05.08.2013 Views

InterScanTM Messaging Security Virtual Appliance - Online Help ...

InterScanTM Messaging Security Virtual Appliance - Online Help ...

InterScanTM Messaging Security Virtual Appliance - Online Help ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

TABLE 11-2. Downstream TLS levels<br />

SECURITY<br />

LEVELS<br />

encrypt Mandatory TLS<br />

verify Mandatory TLS<br />

secure Secure-channel TLS<br />

Configuring Transport Layer <strong>Security</strong> Settings<br />

Table 11-2 lists the downstream TLS security levels in order of increasing security. For<br />

more information on each security level, visit:<br />

http://www.postfix.org/TLS_README.html#client_tls<br />

To use site-specific TLS:<br />

1. Set the value of detach_key_postfix in<br />

/opt/trend/imss/config/imss.ini.<br />

detach_key_postfix=smtpd_tls_CAfile:smtpd_tls_cert_file:smtp<br />

d_tls_key_file:smtp_tls_CAfile:smtp_tls_cert_file:smtp_tls_k<br />

ey_file:smtpd_tls_security_level:smtp_tls_security_level<br />

Note: The settings of postfix configured by the Web console do not have to apply to all<br />

scanners. IMSVA uses the key detach_key_postfix in imss.ini to override<br />

existing settings in main.cf.<br />

2. Restart IMSSMGR Service.<br />

Here you need to “Enter the IMSVA shell environment”.<br />

$ /opt/trend/imss/script/S99MANAGER restart<br />

3. Save your Certificate Authority (CA), IMSVA public key, and IMSVA private key in<br />

the /opt/trend/imss/postfix/etc/postfix folder.<br />

4. Configure /opt/trend/imss/postfix/etc/postfix/main.cf.<br />

• For incoming site-specific TLS settings:<br />

smtpd_tls_security_level = may<br />

LEVELS<br />

11-9

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!