt;br /&gt;
 # packages get installed&lt;br /&gt;
 # deb https://[CUSTOMERID:PASSWORD]@software.open-xchange.com/products/appsuite/stable/backend/updates/DebianBuster/ /&lt;br /&gt;
&lt;br /&gt;
and run&lt;br /&gt;
&lt;br /&gt;
 $ apt-get update&lt;br /&gt;
 $ apt-get install open-xchange-dav&lt;br /&gt;
&lt;br /&gt;
=== SUSE Linux Enterprise Server 12===&lt;br /&gt;
&lt;br /&gt;
Add the package repository using zypper if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ar https://software.open-xchange.com/products/appsuite/stable/backend/SLE_12 ox&lt;br /&gt;
&lt;br /&gt;
If you have a valid maintenance subscription, please run the following command and add the ldb account data to the url so that the most recent packages get installed:&lt;br /&gt;
&lt;br /&gt;
 $ zypper ar https://[CUSTOMERID:PASSWORD]@software.open-xchange.com/products/appsuite/stable/backend/updates/SLES11 ox-updates&lt;br /&gt;
&lt;br /&gt;
and run&lt;br /&gt;
&lt;br /&gt;
 $ zypper ref&lt;br /&gt;
 $ zypper in open-xchange-dav&lt;br /&gt;
&lt;br /&gt;
=== RedHat Enterprise Linux 6===&lt;br /&gt;
&lt;br /&gt;
Start a console and create a software repository file if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ vim /etc/yum.repos.d/ox.repo&lt;br /&gt;
&lt;br /&gt;
 [ox]&lt;br /&gt;
 name=Open-Xchange&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/stable/backend/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 # if you have a valid maintenance subscription, please uncomment the &lt;br /&gt;
 # following and add the ldb account data to the url so that the most recent&lt;br /&gt;
 # packages get installed&lt;br /&gt;
 # [ox-updates]&lt;br /&gt;
 # name=Open-Xchange Updates&lt;br /&gt;
 # baseurl=https://[CUSTOMERID:PASSWORD]@software.open-xchange.com/products/appsuite/stable/backend/updates/RHEL6/&lt;br /&gt;
 # gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 # enabled=1&lt;br /&gt;
 # gpgcheck=1&lt;br /&gt;
 # metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and run&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-dav&lt;br /&gt;
&lt;br /&gt;
===RedHat Enterprise Linux 7===&lt;br /&gt;
&lt;br /&gt;
Start a console and create a software repository file if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ vim /etc/yum.repos.d/ox.repo&lt;br /&gt;
&lt;br /&gt;
 [ox]&lt;br /&gt;
 name=Open-Xchange&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/stable/backend/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 # if you have a valid maintenance subscription, please uncomment the &lt;br /&gt;
 # following and add the ldb account data to the url so that the most recent&lt;br /&gt;
 # packages get installed&lt;br /&gt;
 # [ox-updates]&lt;br /&gt;
 # name=Open-Xchange Updates&lt;br /&gt;
 # baseurl=https://[CUSTOMERID:PASSWORD]@software.open-xchange.com/products/appsuite/stable/backend/updates/RHEL7/&lt;br /&gt;
 # gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 # enabled=1&lt;br /&gt;
 # gpgcheck=1&lt;br /&gt;
 # metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and run&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-dav&lt;br /&gt;
&lt;br /&gt;
===CentOS 6===&lt;br /&gt;
&lt;br /&gt;
Start a console and create a software repository file if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ vim /etc/yum.repos.d/ox.repo&lt;br /&gt;
&lt;br /&gt;
 [ox]&lt;br /&gt;
 name=Open-Xchange&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/stable/backend/RHEL6/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 # if you have a valid maintenance subscription, please uncomment the &lt;br /&gt;
 # following and add the ldb account data to the url so that the most recent&lt;br /&gt;
 # packages get installed&lt;br /&gt;
 # [ox-updates]&lt;br /&gt;
 # name=Open-Xchange Updates&lt;br /&gt;
 # baseurl=https://[CUSTOMERID:PASSWORD]@software.open-xchange.com/products/appsuite/stable/backend/updates/RHEL6/&lt;br /&gt;
 # gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 # enabled=1&lt;br /&gt;
 # gpgcheck=1&lt;br /&gt;
 # metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and run&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-dav&lt;br /&gt;
&lt;br /&gt;
===CentOS 7===&lt;br /&gt;
&lt;br /&gt;
Start a console and create a software repository file if not already present:&lt;br /&gt;
&lt;br /&gt;
 $ vim /etc/yum.repos.d/ox.repo&lt;br /&gt;
&lt;br /&gt;
 [ox]&lt;br /&gt;
 name=Open-Xchange&lt;br /&gt;
 baseurl=https://software.open-xchange.com/products/appsuite/stable/backend/RHEL7/&lt;br /&gt;
 gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 enabled=1&lt;br /&gt;
 gpgcheck=1&lt;br /&gt;
 metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
 # if you have a valid maintenance subscription, please uncomment the &lt;br /&gt;
 # following and add the ldb account data to the url so that the most recent&lt;br /&gt;
 # packages get installed&lt;br /&gt;
 # [ox-updates]&lt;br /&gt;
 # name=Open-Xchange Updates&lt;br /&gt;
 # baseurl=https://[CUSTOMERID:PASSWORD]@software.open-xchange.com/products/appsuite/stable/backend/updates/RHEL7/&lt;br /&gt;
 # gpgkey=https://software.open-xchange.com/oxbuildkey.pub&lt;br /&gt;
 # enabled=1&lt;br /&gt;
 # gpgcheck=1&lt;br /&gt;
 # metadata_expire=0m&lt;br /&gt;
&lt;br /&gt;
and run&lt;br /&gt;
&lt;br /&gt;
 $ yum update&lt;br /&gt;
 $ yum install open-xchange-dav&lt;br /&gt;
&lt;br /&gt;
== CalDAV Configuration ==&lt;br /&gt;
&lt;br /&gt;
The following configuration options are available in the configuration files &amp;lt;code&amp;gt;caldav.properties&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;caldav.yml&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
===com.openexchange.caldav.enabled===&lt;br /&gt;
The property &#039;&#039;&#039;com.openexchange.caldav.enabled&#039;&#039;&#039; governs whether a user has access to the CalDAV interface. This can be configured along the config cascade, in the default setting, everyone that has access to the infostore also has access to caldav. This is achieved in the following way:&lt;br /&gt;
&lt;br /&gt;
/opt/open-xchange/etc/caldav.properties:&lt;br /&gt;
  com.openexchange.caldav.enabled=false&lt;br /&gt;
&lt;br /&gt;
/opt/open-xchange/etc/contextSets/caldav.yml&lt;br /&gt;
  premium:&lt;br /&gt;
      com.openexchange.caldav.enabled: true&lt;br /&gt;
      withTags: ucInfostore&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This means: In general CalDAV is turned off, but using the &amp;lt;code&amp;gt;contextSets&amp;lt;/code&amp;gt; feature of the config cascade it is turned on for everyone that has infostore access.&lt;br /&gt;
&lt;br /&gt;
===com.openexchange.caldav.tree===&lt;br /&gt;
Configures the ID of the folder tree used by the CalDAV interface. Currently, this should be set to the default value of &#039;0&#039;.&lt;br /&gt;
&lt;br /&gt;
===com.openexchange.caldav.interval.start===&lt;br /&gt;
Defines the minimum end time of appointments to be synchronized via the CalDAV interface, relative to the current date. Possible values are &amp;quot;one_month&amp;quot; (default), &amp;quot;one_year&amp;quot; and &amp;quot;six_months&amp;quot;.  &lt;br /&gt;
&lt;br /&gt;
===com.openexchange.caldav.interval.end===&lt;br /&gt;
Defines the maximum start time of appointments to be synchronized via the CalDAV interface, relative to the current date. Possible values are &amp;quot;one_year&amp;quot; (default) and &amp;quot;two_years&amp;quot;.  &lt;br /&gt;
&lt;br /&gt;
===com.openexchange.caldav.url===&lt;br /&gt;
Tells users where to find a caldav folder. This can be displayed in frontends. You can use the variables [hostname] and [folderId]. If you chose to deploy caldav as a virtual host (say &#039;dav.open-xchange.com&#039;) use https://dav.open-xchange.com/caldav/[folderId] as the value. If you are using user-agent sniffing use https://[hostname]/caldav/[folderId].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== CardDAV Configuration ==&lt;br /&gt;
&lt;br /&gt;
The following configuration options are available in the configuration files carddav.properties and carddav.yml:&lt;br /&gt;
&lt;br /&gt;
===com.openexchange.carddav.enabled===&lt;br /&gt;
Similarly to CalDAV, the property &#039;&#039;&#039;com.openexchange.carddav.enabled&#039;&#039;&#039; governs whether CardDAV is available for a certain user. This is configured exactly like CalDAV with the config cascade only enabling this for users that have access to the infostore:&lt;br /&gt;
&lt;br /&gt;
/opt/open-xchange/etc/groupware/carddav.properties:&lt;br /&gt;
  com.openexchange.carddav.enabled=false&lt;br /&gt;
&lt;br /&gt;
/opt/open-xchange/etc/groupware/contextSets/carddav.yml&lt;br /&gt;
  premium:&lt;br /&gt;
      com.openexchange.carddav.enabled: true&lt;br /&gt;
      withTags: ucInfostore&lt;br /&gt;
&lt;br /&gt;
===com.openexchange.carddav.ignoreFolders===&lt;br /&gt;
A comma-separated list of folder IDs to exclude from the synchronization. Use this to disable syncing of very large folders (e.g. the global address list in large contexts, which always has ID 6). By default, no folders are excluded.&lt;br /&gt;
&lt;br /&gt;
===com.openexchange.carddav.tree===&lt;br /&gt;
Configures the ID of the folder tree used by the CardDAV interface. Currently, this should be set to the default value of &#039;0&#039;.&lt;br /&gt;
&lt;br /&gt;
===com.openexchange.carddav.exposedCollections===&lt;br /&gt;
Controls which collections are exposed via the CardDAV interface. Possible values are &#039;0&#039;, &#039;1&#039; and &#039;2&#039;. A value of &#039;1&#039; makes each visible folder available as a resource collection, while &#039;2&#039; only exposes an aggregated collection containing  all contact resources from all visible folders. The default value &#039;0&#039; exposes either an aggregated collection or individual collections for each folder, depending on the client&#039;s user-agent that is matched against the pattern in &#039;userAgentForAggregatedCollection&#039;. &lt;br /&gt;
&lt;br /&gt;
===com.openexchange.carddav.userAgentForAggregatedCollection===&lt;br /&gt;
Regular expression to match against the client&#039;s user-agent to decide whether the aggregated collection is exposed or not. The default pattern matches all known varieties of the Mac OS Addressbook client, that doesn&#039;t support multiple collections. Only used if &#039;exposedCollections&#039; is set to &#039;0&#039;. The pattern is used case insensitive. &lt;br /&gt;
&lt;br /&gt;
===com.openexchange.carddav.reducedAggregatedCollection===&lt;br /&gt;
Specifies if all visible folders are used to create the aggregated collection, or if a reduced set of folders only containing the global addressbook and the personal contacts folders should be used. This setting only influences the aggregated collection that is used for clients that don&#039;t support multiple collections. Possible values are &#039;true&#039; and &#039;false.&lt;br /&gt;
&lt;br /&gt;
[[Category: Clients]]&lt;br /&gt;
[[Category: Administrator]]&lt;br /&gt;
[[Category: AppSuite]]&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=My.cnf&amp;diff=25203</id>
		<title>My.cnf</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=My.cnf&amp;diff=25203"/>
		<updated>2020-01-17T14:23:32Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
&lt;br /&gt;
This page lists some performance tuning parameters which we recommend for tuning MySQL database services used for Open-Xchange installations.&lt;br /&gt;
&lt;br /&gt;
We cannot guarantee this is an exhaustive list of required settings. So treat this list of tunings as probably required, but not necessarily sufficient settings for optimal MySQL performance.&lt;br /&gt;
&lt;br /&gt;
Furthermore, as MySQL changes over time, settings which have been correct as of the time of writing may become incorrect later.&lt;br /&gt;
&lt;br /&gt;
However, this list of settings is the result of internal performance testing and real world customer feedback, so it should be valid to some extent.&lt;br /&gt;
&lt;br /&gt;
