[oxhe-announce] Open-Xchange releases OX Abuse Shield v2.8.0

Open-Xchange Hosting Edition Maintenance Announcements oxhe-announce at open-xchange.com
Mon Dec 19 12:42:09 CET 2022


Dear Open-Xchange Customers and Partners,

Open-Xchange is pleased to announce the release of OX Abuse Shield v2.8.0.

OX Abuse Shield provides abuse-prevention for Web Applications (including Webmail), POP, and IMAP. It is integrated with both OX App Suite and OX Dovecot Pro to prevent login and authentication abuse as well as protecting against brute-force attacks.

The goal of OX Abuse Shield is to detect brute forcing of passwords across many servers, services and instances, as well as enforce policy for authentication and authorization. In order to support the real world, brute force detection policy can be tailored to deal with "bulk, but legitimate" users of your service, as well as botnet-wide slow-scans of passwords.

The new OX Abuse Shield v2.8.0 provides the following main improvements:
- Support ELK 7.x Stack
- Support Date Expansion in WebHook URLs
- Enable IP and Login substitution in blocklist return messages
- Add config option to disable password for /metrics endpoint
- Support redis usernames and passwords for redis authentication
- Support hostnames for redis configuration in addition to IP addresses

The new OX Abuse Shield v2.8.0 provides the following fixes:
- Fix an issue where IPv6 ComboAddress returned zero port number (which caused v6 HTTP
listen addresses to not work)
- Return the IP address of the client in JSON of ACL denied response

The new wforce-policy v2.8.0 provides the following main improvements and new features:
- Add redis authentication support to wforce policy
- Docker image for wforce policy, based on wforce docker image

General Information – Please Note

- Open-Xchange encourages administrators to regularly update to the latest available release. To ensure a stable and up to date environment please note the different versions supported. An overview of the latest supported Major, Minor and Public Patch Releases can be found in the OXpedia at: https://oxpedia.org/wiki/index.php?title=OXAbuseShield:Version_Support_Commitment

Shipped packages and versions

- wforce v2.8.0
- wforce-policy v2.8.0
- replfwd v2.8.0

Complete Release Notes 

- OX Abuse Shield:
https://software.open-xchange.com/products/abuseshield/doc/OX_Abuse_Shield_Release_Notes_for_Release_2.8.0_2022-12-19.pdf

Download and Installation

For further details about OX Abuse Shield installation and configuration, mandatory and optional packages, policies, please refer to the documentation provided: https://oxpedia.org/wiki/index.php?title=AppSuite:OX_Abuse_Shield

Best regards,
Your Open-Xchange Team

-------------------------------------------------------------------------------------
Open-Xchange AG, Hohenzollernring 72, 50672 Cologne, District Court Cologne HRB 95366
Managing Board: Andreas Gauger, Dirk Valbert, Frank Hoberg, Stephan Martin
Chairman of the Board: Richard Seibt

European Office:
Open-Xchange GmbH, Olper Huette 5f, D-57462 Olpe, Germany, District Court Siegen, HRB 8718
Managing Director: Manuel Engel

US Office:
Open-Xchange. Inc., 530 Lytton Avenue, Palo Alto, CA 94301, USA
-------------------------------------------------------------------------------------


More information about the oxhe-announce mailing list