/**
* SquirrelMail configtest script
*
- * Copyright (c) 2003-2005 The SquirrelMail Project Team
- * Licensed under the GNU GPL. For full terms see the file COPYING.
- *
+ * @copyright © 2003-2006 The SquirrelMail Project Team
+ * @license http://opensource.org/licenses/gpl-license.php GNU Public License
* @version $Id$
* @package squirrelmail
* @subpackage config
/** @ignore */
define('SM_PATH', '../');
+/* set default value in order to block remote access to script */
+$allow_remote_configtest=false;
+
/*
* Load config before output begins. functions/strings.php depends on
* functions/globals.php. functions/global.php needs to be run before
include(SM_PATH . 'config/config.php');
include(SM_PATH . 'functions/strings.php');
}
-?><!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
+?><!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
+ "http://www.w3.org/TR/1999/REC-html401-19991224/loose.dtd">
<html>
<head>
+ <meta name="robots" content="noindex,nofollow">
<title>SquirrelMail configtest</title>
</head>
<body>
<?php
-
$included = array_map('basename', get_included_files() );
if(!in_array('config.php', $included)) {
if(!file_exists(SM_PATH . 'config/config.php')) {
'Check permissions on that file.');
}
+/* Block remote use of script */
+if (! $allow_remote_configtest) {
+ sqGetGlobalVar('REMOTE_ADDR',$client_ip,SQ_SERVER);
+ sqGetGlobalVar('SERVER_ADDR',$server_ip,SQ_SERVER);
+
+ if ((! isset($client_ip) || $client_ip!='127.0.0.1') &&
+ (! isset($client_ip) || ! isset($server_ip) || $client_ip!=$server_ip)) {
+ do_err('Enable "Allow remote configtest" option in squirrelmail configuration in order to use this script.');
+ }
+}
/* checking PHP specs */
echo "<p><table>\n<tr><td>SquirrelMail version:</td><td><b>" . $version . "</b></td></tr>\n" .
date ('d F Y H:i:s', filemtime(SM_PATH . 'config/config.php')) .
"</b></td></tr>\n</table>\n</p>\n\n";
+/* check $config_version */
+if ($config_version!='1.4.0') {
+ do_err('Configuration file version does not match required version. Please update your configuration file.');
+}
+
echo "Checking PHP configuration...<br />\n";
if(!check_php_version(4,1,0)) {
/**
* mbstring.func_overload allows to replace original string and regexp functions
* with their equivalents from php mbstring extension. It causes problems when
- * scripts analyse 8bit strings byte after byte or use 8bit strings in regexp tests.
+ * scripts analyze 8bit strings byte after byte or use 8bit strings in regexp tests.
* Setting can be controlled in php.ini (php 4.2.0), webserver config (php 4.2.0)
* and .htaccess files (php 4.3.5).
*/
echo "Checking paths...<br />\n";
if(!file_exists($data_dir)) {
- do_err("Data dir ($data_dir) does not exist!");
-}
-if(!is_dir($data_dir)) {
- do_err("Data dir ($data_dir) is not a directory!");
+ // data_dir is not that important in db_setups.
+ if (isset($prefs_dsn) && ! empty($prefs_dsn)) {
+ $data_dir_error = "Data dir ($data_dir) does not exist!\n";
+ echo $IND .'<font color="red"><b>ERROR:</b></font> ' . $data_dir_error;
+ } else {
+ do_err("Data dir ($data_dir) does not exist!");
+ }
}
-if(!is_readable($data_dir)) {
- do_err("I cannot read from data dir ($data_dir)!");
+// don't check if errors
+if(!isset($data_dir_error) && !is_dir($data_dir)) {
+ if (isset($prefs_dsn) && ! empty($prefs_dsn)) {
+ $data_dir_error = "Data dir ($data_dir) is not a directory!\n";
+ echo $IND . '<font color="red"><b>ERROR:</b></font> ' . $data_dir_error;
+ } else {
+ do_err("Data dir ($data_dir) is not a directory!");
+ }
}
-if(!is_writable($data_dir)) {
- do_err("I cannot write to data dir ($data_dir)!");
+// datadir should be executable - but no clean way to test on that
+if(!isset($data_dir_error) && !is_writable($data_dir)) {
+ if (isset($prefs_dsn) && ! empty($prefs_dsn)) {
+ $data_dir_error = "Data dir ($data_dir) is not writable!\n";
+ echo $IND . '<font color="red"><b>ERROR:</b></font> ' . $data_dir_error;
+ } else {
+ do_err("Data dir ($data_dir) is not writable!");
+ }
}
-// todo_ornot: actually write something and read it back.