In the end, proper configuration of the database service for performance, but also consistency, durability and high availability is in the responsibility of the customer.&lt;br /&gt;
&lt;br /&gt;
=== Performance items ===&lt;br /&gt;
&lt;br /&gt;
* You should adjust the &amp;lt;code&amp;gt;innodb_buffer_pool_size&amp;lt;/code&amp;gt; parameter for reasonable memory usage. Our DB sizing is mainly memory-driven and this is where most of the memory goes. Our standard DB machine sizing assumption is 32 GB if MySQL dedicated memory on a 48 GB total memory machine. On such a machine, you would configure 32 GB for the innodb_buffer_pool size, being aware that MySQL does also require memory for other things, in particular there are some also per-connection related memory spendings, which can become substantial if you allow for a lot of maximum concurrent connections. Please watch your memory configuration carefully, use monitoring and tools like mysqltuner.pl.&lt;br /&gt;
&lt;br /&gt;
* On bigger installations you should use &amp;lt;code&amp;gt;innodb_file_per_table = 1&amp;lt;/code&amp;gt;, which is creating single files instead of one big blob. If you change this parameter after the database initialization you have to recreate (like dump/drop and re-import) the tables.&lt;br /&gt;
&lt;br /&gt;
* It can help to put different parts of the mysql datadir (iblog, ibdata) on different filesystems / storage devices. This depends on your infrastructure. Settings herefore are &amp;lt;code&amp;gt;datadir&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;innodb_data_home_dir&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;innodb_log_group_home_dir&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* If your storage is fast (handle a lot of IOPS), you may want to adjust the &amp;lt;code&amp;gt;innodb_io_capacity&amp;lt;/code&amp;gt; setting, which defines a limit for the IOPS MySQL will create. The default is 200, which is sensible for single spindle disks. But if you have storage appliances with a lot of fast SAS drives, or even SSDs, this limit can be increased greatly.&lt;br /&gt;
&lt;br /&gt;
=== Functional items ===&lt;br /&gt;
&lt;br /&gt;
* Query cache is to be switched off; as we found in our own benchmarks and as backed up by upstreams, this hurts performance in load situations with high concurrency. [https://dev.mysql.com/doc/refman/5.7/en/query-cache.htm The query cache is deprecated as of MySQL 5.7.20, and is removed in MySQL 8.0], so we recommend also to switch that off.&lt;br /&gt;
* Starting with App Suite 7.10.0, &amp;lt;code&amp;gt;character_set_server&amp;lt;/code&amp;gt; must be set to &amp;lt;code&amp;gt;utf8mb4&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;collation_server&amp;lt;/code&amp;gt; to &amp;lt;code&amp;gt;utf8mb4_general_ci&amp;lt;/code&amp;gt;. For older versions it must be &amp;lt;code&amp;gt;utf8&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;utf8_general_ci&amp;lt;/code&amp;gt; respectively.&lt;br /&gt;
* Starting with MySQL 5.7 &amp;lt;code&amp;gt;innodb_strict_mode&amp;lt;/code&amp;gt; must be disabled.&lt;br /&gt;
* Starting with MySQL 5.6 and MariaDB 10.1 &amp;lt;code&amp;gt;sql_mode&amp;lt;/code&amp;gt; must be configured according to belows matrix.&lt;br /&gt;
&lt;br /&gt;
==== SQL mode matrix ====&lt;br /&gt;
&lt;br /&gt;
The default for the &amp;lt;code&amp;gt;sql_mode&amp;lt;/code&amp;gt; setting changes regularly with MariaDB and MySQL releases and is not even consistent anymore between the two derivates. SQL modes affect how data and queries are handled at runtime. Enabling strict modes might lead to errors in terms of failing queries or even update tasks. We strongly recommend the following configuration to avoid according runtime errors:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! scope=&amp;quot;col&amp;quot;| sql_mode&lt;br /&gt;
! scope=&amp;quot;col&amp;quot;| App Suite 7.8.4&lt;br /&gt;
! scope=&amp;quot;col&amp;quot;| App Suite 7.10.x&lt;br /&gt;
|-&lt;br /&gt;
! scope=&amp;quot;row&amp;quot;| MySQL 5.6&lt;br /&gt;
| &amp;lt;code&amp;gt;NO_ENGINE_SUBSTITUTION&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;NO_ENGINE_SUBSTITUTION&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
! scope=&amp;quot;row&amp;quot;| MySQL 5.7&lt;br /&gt;
| &amp;lt;code&amp;gt;NO_AUTO_CREATE_USER,NO_ENGINE_SUBSTITUTION&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;NO_AUTO_CREATE_USER,NO_ENGINE_SUBSTITUTION,ONLY_FULL_GROUP_BY&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
! scope=&amp;quot;row&amp;quot;| MariaDB &amp;gt;= 10.1&lt;br /&gt;
| &amp;lt;code&amp;gt;NO_AUTO_CREATE_USER,NO_ENGINE_SUBSTITUTION&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;NO_AUTO_CREATE_USER,NO_ENGINE_SUBSTITUTION&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Sample config files ===&lt;br /&gt;
&lt;br /&gt;
For easy deployment we recommend not to edit existing the existing my.cnf file, rather assume the distro provides sane settings for most of the items and override items where needed.&lt;br /&gt;
&lt;br /&gt;
As in MySQL there is a [https://dev.mysql.com/doc/refman/5.7/en/option-files.html last instance wins] semantic in options file parsing, we propose to create a custom include directory &amp;quot;ox.conf.d&amp;quot;, put our custom config files therein, and include this directory as latest directory in /etc/mysql/my.cnf.&lt;br /&gt;
&lt;br /&gt;
To put in that directory, we have one main tuning file called tunings.cnf, one galera-related file if galera is in use, and one more galera host-specific file which contains per-host settings if using galera (separate in a file of its own for easier configuration management).&lt;br /&gt;
&lt;br /&gt;
So, start with adding to the existing my.cnf at the very bottom:&lt;br /&gt;
&lt;br /&gt;
 !includedir /etc/mysql/ox.conf.d/&lt;br /&gt;
&lt;br /&gt;
Create that directory and put in there the generic ox tunings file /etc/mysql/ox.conf.d/tunings.cnf:&lt;br /&gt;
&lt;br /&gt;
 [mysqld]&lt;br /&gt;
 bind-address		 = *&lt;br /&gt;
 &lt;br /&gt;
 #innodb_use_native_aio = 0&lt;br /&gt;
 &lt;br /&gt;
 table_open_cache = 3072&lt;br /&gt;
 table_definition_cache = 4096&lt;br /&gt;
 max_heap_table_size = 64M&lt;br /&gt;
 tmp_table_size = 64M&lt;br /&gt;
 max_connections = 505&lt;br /&gt;
 max_user_connections = 500&lt;br /&gt;
 max_allowed_packet = 16M&lt;br /&gt;
 thread_cache_size = 32&lt;br /&gt;
 query_cache_size = 0&lt;br /&gt;
 query_cache_type = 0&lt;br /&gt;
 innodb_buffer_pool_size = 32G&lt;br /&gt;
 # the default value in MySQL 5.6.6 and higher is 8 when innodb_buffer_pool_size is greater than or equal to 1GB. Otherwise, the default is 1. &lt;br /&gt;
 innodb_buffer_pool_instances = 32&lt;br /&gt;
 innodb_data_file_path = ibdata1:128M:autoextend&lt;br /&gt;
 innodb_file_per_table = 1&lt;br /&gt;
 # innodb_log_file_size should be 25% of the innodb_buffer_pool_size&lt;br /&gt;
 innodb_log_file_size = 4GB&lt;br /&gt;
 # default and recommended value is 2&lt;br /&gt;
 innodb_log_files_in_group = 2&lt;br /&gt;
 # adjust according to your storage&lt;br /&gt;
 #innodb_io_capacity = 1000&lt;br /&gt;
 &lt;br /&gt;
 # we are unsure about this setting. Newer versions of MariaDB seem to be fine with low (=1) settings for this value.&lt;br /&gt;
 # Traditionally we encountered values up to 4x the number of cores.&lt;br /&gt;
 # Default seems to be number of cores, so let&#039;s stick the default&lt;br /&gt;
 # In the end, we need to leave this setting up to you: if you dont get full cpu utilization in cpu-bound situations, this might be a setting to increase.&lt;br /&gt;
 #thread_pool_size = 32&lt;br /&gt;
 &lt;br /&gt;
 binlog_cache_size = 1M&lt;br /&gt;
 sync_binlog = 8&lt;br /&gt;
 binlog_format = row&lt;br /&gt;
 &lt;br /&gt;
 character_set_server = utf8mb4&lt;br /&gt;
 collation_server = utf8mb4_general_ci&lt;br /&gt;
 &lt;br /&gt;
 # default since MySQL 5.5.5 (was MyISAM previously)&lt;br /&gt;
 default_storage_engine = InnoDB&lt;br /&gt;
 &lt;br /&gt;
 innodb_autoinc_lock_mode = 2&lt;br /&gt;
 &lt;br /&gt;
 # keep until 5.6, deprecated later&lt;br /&gt;
 innodb_locks_unsafe_for_binlog = 1&lt;br /&gt;
 &lt;br /&gt;
 # we found this has huge impact on (galera) performance&lt;br /&gt;
 # default (consistent) setting of 1 greatly severs performance&lt;br /&gt;
 # in galera (or async master-slave) deployments, you might be ok with setting this to 0 or 2,&lt;br /&gt;
 # assuming our consistency / availability comes from replication / other cluster nodes&lt;br /&gt;
 innodb_flush_log_at_trx_commit = 0&lt;br /&gt;
 &lt;br /&gt;
 # for performance testing systems, to not use excessive disk space&lt;br /&gt;
 #expire_logs_days = 1&lt;br /&gt;
 &lt;br /&gt;
 # MySQL 5.7.7 has changed the default to 1. Disable it explicitly to prevent from errors based on invalid data stored by former App Suite or MySQL versions.&lt;br /&gt;
 innodb_strict_mode = 0&lt;br /&gt;
 &lt;br /&gt;
 # The following value refers to App Suite 7.10 on top of MySQL 5.7. For other combinations see the sql mode matrix at http://oxpedia.org/wiki/index.php?title=My.cnf.&lt;br /&gt;
 sql_mode = NO_ENGINE_SUBSTITUTION,NO_AUTO_CREATE_USER,ONLY_FULL_GROUP_BY&lt;br /&gt;
&lt;br /&gt;
If using galera, use the following galera configuration file &amp;lt;code&amp;gt;/etc/mysql/ox.conf.d/wsrep.cnf&amp;lt;/code&amp;gt;. See the comments in that file for values to be adjusted.&lt;br /&gt;
&lt;br /&gt;
 [mysqld]&lt;br /&gt;
 # adjust for your distros SO location&lt;br /&gt;
 wsrep_provider=/usr/lib/libgalera_smm.so&lt;br /&gt;
 &lt;br /&gt;
 # this is the big winner and enables us to switch off OX&#039;s replication monitor&lt;br /&gt;
 wsrep_sync_wait=1&lt;br /&gt;
 &lt;br /&gt;
 # pick a unique cluster name&lt;br /&gt;
 wsrep_cluster_name=devcluster&lt;br /&gt;
 # adjust for your IPs / hostnames&lt;br /&gt;
 wsrep_cluster_address=gcomm://10.20.29.68,10.20.29.69,10.20.29.70&lt;br /&gt;
 &lt;br /&gt;
 # put this in host.cnf&lt;br /&gt;
 #wsrep_node_name=...&lt;br /&gt;
 #wsrep_node_address=...&lt;br /&gt;
 &lt;br /&gt;
 # For some MariaDB versions, xtrabackup-v2 no longer works, instead use &amp;quot;mariabackup&amp;quot;&lt;br /&gt;
 # (needs to be installed separately, e.g. via the mariadb-backup-10.2 package)&lt;br /&gt;
 # see upstream documentation for details: &lt;br /&gt;
 # https://mariadb.com/kb/en/library/getting-started-with-mariadb-galera-cluster/#xtrabackup&lt;br /&gt;
 #&lt;br /&gt;
 # wsrep_sst_method=mariabackup&lt;br /&gt;
 wsrep_sst_method=xtrabackup-v2&lt;br /&gt;
&lt;br /&gt;
 # wsrep_sst_auth if of format username:password&lt;br /&gt;
 # pick whatever you configured on the donor node&lt;br /&gt;
 wsrep_sst_auth=sstuser:...&lt;br /&gt;
 &lt;br /&gt;
 # galera-specific tunings&lt;br /&gt;
 wsrep_slave_threads = 32&lt;br /&gt;
 &lt;br /&gt;
 # finally, enable wsrep: required for some MariaDB versions&lt;br /&gt;
 wsrep_on=ON -- Enable wsrep replication (MariaDB starting 10.1.1) &lt;br /&gt;
&lt;br /&gt;
Galera-related host-specific settings go in /etc/mysql/ox.conf.d/host.cnf:&lt;br /&gt;
&lt;br /&gt;
 [mysqld]&lt;br /&gt;
 # the nodes hostname&lt;br /&gt;
 wsrep_node_name=...&lt;br /&gt;
 # and the IP of the wsrep relevant interface, if multiple&lt;br /&gt;
 wsrep_node_address=10.20.29.68&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=SourceCodeAccess&amp;diff=25182</id>
		<title>SourceCodeAccess</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=SourceCodeAccess&amp;diff=25182"/>
		<updated>2020-01-08T10:11:26Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= How to download the Open-Xchange source code =&lt;br /&gt;
&lt;br /&gt;
Starting with 6.22 the source code of Open-Xchange server is available from Git repositories.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The following repositories exist:&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
! Repository&lt;br /&gt;
! content&lt;br /&gt;
|- &lt;br /&gt;
| https://gitlab.open-xchange.com/middleware/core&lt;br /&gt;
