05.08.2013 Views

InterScanTM Messaging Security Virtual Appliance - Online Help ...

InterScanTM Messaging Security Virtual Appliance - Online Help ...

InterScanTM Messaging Security Virtual Appliance - Online Help ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Trend Micro InterScan <strong>Messaging</strong> <strong>Security</strong> <strong>Virtual</strong> <strong>Appliance</strong> Administrator’s Guide<br />

11-12<br />

<strong>Security</strong> parameters can be customized in the upstream site-specific TLS settings.<br />

TABLE 11-3. Upstream Site-specific TLS <strong>Security</strong> Parameters<br />

SECURITY<br />

PARAMETER<br />

Table 11-3 lists the upstream site-specific TLS security parameters in order of increasing<br />

security and customization. For example:<br />

smtpd_tls_policy:<br />

DESCRIPTION<br />

req_cert In mandatory TLS mode, IMSVA requires a trusted<br />

remote SMTP client certificate to allow TLS connections<br />

to proceed. This parameter overrides<br />

smtpd_tls_req_ccert in main.cf. In opportunistic<br />

TLS mode, this parameter does not work.<br />

ciphers The minimum TLS cipher grade that IMSVA uses. In<br />

opportunistic TLS mode, this parameter overrides<br />

smtpd_tls_ciphers in main.cf. In mandatory TLS<br />

mode, this parameter overrides<br />

smtpd_tls_mandatory_ciphers. The alternative<br />

parameters smtp_tls_exclude_ciphers and<br />

smtp_tls_mandatory_exclude_ciphers may<br />

also be used.<br />

protocols SSL/TLS protocols can be accepted by IMSVA. In<br />

mandatory TLS mode, this parameter overrides<br />

smtpd_tls_mandatory_protocols in main.cf.<br />

In opportunistic TLS mode, this parameter overrides<br />

smtpd_tls_protocols.<br />

exclude Ciphers can be excluded from the IMSVA cipher list.<br />

This parameter overrides<br />

smtpd_tls_exclude_ciphers in main.cf for all<br />

TLS security levels. This parameter also overrides<br />

smtpd_tls_mandatory_exclude_ciphers in<br />

mandatory TLS mode.<br />

encrypt req_cert=yes ciphers=medium<br />

protocols=TLSv1

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!