-echo $IND . "Data dir OK.<br />\n";
-
+if (isset($data_dir_error)) {
+ echo " Some plugins might need access to data directory.<br />\n";
+} else {
+ // todo_ornot: actually write something and read it back.
+ echo $IND . "Data dir OK.<br />\n";
+}
if($data_dir == $attachment_dir) {
echo $IND . "Attachment dir is the same as data dir.<br />\n";
+ if (isset($data_dir_error)) {
+ do_err($data_dir_error);
+ }
} else {
if(!file_exists($attachment_dir)) {
do_err("Attachment dir ($attachment_dir) does not exist!");
if ( $squirrelmail_default_language != 'en_US' ) {
$loc_path = SM_PATH .'locale/'.$squirrelmail_default_language.'/LC_MESSAGES/squirrelmail.mo';
if( ! file_exists( $loc_path ) ) {
- do_err('You have set <i>' . $squirrelmail_default_language .
+ do_err('You have set <i>' . $squirrelmail_default_language .
'</i> as your default language, but I cannot find this translation (should be '.
'in <tt>' . $loc_path . '</tt>). Please note that you have to download translations '.
'separately from the main SquirrelMail package.', FALSE);
} elseif ( ! is_readable( $loc_path ) ) {
- do_err('You have set <i>' . $squirrelmail_default_language .
+ do_err('You have set <i>' . $squirrelmail_default_language .
'</i> as your default language, but I cannot read this translation (file '.
'in <tt>' . $loc_path . '</tt> unreadable).', FALSE);
} else {
echo $IND . "Base URL detected as: <tt>" . htmlspecialchars(get_location()) . "</tt><br />\n";
+/* check minimal requirements for other security options */
-/* check outgoing mail */
-
-if($use_smtp_tls || $use_imap_tls) {
+/* imaps or ssmtp */
+if($use_smtp_tls == 1 || $use_imap_tls == 1) {
if(!check_php_version(4,3,0)) {
do_err('You need at least PHP 4.3.0 for SMTP/IMAP TLS!');
}
do_err('You need the openssl PHP extension to use SMTP/IMAP TLS!');
}
}
+/* starttls extensions */
+if($use_smtp_tls == 2 || $use_imap_tls == 2) {
+ if (! function_exists('stream_socket_enable_crypto')) {
+ do_err('If you want to use STARTTLS extension, you need stream_socket_enable_crypto() function from PHP 5.1.0 and newer.');
+ }
+}
+/* digest-md5 */
+if ($smtp_auth_mech=='digest-md5' || $imap_auth_mech =='digest-md5') {
+ if (!extension_loaded('xml')) {
+ do_err('You need the PHP XML extension to use Digest-MD5 authentication!');
+ }
+}
+
+/* check outgoing mail */
echo "Checking outgoing mail service....<br />\n";
echo $IND . "sendmail OK<br />\n";
} else {
- $stream = fsockopen( ($use_smtp_tls?'tls://':'').$smtpServerAddress, $smtpPort,
+ $stream = fsockopen( ($use_smtp_tls==1?'tls://':'').$smtpServerAddress, $smtpPort,
$errorNumber, $errorString);
if(!$stream) {
do_err("Error connecting to SMTP server \"$smtpServerAddress:$smtpPort\".".
htmlspecialchars($smtpline));
}
+ /* smtp starttls checks */
+ if ($use_smtp_tls==2) {
+ // if something breaks, script should close smtp connection on exit.