| The main repository containing most of the parts of Open-Xchange server&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.open-xchange.com/frontend/core&lt;br /&gt;
| The user interface of OX App Suite&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.open-xchange.com/appsuite/guard&lt;br /&gt;
| The server-code and UI for OX Guard (PGP implementation)&lt;br /&gt;
|-&lt;br /&gt;
| https://code.open-xchange.com/git/frontend6&lt;br /&gt;
| The AJAX user interface (version 6)&lt;br /&gt;
|-&lt;br /&gt;
| documentconverter-api&lt;br /&gt;
| The API of the server-based part of the documentconverter needed for OX Text&lt;br /&gt;
|-&lt;br /&gt;
| office&lt;br /&gt;
| The server-code for OX Text and OX Spreadsheet&lt;br /&gt;
|-&lt;br /&gt;
| office-web&lt;br /&gt;
| The frontend-code for OX Text and OX Spreadsheet&lt;br /&gt;
|-&lt;br /&gt;
| mobile-api-facade&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Git operations to access the code ==&lt;br /&gt;
&lt;br /&gt;
To clone a repository in case of gitlab please follow the instructions shown there.&lt;br /&gt;
For cloning from code.open-xchange.com, run&lt;br /&gt;
&lt;br /&gt;
 $ git clone https://code.open-xchange.com/git/&amp;lt;repository&amp;gt;&lt;br /&gt;
 $ cd &amp;lt;repository&amp;gt;&lt;br /&gt;
 $ git checkout -t origin/&amp;lt;branch&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== The currently used Git branches ==&lt;br /&gt;
&lt;br /&gt;
For a list of available branches, run&lt;br /&gt;
&lt;br /&gt;
 $ git branch -r&lt;br /&gt;
&lt;br /&gt;
The main development process uses the following branches:&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
! Git branch&lt;br /&gt;
! content&lt;br /&gt;
|- &lt;br /&gt;
| develop&lt;br /&gt;
| head development&lt;br /&gt;
|-&lt;br /&gt;
| release-&amp;lt;version&amp;gt;&lt;br /&gt;
| stabilizing for &amp;lt;version&amp;gt; release&lt;br /&gt;
|-&lt;br /&gt;
| master&lt;br /&gt;
| maintenance of current release&lt;br /&gt;
|-&lt;br /&gt;
| master-&amp;lt;version&amp;gt;&lt;br /&gt;
| maintenance of previous releases&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: OX6]]&lt;br /&gt;
[[Category: AppSuite]]&lt;br /&gt;
[[Category: Developer]]&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=SourceCodeAccess&amp;diff=25181</id>
		<title>SourceCodeAccess</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=SourceCodeAccess&amp;diff=25181"/>
		<updated>2020-01-08T10:02:20Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= How to download the Open-Xchange source code =&lt;br /&gt;
&lt;br /&gt;
Starting with 6.22 the source code of Open-Xchange server is available from Git repositories.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The following repositories exist:&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
! Repository&lt;br /&gt;
! content&lt;br /&gt;
|- &lt;br /&gt;
| https://gitlab.open-xchange.com/middleware/core&lt;br /&gt;
| The main repository containing most of the parts of Open-Xchange server&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.open-xchange.com/frontend/core&lt;br /&gt;
| The user interface of OX App Suite&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.open-xchange.com/appsuite/guard&lt;br /&gt;
| The server-code and UI for OX Guard (PGP implementation)&lt;br /&gt;
|-&lt;br /&gt;
| https://code.open-xchange.com/git/frontend6&lt;br /&gt;
| The AJAX user interface (version 6)&lt;br /&gt;
|-&lt;br /&gt;
| documentconverter-api&lt;br /&gt;
| The API of the server-based part of the documentconverter needed for OX Text&lt;br /&gt;
|-&lt;br /&gt;
| office&lt;br /&gt;
| The server-code for OX Text and OX Spreadsheet&lt;br /&gt;
|-&lt;br /&gt;
| office-web&lt;br /&gt;
| The frontend-code for OX Text and OX Spreadsheet&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Git operations to access the code ==&lt;br /&gt;
&lt;br /&gt;
To clone a repository in case of gitlab please follow the instructions shown there.&lt;br /&gt;
For cloning from code.open-xchange.com, run&lt;br /&gt;
&lt;br /&gt;
 $ git clone https://code.open-xchange.com/git/&amp;lt;repository&amp;gt;&lt;br /&gt;
 $ cd &amp;lt;repository&amp;gt;&lt;br /&gt;
 $ git checkout -t origin/&amp;lt;branch&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== The currently used Git branches ==&lt;br /&gt;
&lt;br /&gt;
For a list of available branches, run&lt;br /&gt;
&lt;br /&gt;
 $ git branch -r&lt;br /&gt;
&lt;br /&gt;
The main development process uses the following branches:&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
! Git branch&lt;br /&gt;
! content&lt;br /&gt;
|- &lt;br /&gt;
| develop&lt;br /&gt;
| head development&lt;br /&gt;
|-&lt;br /&gt;
| release-&amp;lt;version&amp;gt;&lt;br /&gt;
| stabilizing for &amp;lt;version&amp;gt; release&lt;br /&gt;
|-&lt;br /&gt;
| master&lt;br /&gt;
| maintenance of current release&lt;br /&gt;
|-&lt;br /&gt;
| master-&amp;lt;version&amp;gt;&lt;br /&gt;
| maintenance of previous releases&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: OX6]]&lt;br /&gt;
[[Category: AppSuite]]&lt;br /&gt;
[[Category: Developer]]&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=Mailclient_autoconfiguration&amp;diff=25174</id>
		<title>Mailclient autoconfiguration</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=Mailclient_autoconfiguration&amp;diff=25174"/>
		<updated>2020-01-03T11:00:54Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Providing autoconfiguration for mail clients =&lt;br /&gt;
&lt;br /&gt;
This article explains a solution for autoconfiguration for a set of mail clients which can be configured against a mail system automatically by just entering email address and password. There are three widely used approaches to do this via a self hosted lookup method, based on Microsoft&#039;s autodiscover, [https://developer.mozilla.org/en-US/docs/Mozilla/Thunderbird/Autoconfiguration Mozilla&#039;s autoconfig], and iOS/MacOS provisioning which are relevant to support detecting IMAP and SMTP server details for client configuration. Another option is solely based on DNS SRV discovery ([https://tools.ietf.org/html/rfc6186 RFC 6186]).&lt;br /&gt;
&lt;br /&gt;
Since [[AppSuite:EM_Client_for_OX_App_Suite|eMClient for OX App Suite]] is using the Microsoft based solution this service is especially important to have a smooth user experience for customer environments offering it to their users.&lt;br /&gt;
&lt;br /&gt;
autodiscover and autoconfig are based on XML schemas. Therefore for very simple deployments it might even be enough to serve some static XML files for both usecases. Please see the respective vendor standard documentation for more details.&lt;br /&gt;
&lt;br /&gt;
In this article we show how to deploy a simple autoconfiguration service based on the open source solution [https://automx.org/en/ automx].&lt;br /&gt;
&lt;br /&gt;
== Preparations ==&lt;br /&gt;
&lt;br /&gt;
The autoconfiguration protocols use several ways to find the XML provided later by automx. In the following section there is listed in which order the protocols are looking for the XML. Depending where you would like to serve the XML files you can choose from those options.&lt;br /&gt;
&lt;br /&gt;
The domain example.org as in those examples are the ones taken from the entered email address.&lt;br /&gt;
&lt;br /&gt;
=== autoconfig ===&lt;br /&gt;
&lt;br /&gt;
# http://autoconfig.example.org/mail/config-v1.1.xml&lt;br /&gt;
# http://example.org/.well-known/autoconfig/mail/config-v1.1.xml&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== autodiscover ===&lt;br /&gt;
&lt;br /&gt;
# https://example.org/autodiscover/autodiscover.xml&lt;br /&gt;
# https://autodiscover.example.org/autodiscover/autodiscover.xml&lt;br /&gt;
# DNS SRV lookup for autodiscover.tcp.example.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== DNS SRV ===&lt;br /&gt;
&lt;br /&gt;
A DNS SRV entry for autodiscover would look like this:&lt;br /&gt;
&lt;br /&gt;
  _autodiscover._tcp                      IN      SRV 0 0 443 $HOSTNAME.example.org.&lt;br /&gt;
&lt;br /&gt;
The following DNS SRV records can be used to provide configuration hints for mail clients supporting RFC 6186:&lt;br /&gt;
&lt;br /&gt;
  _submission._tcp     SRV 0 1 587 mail.example.org.&lt;br /&gt;
  _imap._tcp           SRV 2 1 143 imap.example.org.&lt;br /&gt;
  _imaps._tcp          SRV 1 1 993 imap.example.org.&lt;br /&gt;
  _pop3._tcp           SRV 4 1 110 pop3.example.org.&lt;br /&gt;
  _pop3s._tcp          SRV 3 1 995 pop3.example.org.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== automx ==&lt;br /&gt;
&lt;br /&gt;
=== Installation ===&lt;br /&gt;
&lt;br /&gt;
If you would like to support eMClient for OX App Suite please make sure that you are using a version after 1.1.1 or an earlier patched version which supports the DAV and OX services.&lt;br /&gt;
Also please note that the current versions of automx2 do neither support DAV nor the OX service extensions for autodiscover. It currently only supports IMAP and SMTP services.&lt;br /&gt;
&lt;br /&gt;
For manual installation please refer to the [https://automx.org/en/#download automx download instructions].&lt;br /&gt;
&lt;br /&gt;
RPM packages for SUSE and RHEL flavours are provided by the [https://software.opensuse.org/package/automx Open Build Service]. Those packages are currently version 0.10.2 with the above patches applied and are working with Python 2.&lt;br /&gt;
&lt;br /&gt;
=== Configuration ===&lt;br /&gt;
&lt;br /&gt;
==== automx ====&lt;br /&gt;
&lt;br /&gt;
Please find detailed documentation via &#039;&#039;&#039;man automx.conf&#039;&#039;&#039; and for more dynamic setups automx_script, automx_ldap and automx_sql.&lt;br /&gt;
&lt;br /&gt;
/etc/automx.conf:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
[automx]&lt;br /&gt;
provider = example.org&lt;br /&gt;
domains = example.org, example.com&lt;br /&gt;
debug = no&lt;br /&gt;
logfile = /var/log/automx/automx.log&lt;br /&gt;
&lt;br /&gt;
# Protect against DoS&lt;br /&gt;
memcache = 127.0.0.1:11211&lt;br /&gt;
memcache_ttl = 600&lt;br /&gt;
client_error_limit = 20&lt;br /&gt;
rate_limit_exception_networks = 127.0.0.0/8, ::1/128&lt;br /&gt;
&lt;br /&gt;
# The DEFAULT section is always merged into each other section. Each section&lt;br /&gt;
# can overwrite settings done here.&lt;br /&gt;
[DEFAULT]&lt;br /&gt;
account_type = email&lt;br /&gt;
account_name = example Mail&lt;br /&gt;
account_name_short = example Mail&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
# If a domain is listed in the automx section, it may have its own section. If&lt;br /&gt;
# none is found here, the global section is used.&lt;br /&gt;
[global]&lt;br /&gt;
backend = static&lt;br /&gt;
action = settings&lt;br /&gt;
&lt;br /&gt;
# EAS (mobilesync)&lt;br /&gt;
server_url = https://eas.example.org&lt;br /&gt;
server_name = example&lt;br /&gt;
&lt;br /&gt;
# If you want to sign mobileconfig profiles, enable these options. Make sure&lt;br /&gt;
# that your webserver has proper privileges to read the key. The cert file&lt;br /&gt;
# must contain the server certificate and all intermediate certificates. You&lt;br /&gt;
# can simply concatenate these certificates.&lt;br /&gt;
#sign_mobileconfig = yes&lt;br /&gt;
#sign_cert = /path/to/cert&lt;br /&gt;
#sign_key = /path/to/key&lt;br /&gt;
&lt;br /&gt;
smtp = yes&lt;br /&gt;
smtp_server = mail.example.org&lt;br /&gt;
smtp_port = 587&lt;br /&gt;
smtp_encryption = starttls&lt;br /&gt;
smtp_auth = plaintext&lt;br /&gt;
smtp_auth_identity = %s&lt;br /&gt;
smtp_refresh_ttl = 6&lt;br /&gt;
smtp_default = yes&lt;br /&gt;
&lt;br /&gt;
imap = yes&lt;br /&gt;
imap_server = mail.example.org&lt;br /&gt;
imap_port = 993&lt;br /&gt;
imap_encryption = ssl&lt;br /&gt;
imap_auth = plaintext&lt;br /&gt;
imap_auth_identity = %s&lt;br /&gt;
imap_refresh_ttl = 6&lt;br /&gt;
pop = yes&lt;br /&gt;
pop_server = mail.example.org&lt;br /&gt;
pop_port = 995&lt;br /&gt;
pop_encryption = ssl&lt;br /&gt;
pop_auth = plaintext&lt;br /&gt;
pop_auth_identity = %s&lt;br /&gt;
pop_refresh_ttl = 6&lt;br /&gt;
