Skip to content

From Zimbra

Read Coming from another server first. This page covers what is particular to Zimbra.

Zimbra keeps more than mail in each mailbox: calendars, contacts, tasks and Briefcase files. IMAP carries only the mail, so the rest comes across as exported files.

Who people are

Check how the domain authenticates:

zmprov gd example.com zimbraAuthMech

ad: Active Directory

Choice A. Use the Active Directory settings, pointed at the same domain controllers Zimbra uses (zimbraAuthLdapURL on the domain).

zimbra or empty: Zimbra's own LDAP

The accounts and their password hashes are in Zimbra's OpenLDAP, which goes away with Zimbra, so this is choice B. Zimbra stores {SSHA512} hashes, or {SSHA} on older installs. Both are read.

The connection details, on the Zimbra server:

zmlocalconfig ldap_url
zmlocalconfig -s zimbra_ldap_userdn zimbra_ldap_password

Zimbra's LDAP normally accepts connections only from Zimbra's own servers. Allow the inbuxa host through the firewall for the length of the migration.

Field Value
Server URL from ldap_url
Bind DN, Bind Secret zimbra_ldap_userdn, zimbra_ldap_password
Base DN the domain's people branch, such as ou=people,dc=example,dc=com
Use Bind Authentication Off
Login Filter (&(objectClass=zimbraAccount)(zimbraMailDeliveryAddress=?)(zimbraAccountStatus=active))
Mailbox Filter (&(objectClass=zimbraAccount)(|(zimbraMailDeliveryAddress=?)(zimbraMailAlias=?))(zimbraAccountStatus=active))
Primary E-mail Attribute zimbraMailDeliveryAddress
E-mail Alias Attribute zimbraMailAlias
Password Attribute userPassword
Description Attribute displayName
Member Of Filter, Member Of Attribute empty

Check the filters with ldapsearch against one account before you save them. Zimbra's system accounts (the spam and ham training accounts, virus quarantine, GAL sync) match zimbraAccount too. They have no business in inbuxa, so don't copy them. Nothing creates them unless they are copied or receive mail.

Distribution lists become mailing lists in inbuxa. To list them and their members:

zmprov gadl
zmprov gdlm [email protected]

Copying the mail

Zimbra lets an administrator sign in to IMAP on someone's behalf. imapsync signs in as the person with the administrator's credentials, and imapsync's Zimbra notes cover the details for your version:

imapsync \
  --host1 zimbra.example.com --ssl1 \
  --user1 '[email protected]' \
  --authuser1 '[email protected]' --password1 "$ZIMBRA_ADMIN_PASSWORD" \
  --host2 mail.example.net --ssl2 \
  --user2 '[email protected]%[email protected]' \
  --password2 "$MIGRATOR_PASSWORD" \
  --automap

zmprov -l gaa example.com lists the domain's accounts.

Two things to watch:

  • Shared folders. A folder someone else shared can show up in the person's IMAP folder list. Copying it copies the owner's mail into their mailbox as well. Leave those folders out with --exclude.
  • Tags. Zimbra's tags aren't IMAP folders or standard flags, and may not come across.

Calendars and contacts

Zimbra exports each folder over its REST interface. As an administrator, on the Zimbra server:

zmmailbox -z -m [email protected] getRestURL '/Calendar?fmt=ics' > alice-calendar.ics
zmmailbox -z -m [email protected] getRestURL '/Contacts?fmt=vcf' > alice-contacts.vcf

Each calendar and address book is a folder of its own; use its name in place of Calendar or Contacts. People can also export their own from the Zimbra web client.

Each person then imports the files in the webmail. See importing a calendar and importing contacts.

Briefcase files download the same way (/Briefcase?fmt=zip) and go into inbuxa's Files. Tasks don't have a place to go yet.

Filters

Zimbra keeps each person's filters as a Sieve script on their account:

zmprov ga [email protected] zimbraMailSieveScript

Scripts that stick to standard Sieve upload as they are. Zimbra adds its own extensions for tags and flags, and a script that uses them won't compile. Rebuild those rules in the webmail's filter editor. Out-of-office is set again by the person.