From Zimbra¶
Read Coming from another server first. This page covers what is particular to Zimbra.
Zimbra keeps more than mail in each mailbox: calendars, contacts, tasks and Briefcase files. IMAP carries only the mail, so the rest comes across as exported files.
Who people are¶
Check how the domain authenticates:
ad: Active Directory¶
Choice A. Use the Active Directory settings,
pointed at the same domain controllers Zimbra uses (zimbraAuthLdapURL on
the domain).
zimbra or empty: Zimbra's own LDAP¶
The accounts and their password hashes are in Zimbra's OpenLDAP, which goes
away with Zimbra, so this is choice B. Zimbra
stores {SSHA512} hashes, or {SSHA} on older installs. Both are read.
The connection details, on the Zimbra server:
Zimbra's LDAP normally accepts connections only from Zimbra's own servers. Allow the inbuxa host through the firewall for the length of the migration.
| Field | Value |
|---|---|
| Server URL | from ldap_url |
| Bind DN, Bind Secret | zimbra_ldap_userdn, zimbra_ldap_password |
| Base DN | the domain's people branch, such as ou=people,dc=example,dc=com |
| Use Bind Authentication | Off |
| Login Filter | (&(objectClass=zimbraAccount)(zimbraMailDeliveryAddress=?)(zimbraAccountStatus=active)) |
| Mailbox Filter | (&(objectClass=zimbraAccount)(|(zimbraMailDeliveryAddress=?)(zimbraMailAlias=?))(zimbraAccountStatus=active)) |
| Primary E-mail Attribute | zimbraMailDeliveryAddress |
| E-mail Alias Attribute | zimbraMailAlias |
| Password Attribute | userPassword |
| Description Attribute | displayName |
| Member Of Filter, Member Of Attribute | empty |
Check the filters with ldapsearch against one account before you save
them. Zimbra's system accounts (the spam and ham training accounts, virus
quarantine, GAL sync) match zimbraAccount too. They have no business in
inbuxa, so don't copy them. Nothing creates them unless they are copied
or receive mail.
Distribution lists become mailing lists in inbuxa. To list them and their members:
zmprov gadl
zmprov gdlm [email protected]
Copying the mail¶
Zimbra lets an administrator sign in to IMAP on someone's behalf. imapsync signs in as the person with the administrator's credentials, and imapsync's Zimbra notes cover the details for your version:
imapsync \
--host1 zimbra.example.com --ssl1 \
--user1 '[email protected]' \
--authuser1 '[email protected]' --password1 "$ZIMBRA_ADMIN_PASSWORD" \
--host2 mail.example.net --ssl2 \
--user2 '[email protected]%[email protected]' \
--password2 "$MIGRATOR_PASSWORD" \
--automap
zmprov -l gaa example.com lists the domain's accounts.
Two things to watch:
- Shared folders. A folder someone else shared can show up in the
person's IMAP folder list. Copying it copies the owner's mail into their
mailbox as well. Leave those folders out with
--exclude. - Tags. Zimbra's tags aren't IMAP folders or standard flags, and may not come across.
Calendars and contacts¶
Zimbra exports each folder over its REST interface. As an administrator, on the Zimbra server:
zmmailbox -z -m [email protected] getRestURL '/Calendar?fmt=ics' > alice-calendar.ics
zmmailbox -z -m [email protected] getRestURL '/Contacts?fmt=vcf' > alice-contacts.vcf
Each calendar and address book is a folder of its own; use its name in
place of Calendar or Contacts. People can also export their own from the
Zimbra web client.
Each person then imports the files in the webmail. See importing a calendar and importing contacts.
Briefcase files download the same way (/Briefcase?fmt=zip) and go into
inbuxa's Files. Tasks don't have a place to go yet.
Filters¶
Zimbra keeps each person's filters as a Sieve script on their account:
zmprov ga [email protected] zimbraMailSieveScript
Scripts that stick to standard Sieve upload as they are. Zimbra adds its own extensions for tags and flags, and a script that uses them won't compile. Rebuild those rules in the webmail's filter editor. Out-of-office is set again by the person.