&lt;br /&gt;
carddav = yes&lt;br /&gt;
carddav_server = https://dav.example.org/&lt;br /&gt;
carddav_auth_identity = %s&lt;br /&gt;
&lt;br /&gt;
caldav = yes&lt;br /&gt;
caldav_server = https://dav.example.org/&lt;br /&gt;
caldav_auth_identity = %s&lt;br /&gt;
&lt;br /&gt;
ox = yes&lt;br /&gt;
ox_server = https://ox.example.org/&lt;br /&gt;
ox_auth_identity = %s&lt;br /&gt;
&lt;br /&gt;
follow = imap_starttls&lt;br /&gt;
&lt;br /&gt;
[imap_starttls]&lt;br /&gt;
backend = static_append&lt;br /&gt;
&lt;br /&gt;
imap = yes&lt;br /&gt;
imap_server = mail.example.org&lt;br /&gt;
imap_port = 143&lt;br /&gt;
imap_encryption = starttls&lt;br /&gt;
imap_auth = plaintext&lt;br /&gt;
imap_auth_identity = %s&lt;br /&gt;
imap_refresh_ttl = 6&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Apache ====&lt;br /&gt;
&lt;br /&gt;
e.g. /etc/{apache2,httpd}/conf.d/automx.conf:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
&amp;lt;IfModule mod_wsgi.c&amp;gt;&lt;br /&gt;
    WSGIChunkedRequest On&lt;br /&gt;
&lt;br /&gt;
    WSGIScriptAliasMatch \&lt;br /&gt;
      (?i)^/.+/(autodiscover|config-v1.1).xml \&lt;br /&gt;
      /usr/lib/automx/automx_wsgi.py&lt;br /&gt;
&lt;br /&gt;
    WSGIScriptAlias \&lt;br /&gt;
      /mobileconfig \&lt;br /&gt;
      /usr/lib/automx/automx_wsgi.py&lt;br /&gt;
&lt;br /&gt;
    &amp;lt;Directory &amp;quot;/usr/lib/automx&amp;quot;&amp;gt;&lt;br /&gt;
            Require all granted&lt;br /&gt;
    &amp;lt;/Directory&amp;gt;&lt;br /&gt;
&amp;lt;/IfModule&amp;gt;&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In case the iOS/MacOS web provisioning should be provided there should also be a /etc/{apache2,httpd}/conf.d/automx-web.conf:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
Alias /automx &amp;quot;/usr/share/automx/&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;Directory &amp;quot;/usr/share/automx&amp;quot;&amp;gt;&lt;br /&gt;
    Options Indexes MultiViews&lt;br /&gt;
    Require all granted&lt;br /&gt;
&amp;lt;/Directory&amp;gt;&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
eMClient for OX App Suite has a special requirement to make the autoconfiguration experience nice and straightforward. To make it ask directly for a password instead of later in the setup process (where it requires a restart of the application to be fully functional) it is required to protect the autodiscover.xml via basic auth. In our scenario there is nothing to protect really so in this example we allow any credentials for access but still ask for some.&lt;br /&gt;
&lt;br /&gt;
For this add the following section to /etc/{apache2,httpd}/conf.d/automx.conf:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
    &amp;lt;Location &amp;quot;/autodiscover/autodiscover.xml&amp;quot;&amp;gt;&lt;br /&gt;
            AuthType Basic&lt;br /&gt;
            AuthName &amp;quot;Restricted&amp;quot;&lt;br /&gt;
            AuthBasicProvider anon&lt;br /&gt;
            Anonymous_NoUserID off&lt;br /&gt;
            Anonymous_MustGiveEmail off&lt;br /&gt;
            Anonymous_VerifyEmail off&lt;br /&gt;
            Anonymous_LogEmail off&lt;br /&gt;
            Anonymous *&lt;br /&gt;
            Require valid-user&lt;br /&gt;
    &amp;lt;/Location&amp;gt;&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Related links ==&lt;br /&gt;
&lt;br /&gt;
[[Caldav_carddav_Bundles#Autodiscovery|DAV autodiscovery]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: Clients]]&lt;br /&gt;
[[Category: Administrator]]&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=Mailclient_autoconfiguration&amp;diff=25172</id>
		<title>Mailclient autoconfiguration</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=Mailclient_autoconfiguration&amp;diff=25172"/>
		<updated>2019-12-31T11:42:17Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Providing autoconfiguration for mail clients =&lt;br /&gt;
&lt;br /&gt;
This article explains a solution for autoconfiguration for a set of mail clients which can be configured against a mail system automatically by just entering email address and password. There are three widely used approaches to do this via a self hosted lookup method, based on Microsoft&#039;s autodiscover, [https://developer.mozilla.org/en-US/docs/Mozilla/Thunderbird/Autoconfiguration Mozilla&#039;s autoconfig], and iOS/MacOS provisioning which are relevant to support detecting IMAP and SMTP server details for client configuration. Another option is solely based on DNS SRV discovery ([https://tools.ietf.org/html/rfc6186 RFC 6186]).&lt;br /&gt;
&lt;br /&gt;
Since [[AppSuite:EM_Client_for_OX_App_Suite|eMClient for OX App Suite]] is using the Microsoft based solution this service is especially important to have a smooth user experience for customer environments offering it to their users.&lt;br /&gt;
&lt;br /&gt;
autodiscover and autoconfig are based on XML schemas. Therefore for very simple deployments it might even be enough to serve some static XML files for both usecases. Please see the respective vendor standard documentation for more details.&lt;br /&gt;
&lt;br /&gt;
In this article we show how to deploy a simple autoconfiguration service based on the open source solution [https://automx.org/en/ automx].&lt;br /&gt;
&lt;br /&gt;
== Preparations ==&lt;br /&gt;
&lt;br /&gt;
The autoconfiguration protocols use several ways to find the XML provided later by automx. In the following section there is listed in which order the protocols are looking for the XML. Depending where you would like to serve the XML files you can choose from those options.&lt;br /&gt;
&lt;br /&gt;
The domain example.org as in those examples are the ones taken from the entered email address.&lt;br /&gt;
&lt;br /&gt;
=== autoconfig ===&lt;br /&gt;
&lt;br /&gt;
# http://autoconfig.example.org/mail/config-v1.1.xml&lt;br /&gt;
# http://example.org/.well-known/autoconfig/mail/config-v1.1.xml&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== autodiscover ===&lt;br /&gt;
&lt;br /&gt;
# https://example.org/autodiscover/autodiscover.xml&lt;br /&gt;
# https://autodiscover.example.org/autodiscover/autodiscover.xml&lt;br /&gt;
# DNS SRV lookup for autodiscover.tcp.example.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== DNS SRV ===&lt;br /&gt;
&lt;br /&gt;
A DNS SRV entry for autodiscover would look like this:&lt;br /&gt;
&lt;br /&gt;
  _autodiscover._tcp                      IN      SRV 0 0 443 $HOSTNAME.example.org.&lt;br /&gt;
&lt;br /&gt;
The following DNS SRV records can be used to provide configuration hints for mail clients supporting RFC 6186:&lt;br /&gt;
&lt;br /&gt;
  _submission._tcp     SRV 0 1 587 mail.example.org.&lt;br /&gt;
  _imap._tcp           SRV 2 1 143 imap.example.org.&lt;br /&gt;
  _imaps._tcp          SRV 1 1 993 imap.example.org.&lt;br /&gt;
  _pop3._tcp           SRV 4 1 110 pop3.example.org.&lt;br /&gt;
  _pop3s._tcp          SRV 3 1 995 pop3.example.org.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== automx ==&lt;br /&gt;
&lt;br /&gt;
=== Installation ===&lt;br /&gt;
&lt;br /&gt;
If you would like to support eMClient for OX App Suite please make sure that you are using a version after 1.1.1 or an earlier patched version which supports the DAV and OX services.&lt;br /&gt;
&lt;br /&gt;
For manual installation please refer to the [https://automx.org/en/#download automx download instructions].&lt;br /&gt;
&lt;br /&gt;
RPM packages for SUSE and RHEL flavours are provided by the [https://software.opensuse.org/package/automx Open Build Service]. Those packages are currently version 0.10.2 with the above patches applied and are working with Python 2.&lt;br /&gt;
&lt;br /&gt;
=== Configuration ===&lt;br /&gt;
&lt;br /&gt;
==== automx ====&lt;br /&gt;
&lt;br /&gt;
Please find detailed documentation via &#039;&#039;&#039;man automx.conf&#039;&#039;&#039; and for more dynamic setups automx_script, automx_ldap and automx_sql.&lt;br /&gt;
&lt;br /&gt;
/etc/automx.conf:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
[automx]&lt;br /&gt;
provider = example.org&lt;br /&gt;
domains = example.org, example.com&lt;br /&gt;
debug = no&lt;br /&gt;
logfile = /var/log/automx/automx.log&lt;br /&gt;
&lt;br /&gt;
# Protect against DoS&lt;br /&gt;
memcache = 127.0.0.1:11211&lt;br /&gt;
memcache_ttl = 600&lt;br /&gt;
client_error_limit = 20&lt;br /&gt;
rate_limit_exception_networks = 127.0.0.0/8, ::1/128&lt;br /&gt;
&lt;br /&gt;
# The DEFAULT section is always merged into each other section. Each section&lt;br /&gt;
# can overwrite settings done here.&lt;br /&gt;
[DEFAULT]&lt;br /&gt;
account_type = email&lt;br /&gt;
account_name = example Mail&lt;br /&gt;
account_name_short = example Mail&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
# If a domain is listed in the automx section, it may have its own section. If&lt;br /&gt;
# none is found here, the global section is used.&lt;br /&gt;
[global]&lt;br /&gt;
backend = static&lt;br /&gt;
action = settings&lt;br /&gt;
&lt;br /&gt;
# EAS (mobilesync)&lt;br /&gt;
server_url = https://eas.example.org&lt;br /&gt;
server_name = example&lt;br /&gt;
&lt;br /&gt;
# If you want to sign mobileconfig profiles, enable these options. Make sure&lt;br /&gt;
# that your webserver has proper privileges to read the key. The cert file&lt;br /&gt;
# must contain the server certificate and all intermediate certificates. You&lt;br /&gt;
# can simply concatenate these certificates.&lt;br /&gt;
#sign_mobileconfig = yes&lt;br /&gt;
#sign_cert = /path/to/cert&lt;br /&gt;
#sign_key = /path/to/key&lt;br /&gt;
&lt;br /&gt;
smtp = yes&lt;br /&gt;
smtp_server = mail.example.org&lt;br /&gt;
smtp_port = 587&lt;br /&gt;
smtp_encryption = starttls&lt;br /&gt;
smtp_auth = plaintext&lt;br /&gt;
smtp_auth_identity = %s&lt;br /&gt;
smtp_refresh_ttl = 6&lt;br /&gt;
smtp_default = yes&lt;br /&gt;
&lt;br /&gt;
imap = yes&lt;br /&gt;
imap_server = mail.example.org&lt;br /&gt;
imap_port = 993&lt;br /&gt;
imap_encryption = ssl&lt;br /&gt;
imap_auth = plaintext&lt;br /&gt;
imap_auth_identity = %s&lt;br /&gt;
imap_refresh_ttl = 6&lt;br /&gt;
pop = yes&lt;br /&gt;
pop_server = mail.example.org&lt;br /&gt;
pop_port = 995&lt;br /&gt;
pop_encryption = ssl&lt;br /&gt;
pop_auth = plaintext&lt;br /&gt;
pop_auth_identity = %s&lt;br /&gt;
pop_refresh_ttl = 6&lt;br /&gt;
&lt;br /&gt;
carddav = yes&lt;br /&gt;
carddav_server = https://dav.example.org/&lt;br /&gt;
carddav_auth_identity = %s&lt;br /&gt;
&lt;br /&gt;
caldav = yes&lt;br /&gt;
caldav_server = https://dav.example.org/&lt;br /&gt;
caldav_auth_identity = %s&lt;br /&gt;
&lt;br /&gt;
ox = yes&lt;br /&gt;
ox_server = https://ox.example.org/&lt;br /&gt;
ox_auth_identity = %s&lt;br /&gt;
&lt;br /&gt;
follow = imap_starttls&lt;br /&gt;
&lt;br /&gt;
[imap_starttls]&lt;br /&gt;
backend = static_append&lt;br /&gt;
&lt;br /&gt;
imap = yes&lt;br /&gt;
imap_server = mail.example.org&lt;br /&gt;
imap_port = 143&lt;br /&gt;
imap_encryption = starttls&lt;br /&gt;
imap_auth = plaintext&lt;br /&gt;
imap_auth_identity = %s&lt;br /&gt;
imap_refresh_ttl = 6&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Apache ====&lt;br /&gt;
&lt;br /&gt;
e.g. /etc/{apache2,httpd}/conf.d/automx.conf:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
&amp;lt;IfModule mod_wsgi.c&amp;gt;&lt;br /&gt;
    WSGIChunkedRequest On&lt;br /&gt;
&lt;br /&gt;
    WSGIScriptAliasMatch \&lt;br /&gt;
      (?i)^/.+/(autodiscover|config-v1.1).xml \&lt;br /&gt;
      /usr/lib/automx/automx_wsgi.py&lt;br /&gt;
&lt;br /&gt;
    WSGIScriptAlias \&lt;br /&gt;
      /mobileconfig \&lt;br /&gt;
      /usr/lib/automx/automx_wsgi.py&lt;br /&gt;
&lt;br /&gt;
    &amp;lt;Directory &amp;quot;/usr/lib/automx&amp;quot;&amp;gt;&lt;br /&gt;
            Require all granted&lt;br /&gt;
    &amp;lt;/Directory&amp;gt;&lt;br /&gt;
&amp;lt;/IfModule&amp;gt;&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In case the iOS/MacOS web provisioning should be provided there should also be a /etc/{apache2,httpd}/conf.d/automx-web.conf:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
