05.08.2013 Views

InterScanTM Messaging Security Virtual Appliance - Online Help ...

InterScanTM Messaging Security Virtual Appliance - Online Help ...

InterScanTM Messaging Security Virtual Appliance - Online Help ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

smtpd_tls_key_file =<br />

/opt/trend/imss/postfix/etc/postfix/key.pem<br />

Configuring Transport Layer <strong>Security</strong> Settings<br />

When the administrator enables the downstream TLS from the Web Console, the<br />

Manager makes the following configuration changes in the main.cf configuration file<br />

that affect the SMTP client:<br />

smtp_tls_security_level = may<br />

Enabling the TLS Support in Outlook Express<br />

To enable TLS support on the Outlook Express Mail clients, follow the procedure<br />

described below.<br />

Converting Certificates<br />

Outlook Express does not recognize the certificates in PEM-format, so they need to be<br />

converted into the PKCS12-format. The example below shows how to convert the<br />

IMSVA signed certificate needed for the Outlook Express clients that contact IMSVA<br />

directly:<br />

[root@imsva82b ~]# openssl pkcs12 -export -out<br />

/tmp/imsva_cert.p12 -inkey /tmp/imsva_key.pem -in<br />

/tmp/imsva_cert.pem<br />

Enter Export Password: <br />

Verifying - Enter Export Password: <br />

[root@imsva82b ~]#<br />

The /tmp/imsva_cert.p12 file contains the IMSVA certificate in PKCS12-format<br />

and must be transferred to the Windows machines running Outlook Express and<br />

communicating directly with IMSVA.<br />

Importing Certificates<br />

Go to the Outlook Express Menu and use the following sequence to see the available<br />

certificates: Menu > Tools > Options > <strong>Security</strong> > Digital IDs.<br />

Click Import… to search for files in the Personal Information Exchange format<br />

(*.pfx, *.p12) and select the imsva_cert.p12 file generated above. Confirm the<br />

certificate import with an empty password to import the certificate.<br />

11-21

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!