+
+ // say helo
+ fwrite($stream,"EHLO $client_ip\r\n");
+
+ $ehlo=array();
+ $ehlo_error = false;
+ while ($line=fgets($stream, 1024)){
+ if (preg_match("/^250(-|\s)(\S*)\s+(\S.*)/",$line,$match)||
+ preg_match("/^250(-|\s)(\S*)\s+/",$line,$match)) {
+ if (!isset($match[3])) {
+ // simple one word extension
+ $ehlo[strtoupper($match[2])]='';
+ } else {
+ // ehlo-keyword + ehlo-param
+ $ehlo[strtoupper($match[2])]=trim($match[3]);
+ }
+ if ($match[1]==' ') {
+ $ret = $line;
+ break;
+ }
+ } else {
+ //
+ $ehlo_error = true;
+ $ehlo[]=$line;
+ break;
+ }
+ }
+ if ($ehlo_error) {
+ do_err('SMTP EHLO failed. You need ESMTP support for SMTP STARTTLS');
+ } elseif (!array_key_exists('STARTTLS',$ehlo)) {
+ do_err('STARTTLS support is not declared by SMTP server.');
+ }
+
+ fwrite($stream,"STARTTLS\r\n");
+ $starttls_response=fgets($stream, 1024);
+ if ($starttls_response[0]!=2) {
+ $starttls_cmd_err = 'SMTP STARTTLS failed. Server replied: '
+ .htmlspecialchars($starttls_response);
+ do_err($starttls_cmd_err);
+ } elseif(! stream_socket_enable_crypto($stream,true,STREAM_CRYPTO_METHOD_TLS_CLIENT)) {
+ do_err('Failed to enable encryption on SMTP STARTTLS connection.');
+ } else {
+ echo $IND . "SMTP STARTTLS extension looks OK.<br />\n";
+ }
+ // According to RFC we should second ehlo call here.
+ }
+
fputs($stream, 'QUIT');
fclose($stream);
echo $IND . 'SMTP server OK (<tt><small>'.
echo "Checking IMAP service....<br />\n";
/** Can we open a connection? */
-$stream = fsockopen( ($use_imap_tls?'tls://':'').$imapServerAddress, $imapPort,
+$stream = fsockopen( ($use_imap_tls==1?'tls://':'').$imapServerAddress, $imapPort,
$errorNumber, $errorString);
if(!$stream) {
do_err("Error connecting to IMAP server \"$imapServerAddress:$imapPort\".".
/** Check capabilities */
fputs($stream, "A001 CAPABILITY\r\n");
-$capline = fgets($stream, 1024);
+$capline = '';
+while ($line=fgets($stream, 1024)){
+ if (preg_match("/A001.*/",$line)) {
+ break;
+ } else {
+ $capline.=$line;
+ }
+}
+
+/* don't display capabilities before STARTTLS */
+if ($use_imap_tls==2 && stristr($capline, 'STARTTLS') === false) {
+ do_err('Your server doesn\'t support STARTTLS.');
+} elseif($use_imap_tls==2) {
+ /* try starting starttls */
+ fwrite($stream,"A002 STARTTLS\r\n");
+ $starttls_line=fgets($stream, 1024);
+ if (! preg_match("/^A002 OK.*/i",$starttls_line)) {
+ $imap_starttls_err = 'IMAP STARTTLS failed. Server replied: '
+ .htmlspecialchars($starttls_line);
+ do_err($imap_starttls_err);
+ } elseif (! stream_socket_enable_crypto($stream,true,STREAM_CRYPTO_METHOD_TLS_CLIENT)) {
+ do_err('Failed to enable encryption on IMAP connection.');
+ } else {
+ echo $IND . "IMAP STARTTLS extension looks OK.<br />\n";
+ }
+
+ // get new capability line
+ fwrite($stream,"A003 CAPABILITY\r\n");
+ $capline='';
+ while ($line=fgets($stream, 1024)){
+ if (preg_match("/A003.*/",$line)) {
+ break;
+ } else {
+ $capline.=$line;
+ }
+ }
+}
echo $IND . 'Capabilities: <tt>'.htmlspecialchars($capline)."</tt><br />\n";
'Try enabling another authentication mechanism like CRAM-MD5, DIGEST-MD5 or TLS-encryption '.
