11.07.2015 Views

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 15 Sending and Receiving MailSSL traffic must be allowed to all protocols at all client stations. The secured connectionis set automatically upon a successful connection to <strong>Kerio</strong> WebMail.The only exception from this restriction is the SMTP protocol. Due to the plenty of SMTPservers which do not support SMTPS and STARTTLS, it is not possible to allow the secureversion of the protocol only. To still provide sufficient security, the SMTP server requiressecure password authentication for the SMTP protocol upon enabling the Require encryptedconnection option. Name and password are still sent by one of the supportedsecure authentication methods.After the security policy is defined, you can create an exception for a group of IP addressesfor which the secured connection will not be required. For this purpose, eithera new IP group can be created or an existing one can be selected. For information on IPaddress settings, see chapter 12.1.If you decide for this communication protection method, make sure that all users havea valid authentication certificate installed on their client stations (for more information,see chapter 10).Supported authentication methods<strong>Kerio</strong> MailServer supports the following methods of user authentication:Figure 15.18Authentication methods• CRAM-MD5 — password authentication method (using MD5 digests). This method is quitecommon and many email clients provide support for it.• DIGEST-MD5 — password authentication method (using MD5 digests).• LOGIN — user passwords are completely unprotected during transfer. If this method isused, it is strongly recommended to enable SSL tunnel connection.• NTLM — this method can be used only in case users are authenticated against an ActiveDirectory domain. It is applicable only to the user accounts that were imported from ActiveDirectory. Configuration of NTLM authentication is addressed in chapter 25.• PLAIN — user passwords are completely unprotected during transfer. If this method isused, it is strongly recommended to enable SSL tunnel connection.• APOP — the authentication method is not displayed in the list, <strong>Kerio</strong> MailServer uses itautomatically to download POP3 accounts.The server provides all the above mentioned authentication methods. They are ordered thesame way as in the table below (from CRAM-MD5). If the selected method is supported by theclient, the other methods will not be used. However, a problem may occur if the passwordis stored in the secure format (SHA1). If this encryption method is used, only LOGIN and160

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!