Alias /automx &amp;quot;/usr/share/automx/&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;Directory &amp;quot;/usr/share/automx&amp;quot;&amp;gt;&lt;br /&gt;
    Options Indexes MultiViews&lt;br /&gt;
    Require all granted&lt;br /&gt;
&amp;lt;/Directory&amp;gt;&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
eMClient for OX App Suite has a special requirement to make the autoconfiguration experience nice and straightforward. To make it ask directly for a password instead of later in the setup process (where it requires a restart of the application to be fully functional) it is required to protect the autodiscover.xml via basic auth. In our scenario there is nothing to protect really so in this example we allow any credentials for access but still ask for some.&lt;br /&gt;
&lt;br /&gt;
For this add the following section to /etc/{apache2,httpd}/conf.d/automx.conf:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
    &amp;lt;Location &amp;quot;/autodiscover/autodiscover.xml&amp;quot;&amp;gt;&lt;br /&gt;
            AuthType Basic&lt;br /&gt;
            AuthName &amp;quot;Restricted&amp;quot;&lt;br /&gt;
            AuthBasicProvider anon&lt;br /&gt;
            Anonymous_NoUserID off&lt;br /&gt;
            Anonymous_MustGiveEmail off&lt;br /&gt;
            Anonymous_VerifyEmail off&lt;br /&gt;
            Anonymous_LogEmail off&lt;br /&gt;
            Anonymous *&lt;br /&gt;
            Require valid-user&lt;br /&gt;
    &amp;lt;/Location&amp;gt;&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Related links ==&lt;br /&gt;
&lt;br /&gt;
[[Caldav_carddav_Bundles#Autodiscovery|DAV autodiscovery]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: Clients]]&lt;br /&gt;
[[Category: Administrator]]&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=My.cnf&amp;diff=25149</id>
		<title>My.cnf</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=My.cnf&amp;diff=25149"/>
		<updated>2019-12-05T22:16:34Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
&lt;br /&gt;
This page lists some performance tuning parameters which we recommend for tuning MySQL database services used for Open-Xchange installations.&lt;br /&gt;
&lt;br /&gt;
We cannot guarantee this is an exhaustive list of required settings. So treat this list of tunings as probably required, but not necessarily sufficient settings for optimal MySQL performance.&lt;br /&gt;
&lt;br /&gt;
Furthermore, as MySQL changes over time, settings which have been correct as of the time of writing may become incorrect later.&lt;br /&gt;
&lt;br /&gt;
However, this list of settings is the result of internal performance testing and real world customer feedback, so it should be valid to some extent.&lt;br /&gt;
&lt;br /&gt;
In the end, proper configuration of the database service for performance, but also consistency, durability and high availability is in the responsibility of the customer.&lt;br /&gt;
&lt;br /&gt;
=== Performance items ===&lt;br /&gt;
&lt;br /&gt;
* You should adjust the &amp;lt;code&amp;gt;innodb_buffer_pool_size&amp;lt;/code&amp;gt; parameter for reasonable memory usage. Our DB sizing is mainly memory-driven and this is where most of the memory goes. Our standard DB machine sizing assumption is 32 GB if MySQL dedicated memory on a 48 GB total memory machine. On such a machine, you would configure 32 GB for the innodb_buffer_pool size, being aware that MySQL does also require memory for other things, in particular there are some also per-connection related memory spendings, which can become substantial if you allow for a lot of maximum concurrent connections. Please watch your memory configuration carefully, use monitoring and tools like mysqltuner.pl.&lt;br /&gt;
&lt;br /&gt;
* On bigger installations you should use &amp;lt;code&amp;gt;innodb_file_per_table = 1&amp;lt;/code&amp;gt;, which is creating single files instead of one big blob. If you change this parameter after the database initialization you have to recreate (like dump/drop and re-import) the tables.&lt;br /&gt;
&lt;br /&gt;
* It can help to put different parts of the mysql datadir (iblog, ibdata) on different filesystems / storage devices. This depends on your infrastructure. Settings herefore are &amp;lt;code&amp;gt;datadir&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;innodb_data_home_dir&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;innodb_log_group_home_dir&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
* If your storage is fast (handle a lot of IOPS), you may want to adjust the &amp;lt;code&amp;gt;innodb_io_capacity&amp;lt;/code&amp;gt; setting, which defines a limit for the IOPS MySQL will create. The default is 200, which is sensible for single spindle disks. But if you have storage appliances with a lot of fast SAS drives, or even SSDs, this limit can be increased greatly.&lt;br /&gt;
&lt;br /&gt;
=== Functional items ===&lt;br /&gt;
&lt;br /&gt;
* Query cache is to be switched off; as we found in our own benchmarks and as backed up by upstreams, this hurts performance in load situations with high concurrency. [https://dev.mysql.com/doc/refman/5.7/en/query-cache.htm The query cache is deprecated as of MySQL 5.7.20, and is removed in MySQL 8.0], so we recommend also to switch that off.&lt;br /&gt;
* Starting with App Suite 7.10.0, &amp;lt;code&amp;gt;character_set_server&amp;lt;/code&amp;gt; must be set to &amp;lt;code&amp;gt;utf8mb4&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;collation_server&amp;lt;/code&amp;gt; to &amp;lt;code&amp;gt;utf8mb4_general_ci&amp;lt;/code&amp;gt;. For older versions it must be &amp;lt;code&amp;gt;utf8&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;utf8_general_ci&amp;lt;/code&amp;gt; respectively.&lt;br /&gt;
* Starting with MySQL 5.7 &amp;lt;code&amp;gt;innodb_strict_mode&amp;lt;/code&amp;gt; must be disabled.&lt;br /&gt;
* Starting with MySQL 5.6 and MariaDB 10.1 &amp;lt;code&amp;gt;sql_mode&amp;lt;/code&amp;gt; must be configured according to belows matrix.&lt;br /&gt;
&lt;br /&gt;
==== SQL mode matrix ====&lt;br /&gt;
&lt;br /&gt;
The default for the &amp;lt;code&amp;gt;sql_mode&amp;lt;/code&amp;gt; setting changes regularly with MariaDB and MySQL releases and is not even consistent anymore between the two derivates. SQL modes affect how data and queries are handled at runtime. Enabling strict modes might lead to errors in terms of failing queries or even update tasks. We strongly recommend the following configuration to avoid according runtime errors:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! scope=&amp;quot;col&amp;quot;| sql_mode&lt;br /&gt;
! scope=&amp;quot;col&amp;quot;| App Suite 7.8.4&lt;br /&gt;
! scope=&amp;quot;col&amp;quot;| App Suite 7.10.x&lt;br /&gt;
|-&lt;br /&gt;
! scope=&amp;quot;row&amp;quot;| MySQL 5.6&lt;br /&gt;
| &amp;lt;code&amp;gt;NO_ENGINE_SUBSTITUTION&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;NO_ENGINE_SUBSTITUTION&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
! scope=&amp;quot;row&amp;quot;| MySQL 5.7&lt;br /&gt;
| &amp;lt;code&amp;gt;NO_AUTO_CREATE_USER,NO_ENGINE_SUBSTITUTION&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;NO_AUTO_CREATE_USER,NO_ENGINE_SUBSTITUTION,ONLY_FULL_GROUP_BY&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
! scope=&amp;quot;row&amp;quot;| MariaDB &amp;gt;= 10.1&lt;br /&gt;
| &amp;lt;code&amp;gt;NO_AUTO_CREATE_USER,NO_ENGINE_SUBSTITUTION&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;NO_AUTO_CREATE_USER,NO_ENGINE_SUBSTITUTION&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Sample config files ===&lt;br /&gt;
&lt;br /&gt;
For easy deployment we recommend not to edit existing the existing my.cnf file, rather assume the distro provides sane settings for most of the items and override items where needed.&lt;br /&gt;
&lt;br /&gt;
As in MySQL there is a [https://dev.mysql.com/doc/refman/5.7/en/option-files.html last instance wins] semantic in options file parsing, we propose to create a custom include directory &amp;quot;ox.conf.d&amp;quot;, put our custom config files therein, and include this directory as latest directory in /etc/mysql/my.cnf.&lt;br /&gt;
&lt;br /&gt;
To put in that directory, we have one main tuning file called tunings.cnf, one galera-related file if galera is in use, and one more galera host-specific file which contains per-host settings if using galera (separate in a file of its own for easier configuration management).&lt;br /&gt;
&lt;br /&gt;
So, start with adding to the existing my.cnf at the very bottom:&lt;br /&gt;
&lt;br /&gt;
 !includedir /etc/mysql/ox.conf.d/&lt;br /&gt;
&lt;br /&gt;
Create that directory and put in there the generic ox tunings file /etc/mysql/ox.conf.d/tunings.cnf:&lt;br /&gt;
&lt;br /&gt;
 [mysqld]&lt;br /&gt;
 bind-address		 = *&lt;br /&gt;
 &lt;br /&gt;
 #innodb_use_native_aio = 0&lt;br /&gt;
 &lt;br /&gt;
 table_open_cache = 3072&lt;br /&gt;
 table_definition_cache = 4096&lt;br /&gt;
 max_heap_table_size = 64M&lt;br /&gt;
 tmp_table_size = 64M&lt;br /&gt;
 max_connections = 505&lt;br /&gt;
 max_user_connections = 500&lt;br /&gt;
 max_allowed_packet = 16M&lt;br /&gt;
 thread_cache_size = 32&lt;br /&gt;
 query_cache_size = 0&lt;br /&gt;
 query_cache_type = 0&lt;br /&gt;
 innodb_buffer_pool_size = 32G&lt;br /&gt;
 # the default value in MySQL 5.6.6 and higher is 8 when innodb_buffer_pool_size is greater than or equal to 1GB. Otherwise, the default is 1. &lt;br /&gt;
 innodb_buffer_pool_instances = 32&lt;br /&gt;
 innodb_data_file_path = ibdata1:128M:autoextend&lt;br /&gt;
 innodb_file_per_table = 1&lt;br /&gt;
 # innodb_log_file_size should be 25% of the innodb_buffer_pool_size&lt;br /&gt;
 innodb_log_file_size = 4GB&lt;br /&gt;
 # default and recommended value is 2&lt;br /&gt;
 innodb_log_files_in_group = 2&lt;br /&gt;
 # adjust according to your storage&lt;br /&gt;
 #innodb_io_capacity = 1000&lt;br /&gt;
 &lt;br /&gt;
 # we are unsure about this setting. Newer versions of MariaDB seem to be fine with low (=1) settings for this value.&lt;br /&gt;
 # Traditionally we encountered values up to 4x the number of cores.&lt;br /&gt;
 # Default seems to be number of cores, so let&#039;s stick the default&lt;br /&gt;
 # In the end, we need to leave this setting up to you: if you dont get full cpu utilization in cpu-bound situations, this might be a setting to increase.&lt;br /&gt;
 #thread_pool_size = 32&lt;br /&gt;
 &lt;br /&gt;
 binlog_cache_size = 1M&lt;br /&gt;
 sync_binlog = 8&lt;br /&gt;
 binlog_format = row&lt;br /&gt;
 &lt;br /&gt;
 character_set_server = utf8mb4&lt;br /&gt;
 collation_server = utf8mb4_general_ci&lt;br /&gt;
 &lt;br /&gt;
 # This was default_table_type previous to MySQL 5.5&lt;br /&gt;
 default_storage_engine = InnoDB&lt;br /&gt;
 &lt;br /&gt;
 innodb_autoinc_lock_mode = 2&lt;br /&gt;
 &lt;br /&gt;
 # keep until 5.6, deprecated later&lt;br /&gt;
 innodb_locks_unsafe_for_binlog = 1&lt;br /&gt;
 &lt;br /&gt;
 # we found this has huge impact on (galera) performance&lt;br /&gt;
 # default (consistent) setting of 1 greatly severs performance&lt;br /&gt;
 # in galera (or async master-slave) deployments, you might be ok with setting this to 0 or 2,&lt;br /&gt;
 # assuming our consistency / availability comes from replication / other cluster nodes&lt;br /&gt;
 innodb_flush_log_at_trx_commit = 0&lt;br /&gt;
 &lt;br /&gt;
 # for performance testing systems, to not use excessive disk space&lt;br /&gt;
 #expire_logs_days = 1&lt;br /&gt;
 &lt;br /&gt;
 # MySQL 5.7.7 has changed the default to 1. Disable it explicitly to prevent from errors based on invalid data stored by former App Suite or MySQL versions.&lt;br /&gt;
 innodb_strict_mode = 0&lt;br /&gt;
 &lt;br /&gt;
 # The following value refers to App Suite 7.10 on top of MySQL 5.7. For other combinations see the sql mode matrix at http://oxpedia.org/wiki/index.php?title=My.cnf.&lt;br /&gt;
 sql_mode = NO_ENGINE_SUBSTITUTION,NO_AUTO_CREATE_USER,ONLY_FULL_GROUP_BY&lt;br /&gt;
&lt;br /&gt;