'in the SquirrelMail configuration.', FALSE);
}
-if($use_imap_tls && stristr($capline, 'STARTTLS') === FALSE) {
- do_err('You have enabled TLS encryption in the config, but the server does not '.
- 'report STARTTLS capability. TLS is probably not supported.', FALSE);
-}
/** OK, close connection */
-fputs($stream, "A002 LOGOUT\r\n");
+fputs($stream, "A004 LOGOUT\r\n");
fclose($stream);
echo "Checking internationalization (i18n) settings...<br />\n";
echo "$IND recode - ";
if (function_exists('recode')) {
echo "Recode functions are available.<br />\n";
-} elseif ($use_php_recode) {
+} elseif (isset($use_php_recode) && $use_php_recode) {
echo "Recode functions are unavailable.<br />\n";
do_err('Your configuration requires recode support, but recode support is missing.');
} else {
echo "$IND iconv - ";
if (function_exists('iconv')) {
echo "Iconv functions are available.<br />\n";
-} elseif ($use_php_iconv) {
+} elseif (isset($use_php_iconv) && $use_php_iconv) {
echo "Iconv functions are unavailable.<br />\n";
do_err('Your configuration requires iconv support, but iconv support is missing.');
} else {
'mysqli' => 'mysqli_connect',
'oci8' => 'ocilogon',
'odbc' => 'odbc_connect',
- 'pgsql' => 'pgsql_connect',
+ 'pgsql' => 'pg_connect',
'sqlite' => 'sqlite_open',
'sybase' => 'sybase_connect'
);
}
foreach($dsns as $type => $dsn) {
- $dbtype = array_shift(explode(':', $dsn));
+ $aDsn = explode(':', $dsn);
+ $dbtype = array_shift($aDsn);
if(isset($db_functions[$dbtype]) && function_exists($db_functions[$dbtype])) {
echo "$IND$dbtype database support present.<br />\n";
echo "$IND$type database connect successful.<br />\n";
} else {
- do_err($db.' database support not present!');
+ do_err($dbtype.' database support not present!');
}
}
} else {
if( empty($ldap_server) ) {
echo $IND."not using LDAP functionality.<br />\n";
} else {
- if ( !function_exists(ldap_connect) ) {
+ if ( !function_exists('ldap_connect') ) {
do_err('Required LDAP support is not available.');
} else {
echo "$IND LDAP support present.<br />\n";
foreach ( $ldap_server as $param ) {
- $linkid = ldap_connect($param['host'], (empty($param['port']) ? 389 : $param['port']) );
+ $linkid = @ldap_connect($param['host'], (empty($param['port']) ? 389 : $param['port']) );
if ( $linkid ) {
echo "$IND LDAP connect to ".$param['host']." successful: ".$linkid."<br />\n";
}
if ( empty($param['binddn']) ) {
- $bind = ldap_bind($linkid);
+ $bind = @ldap_bind($linkid);
} else {
- $bind = ldap_bind($param['binddn'], $param['bindpw']);
+ $bind = @ldap_bind($param['binddn'], $param['bindpw']);
}
if ( $bind ) {
do_err('Unable to Bind to LDAP Server');
}
- ldap_close($linkid);
+ @ldap_close($linkid);
} else {
do_err('Connection to LDAP failed');
}
}
}
}
+
?>
<p>Congratulations, your SquirrelMail setup looks fine to me!</p>
<p><a href="login.php">Login now</a></p>
</body>
-</html>
-<?php
-// vim: et ts=4
-?>
+</html>
\ No newline at end of file