05.08.2013 Views

InterScanTM Messaging Security Virtual Appliance - Online Help ...

InterScanTM Messaging Security Virtual Appliance - Online Help ...

InterScanTM Messaging Security Virtual Appliance - Online Help ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Trend Micro InterScan <strong>Messaging</strong> <strong>Security</strong> <strong>Virtual</strong> <strong>Appliance</strong> Administrator’s Guide<br />

11-20<br />

Data Base Updated<br />

[root@imsva82b ~]#<br />

The /tmp/imsva_cert.pem file contains the IMSVA certificate signed by the<br />

Certificate Authority. You need to distribute this file to all servers and clients<br />

communicating with IMSVA.<br />

Deploying TLS Certificates<br />

Importing Certificates<br />

The TLS support provided by IMSVA uses the same set of keys for upstream and<br />

downstream directions. The CA certificate can be one of the following:<br />

• The real Certification Authority Certificate used to sign all public keys of all clients<br />

and servers communicating with IMSVA.<br />

• Individual certificates of all clients and servers communicating with IMSVA. In this<br />

case, the administrator must copy all individual certificates in one file using the<br />

following commands:<br />

a. For Windows:<br />

copy client_cert1.pem + ... + client_certN.pem<br />

ca_cert.pem<br />

b. For Linux:<br />

cat client_cert1.pem ... client_certN.pem > ca_cert.pem<br />

Configuring Postfix<br />

The Web Console must be used to configure TLS support in IMSVA. It downloads the<br />

key and certificates in the Postfix configuration directory<br />

(/opt/trend/imss/postfix/etc/postfix) and updates the configuration for the<br />

Upstream SMTP Server in the main.cf configuration file:<br />

smtpd_tls_security_level = may<br />

smtpd_tls_CAfile =<br />

/opt/trend/imss/postfix/etc/postfix/ca.pem<br />

smtpd_tls_cert_file =<br />

/opt/trend/imss/postfix/etc/postfix/cert.pem

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!