If using galera, use the following galera configuration file &amp;lt;code&amp;gt;/etc/mysql/ox.conf.d/wsrep.cnf&amp;lt;/code&amp;gt;. See the comments in that file for values to be adjusted.&lt;br /&gt;
&lt;br /&gt;
 [mysqld]&lt;br /&gt;
 # adjust for your distros SO location&lt;br /&gt;
 wsrep_provider=/usr/lib/libgalera_smm.so&lt;br /&gt;
 &lt;br /&gt;
 # this is the big winner and enables us to switch off OX&#039;s replication monitor&lt;br /&gt;
 wsrep_sync_wait=1&lt;br /&gt;
 &lt;br /&gt;
 # pick a unique cluster name&lt;br /&gt;
 wsrep_cluster_name=devcluster&lt;br /&gt;
 # adjust for your IPs / hostnames&lt;br /&gt;
 wsrep_cluster_address=gcomm://10.20.29.68,10.20.29.69,10.20.29.70&lt;br /&gt;
 &lt;br /&gt;
 # put this in host.cnf&lt;br /&gt;
 #wsrep_node_name=...&lt;br /&gt;
 #wsrep_node_address=...&lt;br /&gt;
 &lt;br /&gt;
 # For some MariaDB versions, xtrabackup-v2 no longer works, instead use &amp;quot;mariabackup&amp;quot;&lt;br /&gt;
 # (needs to be installed separately, e.g. via the mariadb-backup-10.2 package)&lt;br /&gt;
 # see upstream documentation for details: &lt;br /&gt;
 # https://mariadb.com/kb/en/library/getting-started-with-mariadb-galera-cluster/#xtrabackup&lt;br /&gt;
 #&lt;br /&gt;
 # wsrep_sst_method=mariabackup&lt;br /&gt;
 wsrep_sst_method=xtrabackup-v2&lt;br /&gt;
&lt;br /&gt;
 # wsrep_sst_auth if of format username:password&lt;br /&gt;
 # pick whatever you configured on the donor node&lt;br /&gt;
 wsrep_sst_auth=sstuser:...&lt;br /&gt;
 &lt;br /&gt;
 # galera-specific tunings&lt;br /&gt;
 wsrep_slave_threads = 32&lt;br /&gt;
 &lt;br /&gt;
 # finally, enable wsrep: required for some MariaDB versions&lt;br /&gt;
 wsrep_on=ON -- Enable wsrep replication (MariaDB starting 10.1.1) &lt;br /&gt;
&lt;br /&gt;
Galera-related host-specific settings go in /etc/mysql/ox.conf.d/host.cnf:&lt;br /&gt;
&lt;br /&gt;
 [mysqld]&lt;br /&gt;
 # the nodes hostname&lt;br /&gt;
 wsrep_node_name=...&lt;br /&gt;
 # and the IP of the wsrep relevant interface, if multiple&lt;br /&gt;
 wsrep_node_address=10.20.29.68&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:Syslog_Configuration&amp;diff=25078</id>
		<title>AppSuite:Syslog Configuration</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=AppSuite:Syslog_Configuration&amp;diff=25078"/>
		<updated>2019-11-22T16:35:54Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Open-Xchange Syslog Configuration=&lt;br /&gt;
&lt;br /&gt;
This article is valid up to version &#039;&#039;&#039;7.4.1&#039;&#039;&#039;&lt;br /&gt;
For current information please check [[AppSuite:OX_Logging]]&lt;br /&gt;
&lt;br /&gt;
==Abstract==&lt;br /&gt;
Open-Xchange provides the OSGi package &#039;&#039;open-xchange-log4j&#039;&#039; to enable remote logging via syslog. This is useful for distributed setups or if a logging strategy is already present at the environments the servers are running. If you choose syslog to be the logging mechanism, the syslog service needs some configuration to accept remote logging, even if the service is running on localhost.&lt;br /&gt;
&lt;br /&gt;
The syslog remote logging will open port 514/udp, so don&#039;t forget to firewall it properly if it&#039;s a security risk for you. The default logging facility of Open-Xchange is defined at the &#039;&#039;/opt/open-xchange/etc/log4j.xml&#039;&#039; file. For more granular log filtering this facility can be changed. Please refer to the rsyslog, syslog and syslog-ng documentation for further information.&lt;br /&gt;
&lt;br /&gt;
{{InstallPlugin|pluginname=open-xchange-log4j|toplevel=products|sopath=appsuite/stable/backend|version=App Suite}}&lt;br /&gt;
&lt;br /&gt;
== Configuration ==&lt;br /&gt;
Please note, there are numerous syslog daemons available and the configuration may also differ between Linux distributions. To make open-xchange-log4j running in collaboration with the syslog&lt;br /&gt;
daemon of your choice, you have to enable logging via UDP protocol and listening port 514. Please&lt;br /&gt;
read for details the documentation of your running syslog service. &lt;br /&gt;
=== For RHEL, CentOS and Debian ===&lt;br /&gt;
&lt;br /&gt;
The parameter configuration is done in a configuration file at &#039;&#039;/etc/rsyslog.conf&#039;&#039; in case you are running the popular rsyslog daemon.&lt;br /&gt;
&lt;br /&gt;
 # provides UDP syslog reception&lt;br /&gt;
 $ModLoad imudp&lt;br /&gt;
 $UDPServerRun 514&lt;br /&gt;
&lt;br /&gt;
If you like to enable remote logging it is might be needed to enable this by &amp;quot;/etc/default/rsyslog&amp;quot; configuration file.&lt;br /&gt;
&lt;br /&gt;
 # Options for rsyslogd&lt;br /&gt;
 # -m 0 disables &#039;MARK&#039; messages (deprecated, only used in compat mode &amp;lt; 3)&lt;br /&gt;
 # -r enables logging from remote machines (deprecated, only used in compat mode &amp;lt; 3)&lt;br /&gt;
 # -x disables DNS lookups on messages received with -r&lt;br /&gt;
 # -c compatibility mode&lt;br /&gt;
 # See rsyslogd(8) for more details&lt;br /&gt;
 RSYSLOGD_OPTIONS=&amp;quot;-c4 -r&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; On a recent Debian version, you might have to set compat mode to 0-2 in order for -r to work&lt;br /&gt;
&lt;br /&gt;
Then restart the rsyslog service to enable remote logging.&lt;br /&gt;
 $ /etc/init.d/rsyslog restart&lt;br /&gt;
&lt;br /&gt;
By default, all Open-Xchange log messages are put to &#039;&#039;/var/log/syslog&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
===For SUSE Linux Enterprise Server 11 ===&lt;br /&gt;
SLES11 comes up with syslog-ng, modify the configuration at &#039;&#039;/etc/syslog-ng/syslog-ng.conf&#039;&#039;:&lt;br /&gt;
&lt;br /&gt;
 source src {&lt;br /&gt;
        #&lt;br /&gt;
        # include internal syslog-ng messages&lt;br /&gt;
        # note: the internal() soure is required!&lt;br /&gt;
        #&lt;br /&gt;
        internal();&lt;br /&gt;
 &lt;br /&gt;
        #&lt;br /&gt;
        # the default log socket for local logging:&lt;br /&gt;
        #&lt;br /&gt;
        unix-dgram(&amp;quot;/dev/log&amp;quot;);&lt;br /&gt;
 &lt;br /&gt;
        #&lt;br /&gt;
        # uncomment to process log messages from network:&lt;br /&gt;
        #&lt;br /&gt;
        udp(ip(&amp;quot;0.0.0.0&amp;quot;) port(514));&lt;br /&gt;
 };&lt;br /&gt;
&lt;br /&gt;
Uncomment the last statement of the src definition and restart the syslog service to enable logging.&lt;br /&gt;
 $ /etc/init.d/syslog restart&lt;br /&gt;
&lt;br /&gt;
By default, all Open-Xchange log messages are put to &#039;&#039;/var/log/messages&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
[[Category: OX6]]&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=Tokenlogin_form&amp;diff=24829</id>
		<title>Tokenlogin form</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=Tokenlogin_form&amp;diff=24829"/>
		<updated>2019-08-12T10:59:25Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: /* Example */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Interactive token login form =&lt;br /&gt;
&lt;br /&gt;
== Example ==&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&#039;html4strict&#039;&amp;gt;&lt;br /&gt;
&amp;lt;!DOCTYPE html PUBLIC &amp;quot;-//W3C//DTD HTML 4.01//EN&amp;quot; &amp;quot;http://www.w3.org/TR/html4/strict.dtd&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;html&amp;gt;&lt;br /&gt;
&amp;lt;head&amp;gt;&lt;br /&gt;
&amp;lt;meta http-equiv=&amp;quot;content-type&amp;quot; content=&amp;quot;text/html; charset=UTF-8&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;meta http-equiv=&amp;quot;cache-control&amp;quot; content=&amp;quot;no-cache&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;title&amp;gt;Login&amp;lt;/title&amp;gt;&lt;br /&gt;
&amp;lt;script type=&amp;quot;text/javascript&amp;quot;&amp;gt;&lt;br /&gt;
function uuid() {&lt;br /&gt;
    function hex(len, x) {&lt;br /&gt;
        if (x === undefined) x = Math.random();&lt;br /&gt;
        var s = new Array(len);&lt;br /&gt;
        for (var i = 0; i &amp;lt; len; i++) {&lt;br /&gt;
            x *= 16;&lt;br /&gt;
            var digit = x &amp;amp; 15;&lt;br /&gt;
            s[i] = digit + (digit &amp;lt; 10 ? 48 : 87); // &#039;0&#039; and &#039;a&#039; - 10&lt;br /&gt;
        }&lt;br /&gt;
        return String.fromCharCode.apply(String, s);&lt;br /&gt;
    }&lt;br /&gt;
    return [hex(8), &amp;quot;-&amp;quot;, hex(4), &amp;quot;-4&amp;quot;, hex(3), &amp;quot;-&amp;quot;, hex(4, 0.5 + Math.random() / 4), &amp;quot;-&amp;quot;, hex(12)].join(&amp;quot;&amp;quot;);&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
window.addEventListener(&amp;quot;load&amp;quot;, function () {&lt;br /&gt;
  function sendData() {&lt;br /&gt;
    var XHR = new XMLHttpRequest();&lt;br /&gt;
    var target = &amp;quot;$BASEURL_TO_OX&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
    // Bind the FormData object and the form element&lt;br /&gt;
    var FD = new FormData(form);&lt;br /&gt;
    // enhance with clientToken&lt;br /&gt;
    static_uuid = uuid();&lt;br /&gt;
    FD.append(&#039;clientToken&#039;, static_uuid);&lt;br /&gt;
    FD.append(&#039;jsonResponse&#039;, true);&lt;br /&gt;
&lt;br /&gt;
    // Define what happens on successful data submission&lt;br /&gt;
    XHR.addEventListener(&amp;quot;load&amp;quot;, function(event) {&lt;br /&gt;
      // successful login; now redirect into the session&lt;br /&gt;
      var response=JSON.parse(event.target.responseText);&lt;br /&gt;
      // check for errors&lt;br /&gt;
      if (response.error || !response.url) {&lt;br /&gt;
        error_message.innerHTML = response.error;&lt;br /&gt;
      } else {&lt;br /&gt;
        // finally point to the target&lt;br /&gt;
        window.location.replace(target + response.url + &amp;quot;&amp;amp;clientToken=&amp;quot; + static_uuid);&lt;br /&gt;
      }&lt;br /&gt;
    });&lt;br /&gt;
&lt;br /&gt;
    // Define what happens in case of error&lt;br /&gt;
    XHR.addEventListener(&amp;quot;error&amp;quot;, function(event) {&lt;br /&gt;
      alert(&#039;Oops! Something went wrong.&#039;);&lt;br /&gt;
    });&lt;br /&gt;
&lt;br /&gt;
    // Set up our request&lt;br /&gt;
    XHR.open(&amp;quot;POST&amp;quot;, target + &amp;quot;/ajax/login?action=tokenLogin&amp;amp;authId=&amp;quot; + uuid());&lt;br /&gt;
&lt;br /&gt;
    // The data sent is what the user provided in the form&lt;br /&gt;
    XHR.send(new URLSearchParams(FD));&lt;br /&gt;
  }&lt;br /&gt;
&lt;br /&gt;
  // Access the form element...&lt;br /&gt;
  var form = document.getElementById(&amp;quot;myForm&amp;quot;);&lt;br /&gt;
  var error_message = document.getElementById(&amp;quot;error&amp;quot;);&lt;br /&gt;
&lt;br /&gt;
  // ...and take over its submit event.&lt;br /&gt;
  form.addEventListener(&amp;quot;submit&amp;quot;, function (event) {&lt;br /&gt;
    event.preventDefault();&lt;br /&gt;
&lt;br /&gt;
    sendData();&lt;br /&gt;
  });&lt;br /&gt;
});&lt;br /&gt;
&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;/head&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;body&amp;gt;&lt;br /&gt;
    &amp;lt;form id=&#039;myForm&#039;&amp;gt;&lt;br /&gt;
            &amp;lt;label for=&amp;quot;login&amp;quot;&amp;gt;Username: &amp;lt;/label&amp;gt;&lt;br /&gt;
            &amp;lt;input type=&amp;quot;text&amp;quot; name=&amp;quot;login&amp;quot; id=&amp;quot;login&amp;quot;&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
            &amp;lt;label for=&amp;quot;password&amp;quot;&amp;gt;Password:  &amp;lt;/label&amp;gt;&lt;br /&gt;
            &amp;lt;input type=&amp;quot;password&amp;quot; name=&amp;quot;password&amp;quot; id=&amp;quot;password&amp;quot;&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
            &amp;lt;input type=&amp;quot;submit&amp;quot; value=&amp;quot;Login&amp;quot;&amp;gt;&lt;br /&gt;
            &amp;lt;!-- autologin=true could be leading to unexpected results if there still is a valid session associated with the used browser --&amp;gt;&lt;br /&gt;
            &amp;lt;input type=&amp;quot;hidden&amp;quot; name=&amp;quot;autologin&amp;quot; value=&amp;quot;false&amp;quot;&amp;gt;&lt;br /&gt;
