Practical Guide to Access Zimbra from the CHU of Reims Remotely and Securely

Zimbra is the webmail client deployed at the CHU of Reims for all hospital staff. Accessing this email from a workstation located outside the internal network of the establishment requires compliance with several technical and security requirements, especially since two-factor authentication is becoming widespread in French public health structures.

Recent Zimbra Vulnerabilities and Consequences for Remote Access

Before discussing configuration, one point deserves the attention of any agent connecting from home: the attack surface of Zimbra has been actively exploited in recent months. Patches were released in November 2025 for versions 10.1.13 and 10.0.18, and an upgrade to version 10.1.20 or higher was recommended to fix a remote code execution vulnerability related to the zimbra-snmp package.

The NSA has also reported a phishing campaign supported by a state actor, specifically targeting Zimbra users since July 2025. For an agent at the CHU, this means that every unsecured external connection poses a real, not theoretical, risk.

These alerts explain why healthcare institutions are tightening their remote access conditions. A guide detailing the access to Zimbra from the CHU of Reims from outside allows verification that the procedure followed remains compliant with current recommendations.

Two-Factor Authentication for Hospital Email: What’s Changing

Several French public institutions, including AP-HP and HCL, have made a second authentication factor mandatory for any access to email from outside the network. This trend, confirmed between 2025 and 2026, goes beyond the simple username/password pair still described in the majority of online tutorials.

The principle relies on a temporary code (OTP) generated by an authentication app installed on the agent’s smartphone. After entering their username and password on the Zimbra login page, the user must enter this one-time code before accessing their inbox.

Administrative employee accessing the Zimbra email of the CHU of Reims remotely via a secure VPN

The CNIL is explicitly cited as a regulatory reference to justify this two-factor authentication in the context of hospital teleworking. An agent attempting to bypass this mechanism (by using an old direct login link, for example) would face a systematic block.

Preparing Your Smartphone for the Second Factor

The authentication app must be installed and configured before the first attempt at remote connection. Waiting to be at home on a Sunday evening to discover this step guarantees unnecessary frustration.

  • Install a compatible app (the IT service of the CHU specifies which one) on a personal or professional phone
  • Scan the QR code provided during enrollment, usually done on-site in the IT department
  • Ensure that the phone’s clock is synchronized automatically, as a delay of a few minutes invalidates the OTP codes
  • Keep the backup codes provided during activation in a location separate from the phone itself

IMAP and ActiveSync Configuration on a Personal Device

The Zimbra webmail accessible via browser covers most use cases. For those who prefer a native email client (Outlook, Thunderbird, the Mail app on iOS), two protocols come into play: IMAP and ActiveSync.

IMAP synchronizes emails between the server and the client. ActiveSync goes further by also synchronizing the calendar, contacts, and tasks. The choice depends on the need: an agent who only checks their emails can suffice with IMAP. Someone managing their duty schedule from their phone would benefit from configuring ActiveSync.

Server Settings to Provide

The login credentials are the same as for webmail. The incoming mail server corresponds to the address of the CHU’s Zimbra server (provided by the IT department). The secure IMAP port uses SSL/TLS encryption, and the outgoing SMTP server follows the same encryption logic.

A common mistake is to enter a generic SMTP server (that of their internet service provider) instead of the CHU’s SMTP server. The email then goes out without institutional signature, or may even be blocked by the recipient’s anti-spam filters.

Securing a Personal Device Used for CHU of Reims Email

Connecting from a personal computer is not trivial when the messages transmitted contain health data. National recommendations converge towards a hardening of the connection workstation, not just the network link.

  • Keep the operating system and browser up to date, as vulnerabilities exploited in phishing campaigns targeting Zimbra often rely on outdated browsers
  • Never save the Zimbra password in the browser’s password manager on a shared workstation
  • Use a dedicated session on the family computer, protected by a distinct password, to prevent another household user from accessing professional email
  • Log out of Zimbra after each use rather than simply closing the tab, as the session cookie may remain active

Nurse from the CHU of Reims consulting their Zimbra email remotely on a tablet from home

The CHU login page (mail.chu-reims.fr) displays a message requiring authentication when the session has expired. This behavior is normal and does not mean that the account is blocked. Simply reconnect by entering your credentials and the OTP code again.

The choice between the Modern version and the Classic version of the Zimbra interface, offered at login, has no impact on security. The Modern version provides a touch-friendly interface, while the Classic version is better suited for users accustomed to a heavy client like Outlook. This preference can be changed in the general settings of Zimbra, under “Zimbra Version.”

Accessing professional email outside the walls of the CHU ultimately relies on three pillars: properly configured enhanced authentication in advance, server settings compliant with the IT department’s guidelines, and a personal device maintained in an acceptable security state. Neglecting any of these elements exposes not only the agent but also the patient data that transit in these exchanges.

Practical Guide to Access Zimbra from the CHU of Reims Remotely and Securely