email samples are sent to esvalabs.com to improve deliverability
faster mail queues length calculation on dashboard
Bug fixes
avoid CPU high utilization when reading messages in active queue
avoid memory exausted when generating Spam rules hit reports on large dataset
add backward compatibility with encrypted links generated by ESG 4.x
mail queue logger can handle remote server messages up to 8192 chars
Changes in v5.0.7 (Nov 02, 2021)
Improvements
Syslog: configuration isn’t replicated in cluster setup
Microsoft365/GSuite: faster import of users (at least 2x)
Allow readonly access to relay and user page when the license is expired
Whitelabelling: rollback to previous theme, should the generation fail
Allow cluster destroy should the license expires
Bug fixes
IMAP/POP3: prevent a 500 error on user login
Import 4.9: cleanup old configuration to avoid clamav engine failures
Whitelabelling: don’t reset theme on updates
Release requests: allow empty notification email
Release requests: remove loading browsere popup on successful release
Digest Report: fix selection of options in bulk actions
User preference: read default values for new user when creating on login
Email continuity: use new security policy system to validate user from addresses
ATE: prevent errors when from header is not set in a message
Changes in v5.0.6 (Nov 09, 2021)
Security
Hardened configuration for SSH daemon
Improvements
Chrony: if the offset is above 30 minutes, just set the current time
Check for update after network first configuration
Cluster: better status monitor for file replica
automatically reload mail scanner engine after configuration changes
added confirm modal for shutdown/reboot/suspend cluster actions
Bugfix
First run: wait for database initialization before scheduling reboot
Console: reset fallback address in issue file on first boot
restore release requests functionality
cluster setup: fixed file synchronization of TLS keys
compile smtp check override after migration from 4.9
When creating users inherit all configured default
Fix signature saving error on some configuration
Fix widget for color selection in system preferences
Restored SNMP OID for SMTP traffic
Remove errors on whitelist and blacklist insertions for users with multiple addresses in recipients
Remove errors on whitelist and blacklist insertions for safe-learn users
LDAP set of type other are correctly identified as such
prevent a page error when decrypting links generated by ESG 4.9
Changes in v5.0.5 (Oct 19, 2021)
Security
Abuser lockout: implement incremental lockout for recidive abuser
Adaptive Trust Engine: support BATV address and domain with more than 4 levels
Adaptive Trust Engine: separated history age for different relays
DKIM key: upgrade to 2048 bit
DNS: prevent DoS on SERVFAIL by adding a short term cache
Webapp: force HTTPS with TLS > 1.2
Mail transport agent: disable TLS 1.0 and 1.1 on strict/medium TLS mode
RBL: don’t disclose RBL name on rejection
User Manager: all domain admins are now multi domain admins (no longer restrict the username format)
User Manager: increase password security for Users, by using high-end caching algorithm for user passwords.
Improvements
AntiSpam settings: defaults for new users are explicitly configured and no longer inherited from the domain admin’s configurations
Appliance Sizing: automatic configuration of all resource-intensive services
Backup and Restore: new data importer from ESG 4
Backup and Restore: FTP backup supports TLS
Branding: new Libraesva logo and hypervisor themes
Cluster Setup: simplified setup wizard
Cluster: simplified monitoring and recovery UI
Console: add full ANSI-color support to hypervisor console
Console: interactive console with dynamic data
Crash auto-recovery: auto-repair services for most disk crash situation
DKIM: disabled signature for empty envelope from
Dashboard Threat Map: high level threat distribution like phishing, spoofing and whaling
Details page: quick summary for rejected email
Details page: threat or indicators identified by the internal engines
Disk expansion: support for 60 disk expansions
Licensing: new licensing system
MailIntercept: new dedicated configuration page
Machine Learning: new page with statistical records of CRM114 machine learning engine
Machine Learning: new page with statistical records of Bayes machine learning engine
Message Actions: all actions can be executed from all message views
Message details: add DSN and description to all SMTP reject listing, to distinguish temporary from permanent failures
Message details: new analytical representation of email path
Message details: new delivery status badges, which includes all statuses (e.g. recalled, released, …)
NTP: system clock synchronizations is always enabled and synchronized
Network: refactored network management with multiple interface and route configurations
Phishing Highlight: removed some options which are now managed directly by the ESG security team
Quarantine list: show scan results and delivery status
Quarantine settings: explicit configuration of default settings for new users (no longer inherit domain admin configuration)
Reboot/Shutdown: prompt feedback of the progress of the reboot
SASL: automatic realm initialization and asynchronous configuration
Sandboxes: URLSand and Quicksand configurations are on distinct pages
Scan result: Dictionary and DNSBL reporting has been improved
Scan result: new “Archive Encrypted” scan result
Scan result: new “QuickSand URI Disarmed” scan result
Scan result: “OFF” messages (not scanned because of exception rules) are displayed in message lists
Search page: searches with advanced filters can be saved to be used with report pages
Search page: can now search also among rejected messages
Social graph: refined interface and interactions
System preferences: increased the default value of records displayed in message lists
System preferences: new color palettes and new color picker
System resource: new dedicated page, with detailed resource statistics
TLS Certificates: TLS certificate can be shared in a cluster setup
White-labelling: logo automatic scaling from many raster formats
Wizard: brand new first-run wizard, with configuration loader from ESG 4.9
VM hardware improvements
Use EFI in all hypervisors which support it
Add Secure boot and security options in VMware 6.7+
Add IOMMU in VMware 6.7+
Use GPT partitioning which allows up to 60 disk expansions
Support for in-place operating system migration
Fully automated build-chain for many target hypervisors. Supported vSphere 6.0-6.5,
vSphere 6.7+, Proxmox KVM, Hyper-V, Xen
Bug fixes
User Manager: Read-Only administrator can modify their own profile
Mail transport agent: default email max size lowered to 25 MB, to avoid delivery issues to M365 and GSuite
Licensing: atomically switch license without services restart
Breaking Changes
License file: license file for ESG 4.x isn’t valid on ESG 5.x. You should have received the updated license from your channel, if you haven’t please contact us.
Scheduled reports: not migrated from ESG 4.9, must be recreated manually
Quarantine link: links generated from ESG 4.9 are no longer valid. Messages can be released from WebUI after migration process for history and quarantine is completed.
Legacy end-user API (URL /esva-api/myemail.php) (new user API for mobile applications to be used instead. URL: /api/v1)
Administrative API (URL /esva-api/) for system configuration (available from ESG 5.1. URL: /api/v2)
Distributed setup: not available, will be released in a future release.