            &amp;lt;input type=&amp;quot;hidden&amp;quot; name=&amp;quot;client&amp;quot; value=&amp;quot;open-xchange-appsuite&amp;quot;&amp;gt;&lt;br /&gt;
            &amp;lt;input type=&amp;quot;hidden&amp;quot; name=&amp;quot;version&amp;quot; value=&amp;quot;Sample Loginpage&amp;quot;&amp;gt;&lt;br /&gt;
            &amp;lt;input type=&amp;quot;hidden&amp;quot; name=&amp;quot;uiWebPath&amp;quot; value=&amp;quot;/appsuite/&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;/form&amp;gt;&lt;br /&gt;
    &amp;lt;div id=&#039;error&#039; /&amp;gt;&lt;br /&gt;
&amp;lt;/body&amp;gt;&lt;br /&gt;
&amp;lt;/html&amp;gt;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=Dovecot_Mailpush&amp;diff=24774</id>
		<title>Dovecot Mailpush</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=Dovecot_Mailpush&amp;diff=24774"/>
		<updated>2019-07-24T20:32:14Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;&#039;Please find the up-to-date version of this article [https://doc.dovecot.org/plugin-settings/push_notification/ here]&#039;&#039;&#039;&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=Tokenlogin_form&amp;diff=24770</id>
		<title>Tokenlogin form</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=Tokenlogin_form&amp;diff=24770"/>
		<updated>2019-07-16T07:38:32Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: Created page with &amp;quot;= Interactive token login form =  == Example == &amp;lt;syntaxhighlight lang=&amp;#039;html4strict&amp;#039;&amp;gt; &amp;lt;!DOCTYPE html PUBLIC &amp;quot;-//W3C//DTD HTML 4.01//EN&amp;quot; &amp;quot;http://www.w3.org/TR/html4/strict.dtd&amp;quot;&amp;gt;...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Interactive token login form =&lt;br /&gt;
&lt;br /&gt;
== Example ==&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&#039;html4strict&#039;&amp;gt;&lt;br /&gt;
&amp;lt;!DOCTYPE html PUBLIC &amp;quot;-//W3C//DTD HTML 4.01//EN&amp;quot; &amp;quot;http://www.w3.org/TR/html4/strict.dtd&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;html&amp;gt;&lt;br /&gt;
&amp;lt;head&amp;gt;&lt;br /&gt;
&amp;lt;meta http-equiv=&amp;quot;content-type&amp;quot; content=&amp;quot;text/html; charset=UTF-8&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;meta http-equiv=&amp;quot;cache-control&amp;quot; content=&amp;quot;no-cache&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;title&amp;gt;Login&amp;lt;/title&amp;gt;&lt;br /&gt;
&amp;lt;script type=&amp;quot;text/javascript&amp;quot;&amp;gt;&lt;br /&gt;
function uuid() {&lt;br /&gt;
    function hex(len, x) {&lt;br /&gt;
        if (x === undefined) x = Math.random();&lt;br /&gt;
        var s = new Array(len);&lt;br /&gt;
        for (var i = 0; i &amp;lt; len; i++) {&lt;br /&gt;
            x *= 16;&lt;br /&gt;
            var digit = x &amp;amp; 15;&lt;br /&gt;
            s[i] = digit + (digit &amp;lt; 10 ? 48 : 87); // &#039;0&#039; and &#039;a&#039; - 10&lt;br /&gt;
        }&lt;br /&gt;
        return String.fromCharCode.apply(String, s);&lt;br /&gt;
    }&lt;br /&gt;
    return [hex(8), &amp;quot;-&amp;quot;, hex(4), &amp;quot;-4&amp;quot;, hex(3), &amp;quot;-&amp;quot;, hex(4, 0.5 + Math.random() / 4), &amp;quot;-&amp;quot;, hex(12)].join(&amp;quot;&amp;quot;);&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
window.addEventListener(&amp;quot;load&amp;quot;, function () {&lt;br /&gt;
  function sendData() {&lt;br /&gt;
    var XHR = new XMLHttpRequest();&lt;br /&gt;
    var target = &amp;quot;$BASEURL_TO_OX&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
    // Bind the FormData object and the form element&lt;br /&gt;
    var FD = new FormData(form);&lt;br /&gt;
    // enhance with clientToken&lt;br /&gt;
    static_uuid = uuid();&lt;br /&gt;
    FD.append(&#039;clientToken&#039;, static_uuid);&lt;br /&gt;
    FD.append(&#039;jsonResponse&#039;, true);&lt;br /&gt;
&lt;br /&gt;
    // Define what happens on successful data submission&lt;br /&gt;
    XHR.addEventListener(&amp;quot;load&amp;quot;, function(event) {&lt;br /&gt;
      // successful login; now redirect into the session&lt;br /&gt;
      var response=JSON.parse(event.target.responseText);&lt;br /&gt;
      // check for errors&lt;br /&gt;
      if (response.error || !response.url) {&lt;br /&gt;
        error_message.innerHTML = response.error;&lt;br /&gt;
      } else {&lt;br /&gt;
        // finally point to the target&lt;br /&gt;
        window.location.replace(target + response.url + &amp;quot;&amp;amp;clientToken=&amp;quot; + static_uuid);&lt;br /&gt;
      }&lt;br /&gt;
    });&lt;br /&gt;
&lt;br /&gt;
    // Define what happens in case of error&lt;br /&gt;
    XHR.addEventListener(&amp;quot;error&amp;quot;, function(event) {&lt;br /&gt;
      alert(&#039;Oops! Something went wrong.&#039;);&lt;br /&gt;
    });&lt;br /&gt;
&lt;br /&gt;
    // Set up our request&lt;br /&gt;
    XHR.open(&amp;quot;POST&amp;quot;, target + &amp;quot;/ajax/login?action=tokenLogin&amp;amp;authId=&amp;quot; + uuid());&lt;br /&gt;
&lt;br /&gt;
    // The data sent is what the user provided in the form&lt;br /&gt;
    XHR.send(new URLSearchParams(FD));&lt;br /&gt;
  }&lt;br /&gt;
&lt;br /&gt;
  // Access the form element...&lt;br /&gt;
  var form = document.getElementById(&amp;quot;myForm&amp;quot;);&lt;br /&gt;
  var error_message = document.getElementById(&amp;quot;error&amp;quot;);&lt;br /&gt;
&lt;br /&gt;
  // ...and take over its submit event.&lt;br /&gt;
  form.addEventListener(&amp;quot;submit&amp;quot;, function (event) {&lt;br /&gt;
    event.preventDefault();&lt;br /&gt;
&lt;br /&gt;
    sendData();&lt;br /&gt;
  });&lt;br /&gt;
});&lt;br /&gt;
&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;/head&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;body&amp;gt;&lt;br /&gt;
    &amp;lt;form id=&#039;myForm&#039;&amp;gt;&lt;br /&gt;
            &amp;lt;label for=&amp;quot;login&amp;quot;&amp;gt;Username: &amp;lt;/label&amp;gt;&lt;br /&gt;
            &amp;lt;input type=&amp;quot;text&amp;quot; name=&amp;quot;login&amp;quot; id=&amp;quot;login&amp;quot;&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
            &amp;lt;label for=&amp;quot;password&amp;quot;&amp;gt;Password:  &amp;lt;/label&amp;gt;&lt;br /&gt;
            &amp;lt;input type=&amp;quot;password&amp;quot; name=&amp;quot;password&amp;quot; id=&amp;quot;password&amp;quot;&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
            &amp;lt;input type=&amp;quot;submit&amp;quot; value=&amp;quot;Login&amp;quot;&amp;gt;&lt;br /&gt;
            &amp;lt;input type=&amp;quot;hidden&amp;quot; name=&amp;quot;autologin&amp;quot; value=&amp;quot;true&amp;quot;&amp;gt;&lt;br /&gt;
            &amp;lt;input type=&amp;quot;hidden&amp;quot; name=&amp;quot;client&amp;quot; value=&amp;quot;open-xchange-appsuite&amp;quot;&amp;gt;&lt;br /&gt;
            &amp;lt;input type=&amp;quot;hidden&amp;quot; name=&amp;quot;version&amp;quot; value=&amp;quot;Sample Loginpage&amp;quot;&amp;gt;&lt;br /&gt;
            &amp;lt;input type=&amp;quot;hidden&amp;quot; name=&amp;quot;uiWebPath&amp;quot; value=&amp;quot;/appsuite/&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;/form&amp;gt;&lt;br /&gt;
    &amp;lt;div id=&#039;error&#039; /&amp;gt;&lt;br /&gt;
&amp;lt;/body&amp;gt;&lt;br /&gt;
&amp;lt;/html&amp;gt;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
	<entry>
		<id>https://wiki.open-xchange.com/wiki/index.php?title=Login_variations&amp;diff=24769</id>
		<title>Login variations</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-xchange.com/wiki/index.php?title=Login_variations&amp;diff=24769"/>
		<updated>2019-07-16T07:33:30Z</updated>

		<summary type="html">&lt;p&gt;WolfgangRosenauer: /* Token Login */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div class=&amp;quot;title&amp;quot;&amp;gt;Login variations&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Introduction:&#039;&#039;&#039; This paper describes Open-Xchanges&#039;s authentication and session handling. It gives an overview of all available mechanisms and on how to safely pass on sessions from external applications to the Open-Xchange Server (Single Sign On, SSO).&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
The Open-Xchange Server web front-end is implemented in AJAX (Asynchronous JavaScript and XML). Thus the complete user interface (GUI) is running in a browser. Opposed to standard web applications there are no HTML pages generated and delivered by the browser.&lt;br /&gt;
&lt;br /&gt;
The complete user front-end is rendered and displayed in the browser. Based on HTTP/S  the data are exchanged with the server via JavaScript Object Notation (JSON). That means it is not possible to simulate front-end actions  via HTTP/S request by simulating respectively formatted GET/POST calls. Instead, another abstraction is taking place that exclusively transfers data from GUI to server and vice versa.&lt;br /&gt;
&lt;br /&gt;
The Open-Xchange Server includes a session daemon (sessiond) that keeps the current data of a logged in user. If successfully authenticated the information kept in the session are sufficient for accessing the Open-Xchange Server.&lt;br /&gt;
&lt;br /&gt;
==Access to IMAP Back-End services==&lt;br /&gt;
To access external E-Mail systems (IMAP/SMTP) the Open-Xchange Server has to know the credentials of the current user for the system, i. e. the session object has to keep the respective password for the access in plain text. That means authenticating via SessionIDs alone is not sufficient. Authentication always has to take place by entering the username and password.&lt;br /&gt;
&lt;br /&gt;
(There are two exceptions: either if one master password is used for all IMAP accounts, or if a very special implementation of MAL is used, which does not need a password.)&lt;br /&gt;
&lt;br /&gt;
==Basic Implementation Rules==&lt;br /&gt;
* It must not be possible to get a valid session by e. g. guessing a SessionID. This is especially important when being passed on by an external system&lt;br /&gt;
* A session must not be verified by a single SessionID only, but has to compare at least two different data types, this is what the Session-Secret is for&lt;br /&gt;
* Both SessionID and Session-Secret must never be passed from the Open-Xchange server to the client in the same request. This ensures, that potential issues in the stack between the client and Open-Xchange (proxies, caches, loadbalancer, Apache, …) can not lead to wrong sessions &lt;br /&gt;
* To enhance security Session-Secret and SessionID are transferred as different data types. The Session-Secret will always be transferred as a cookie, the SessionID will be transferred as URL parameter if persistent auto-login is not activated for this session.&lt;br /&gt;
* It must never be possible to have conflicting session information per client (multiple cookies) within the same cookie store&lt;br /&gt;
* If any error in the session handling is detected, the relevant request is discarded and logged. It is not tried to fix the issue&lt;br /&gt;
* In memory data (SessionID) of the browser GUI must never be changed during a valid session&lt;br /&gt;
* All relevant information regarding session management must always be written to the relevant logfiles&lt;br /&gt;
* The whole mechanism is only secure when being used via encrypted connection&lt;br /&gt;
* ATTENTION: If persistent autologin is activated for the system and a user decided to use it, all information necessary to access the Open-Xchange server is stored within the browsers cookie store.  This means, that the security of the whole system depends on the level of security of the browsers cookie store&lt;br /&gt;
&lt;br /&gt;
== Authentication and Session Tokens ==&lt;br /&gt;
Following tokens are used for the session management:&lt;br /&gt;
&lt;br /&gt;
=== SessionID ===&lt;br /&gt;
