@mahescho ok, but even if what is logged does not look like an error to you if may provide additional insights here. Or does nothing get logged at all? Since this happens in a web browser there may also be additional hints in the browser console.
Coming back to z-push-admin do these additionally selected folders show there? Can additional folders be added through z-push-admin?
Maybe it would make sense to follow this up with the Kopano support directly, so that someone could have a look at the system directly?
I don’t have a support subscription so that won’t help.
All that was left was to start from scratch so I purged any z-push package from my server and installed z-push again.
And to my big surprise Outlook started to sync without any state errors and completed the full sync after some time.
So, cause unknown but issue resolved.
I want to configure certificate based authentication for z-push so that only devices with a client certificate from our ca are able to synchronize via activesync.
I tried to set the following option with the ca from a Univention server, but can still synchronize without setting a client certificate.
// When using client certificates, we can check if the login sent matches the owner of the certificate.
// This setting specifies the owner parameter in the certificate to look at.
In Z-Push client certificate is optional for authentication. That means that the users without a certificate will be able to login using the correct username and password. If you want to allow only users with certificates, you’ll have to do some code changes.
And if I’m setting a client certificate the client cannot setup the account (I cant see any errors in the z-push logs).
Am I missing a configuration or am I making another misconfiguration?
It’s difficult to say anything without Z-Push/webserver logs. Is the auth user the same as SSL_CLIENT_S_DN_CN value?
Good to know there is a 20.04 repo available now. While updating the repo link from 18.04 to 20.04 I also noticed that the old URL I was using was http and not https - another welcome change I had not adopted.
if your users login using their full email address and not just the username, then you have to set
thats the solution, i already find out
the question is, why is the same variable in two configs?
because autodiscover and Z-Push are two different components which might be installed on different systems or you might want to have different settings, so it doesn’t make sense to have the same config for both.
The autodiscover of Outlook 2016 worked with Z-Push until recently. Since a few days we observe that the autodiscover of Outlook 2016 writes the same errors in the autodiscover.log as Outlook 2019. Is there any information that Microsoft has changed the autodiscover of Outlook 2016 in the last days with a patch?
z-push-common has a dependency on php-soap package without specifying its version. As you already had php7.0-soap installed, it was good enough for Z-Push. As you were trying to remove it without installing a newer php-soap version first, Z-Push would be removed as well.
Also, this wouldn’t have happened if the php7.0* packages were upgraded to php7.3* packages during the OS upgrade, so that’s the issue you have to look at.