The SessionID is used to identify every session. It is a UUID, generated by the backend via default Java UUID implementation. It is written into the OX logfiles for every log message. When no auto-login is used for the session, then the SessionID is transferred as an URL parameter. If auto-login is activated, then the SessionID is transferred as a cookie.&lt;br /&gt;
&lt;br /&gt;
=== Session-Secret ===&lt;br /&gt;
The Session-Secret is used to verify every session. It is a UUID, generated by the backend via default Java UUID implementation. Only accesses, where the Session-Secret matches with the one stored in SessionD for the given SessionID are valid. Mismatches lead to immediate session termination.&lt;br /&gt;
&lt;br /&gt;
=== Public Session ===&lt;br /&gt;
The public Session is used as a replacement for the SessionID. It is a UUID, generated by the backend via default Java UUID implementation. The Public Session is transferred as a cookie named &amp;lt;tt&amp;gt;open-xchange-public-session-uuid&amp;lt;/tt&amp;gt;. Using the Public Session is limited to some non critical requests. By using this cookie instead of a request parameter, the browser is able to cache the response of special requests (e.g. contact images).&lt;br /&gt;
&lt;br /&gt;
=== Random ===&lt;br /&gt;
The Random-Token is a one time token with a limited lifetime, which is used to initiate sessions through 3rd party applications or websites. It is a UUID, generated by the backend via default Java UUID implementation. This token is deprecated and subject to change.&lt;br /&gt;
&lt;br /&gt;
=== Cookie Handling ===&lt;br /&gt;
In several situations, cookies are used to store and transfer the session tokens. The following rules for cookie creation and storage apply.&lt;br /&gt;
&lt;br /&gt;
==== Only one cookie per client session type ====&lt;br /&gt;
It must never happen, that the same client has more than one session associated with an Open-Xchange server. Therefore the cookies need to have the same name. If a new cookie is set to the browser, the original one will be overwritten. With the next client access either the SessionID or the Session-Secret do not match anymore and the invalid session is terminated.&lt;br /&gt;
Multiple clients with same cookie store.&lt;br /&gt;
&lt;br /&gt;
On the other hand it may happen, that several clients use the same cookie store. E.g. a standard browser GUI session and a browser plugin session. Therefore the cookie name needs to contain informations about the client.&lt;br /&gt;
&lt;br /&gt;
==== Naming of cookies ====&lt;br /&gt;
The cookies are named following this schema:&lt;br /&gt;
&lt;br /&gt;
  open-xchange-session-&amp;lt;&amp;lt;name token&amp;gt;&amp;gt;=&amp;lt;&amp;lt;SessionID&amp;gt;&amp;gt;&lt;br /&gt;
  open-xchange-secret-&amp;lt;&amp;lt;name token&amp;gt;&amp;gt;=&amp;lt;&amp;lt;Session-Secret&amp;gt;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Where &amp;lt;&amp;lt;name token&amp;gt;&amp;gt; is generated from configurable data associated with the client. It is a md5-hash build from the client-id and the User-Agent is used to identify the client. Other parameters can be added through a configuration file. If a request is performed by a browser with an invalid hash the corresponding cookies and session are invalidated.&lt;br /&gt;
&lt;br /&gt;
====Lifetime of cookies====&lt;br /&gt;
Normally, cookies are session cookies, which get invalid/deleted when the browser is shut down. &lt;br /&gt;
Using the persistent auto-login, the cookies are persistent cookies, with a configurable default. The default lifetime is one week.&lt;br /&gt;
&lt;br /&gt;
====Security of a cookie====&lt;br /&gt;
Cookies can be configured in different ways to be secure. For further information visit [[OXSessionSecurityFeatures]] &lt;br /&gt;
&lt;br /&gt;
All cookies get deleted when a logout is performed.&lt;br /&gt;
&lt;br /&gt;
==IP Check==&lt;br /&gt;
Per default an IP check is activated to terminate every session immediately, if the IP address of the client changes during the session lifetime. This check is not processed, when a session is reactivated following the persistent auto-login process.&lt;br /&gt;
There are several configuration options to enable, disable the IP Check and to define IP Ranges to omit the check and/or accept recurring connections from within these ranges. For further information on the configuration see [https://oxpedia.org/wiki/index.php?title=AppSuite:Configuration_properties_7.8.2 configuration properties].&lt;br /&gt;
&lt;br /&gt;
==Access via web browser with user credentials==&lt;br /&gt;
When directly logging in to the system by entering the credentials, following steps will be done to authenticate the user or verify the validity of the session after the authentication:&lt;br /&gt;
&lt;br /&gt;
# The browser sends initial request to the Open-Xchange server. The client represented by the application:&lt;br /&gt;
## is not authenticated yet&lt;br /&gt;
## has no cookie&lt;br /&gt;
## has no session ID.&lt;br /&gt;
# Open-Xchange server sends an AJAX application to browser.  The application is loaded into the browser and no data is exchanged between server and application.&lt;br /&gt;
# The AJAX application then will try to do an auto-login. Because the application has no knowledge of the cookies that may already be stored in the browser it will try to login the client. For further information on auto-login see [[OXSessionAutologin]]. With the precondition form 1. the auto-login try will be denied.&lt;br /&gt;
# The user enters username and password in the front-end.&lt;br /&gt;
# The username and password are sent to the server via JSON (SSL). If the user activated persistent auto-login on the login screen, this information is passed with the same request.&lt;br /&gt;
# The server authenticates the client and sends following data back to the browser via JSON (the data are saved in the session object):&lt;br /&gt;
## Session ID via JSON object&lt;br /&gt;
## (Optional) Random token for initial login via JSON object. For the random token to be send the server needs to be configured(see login.properties – com.openexchange.axaj.login.randomToken). CAUTION! The random token is deprecated and should no longer be used!&lt;br /&gt;
## Cookie with JSESSIONID. The JSESSIONID is set for loadbalancing to the browser&lt;br /&gt;
## Cookie containing the session secret. If persistent auto-login is selected, the cookie is configured with the relevant type and validity.&lt;br /&gt;
## Cookie containing the public identifier.&lt;br /&gt;
# The AJAX front-end saves the session ID in its memory. (Optional)  Ignores the random token.&lt;br /&gt;
# If the persistent auto-login is enabled the AJAX front-end will send a store request. If no error occurs a configured cookie with the relevant type and validity containing the session ID is set to the browser. &lt;br /&gt;
# The AJAX front-end sends initial data request via JSON to the Open-Xchange server and provides the session ID as an URL parameter. The secret is send along as a cookie.&lt;br /&gt;
# The Open-Xchange server processes this data request and compares:&lt;br /&gt;
## Session ID for validity in sessiond&lt;br /&gt;
## Session-Secret from the cookie for validity with session&lt;br /&gt;
# The request is correctly authenticated and is answered by the server.&lt;br /&gt;
# (Optional) Random token is discarded after timeout from sessiond.&lt;br /&gt;
# Repeat 9. - 11. until end of session&lt;br /&gt;
&lt;br /&gt;
If the user does not use the persistent auto-login, the session is only valid as long as the browser is opened. It will be cleared either on logout, on  browser termination or with any occurring error.&lt;br /&gt;
&lt;br /&gt;
For any details on the requests and responses please visit the [https://documentation.open-xchange.com/latest/middleware/http-api-gen/#_login_resource Technical Documentation]&lt;br /&gt;
&lt;br /&gt;
==Access via web browser after authentication with external system==&lt;br /&gt;
The goal is to authenticate in the Open-Xchange system through an external system and to safely pass on the received session data to a browser. To do so the external system has to know the user data (username, password) in plain text. &lt;br /&gt;
&lt;br /&gt;
The process is based on the session initialization in the Open-Xchange Server via the JSON interface and on passing on the received data to a browser. The browser finally initializes the session with an additional random token that is only valid for one single access. &lt;br /&gt;
#	External tool sends initial JSON request directly to Open-Xchange Server&lt;br /&gt;
##	not authenticated yet&lt;br /&gt;
##	no cookie&lt;br /&gt;
##	no SessionID&lt;br /&gt;
#	The Open-Xchange Server authenticates and delivers back following data to external tool via JSON (all the data are stored in the session object in sessiond)&lt;br /&gt;
##	SessionID in JSON object&lt;br /&gt;
##	Random token for initial login via JSON object (required for SSO login)&lt;br /&gt;
##	Cookie with Session-Secret is not set&lt;br /&gt;
#	External tool starts browser with special URL, that contains at least following data:&lt;br /&gt;
##	Random token for initial login&lt;br /&gt;
#	Open-Xchange Server compares:&lt;br /&gt;
##	Random token for validity in sessiond&lt;br /&gt;
#	Open-Xchange Server sends to the browser:&lt;br /&gt;
##	SessionID in JSON object&lt;br /&gt;
##	Cookie with JSESSIONID for loadbalancing is set to the browser&lt;br /&gt;
#	The second part of the tokens is delivered in a separate request&lt;br /&gt;
##	Cookie with Session-Secret is set to the browser If persistent auto-login is selected, the cookie is configured with the relevant type and validity&lt;br /&gt;
#	Open-Xchange removes random token from sessiond.&lt;br /&gt;
&lt;br /&gt;
Then the process continues as described in the section above. The session is then verified with the SessionID and Session-Secret.&lt;br /&gt;
&lt;br /&gt;
==Token Login==&lt;br /&gt;
A dedicated login action (tokenLogin) is used to acquire a server token bound to a given client token. The combination of these tokens allows another client to gain a valid session. This Login is intended to replace the random token login. With this method there is no request or response containing all necessary information to create a valid session.&lt;br /&gt;
&lt;br /&gt;
An example how to use this method to implement an external interactive login page using XHR can be found [[Tokenlogin_form|here]]&lt;br /&gt;
&lt;br /&gt;
==Form Login==&lt;br /&gt;
The Form Login provides a simple way of accessing the web frontend just by using standard HTML forms. The response contains a redirect link to the Web-UI. See [[OXSessionFormLogin]] for details.&lt;br /&gt;
&lt;br /&gt;
==Redeem Token Login==&lt;br /&gt;
With a valid session it is possible to acquire a secret. Using this secret another system is able to generate a valid session.&lt;br /&gt;
This session may also contain the users password (configurable). The system in question needs to be registered at the server and has to identify itself with a key configured at the open-xchange server. This is only for internal communication and by default no keys are available.&lt;br /&gt;
&lt;br /&gt;
== Authentication against other services ==&lt;br /&gt;
OX6 and AppSuite allow authentication using other services, too. This is not in the scope of this article. The Services team is available to build plugins for such services. Some standard ones are already implemented, see the following articles for that:&lt;br /&gt;
* [[Authentication IMAP Plugin description]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For further information on the session see [[OXSessionLifecycle]].&lt;br /&gt;
&lt;br /&gt;
For further information on HTTP API visit the [https://documentation.open-xchange.com/latest/middleware/http-api-gen/#_login_resource Technical Documentation]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Server]]&lt;br /&gt;
[[Category:OX6]]&lt;br /&gt;
[[Category:AppSuite]]&lt;br /&gt;
[[Category:Auth]]&lt;/div&gt;</summary>
		<author><name>WolfgangRosenauer</name></author>
	</entry>
</feed>