11.07.2015 Views

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

15.6 Advanced OptionsPLAIN authentication methods can be used. If you select the secure CRAM-MD5 and DIGEST-MD5 methods, the system selects one of the secure authentication methods and it will beimpossible to log in to <strong>Kerio</strong> MailServer. If the password is stored in the SHA format, disableall methods but LOGIN and PLAIN.Operational system Authentication againstActive DirectoryUser mailboxesare stored locallyand passwordsare secured byDES encryptionUser mailboxesare stored locallyand passwordsare secured bySHA encryptionMS WindowsNTLMCRAM-MD5LOGINLOGINDIGEST-MD5PLAINPLAINLOGINPLAINLINUXLOGINCRAM-MD5LOGINPLAINDIGEST-MD5PLAINLOGINPLAINMac OS XLOGINCRAM-MD5LOGINPLAINDIGEST-MD5PLAINLOGINPLAINTable 15.3Authentication methodsFurther recommendations:• If a client authentication method fails, it is recommended to disable it in <strong>Kerio</strong> MailServer(uncheck it in the Enabled authentication methods list).• For all authentication methods, it is recommended to enable SSL login to the mail clients.Check Allow NTLM authentication for users with Kerberos authentication to allow users fromActive Directory to authenticate when attempting to log in to <strong>Kerio</strong> MailServer. In order for theNTLM authentication to be functional, both the computer as well as the user account have tobe parts of the domain used for authentication. The NTLM (SPA) authentication must be alsoenabled in users’ mail clients.To see what is necessary to be set in <strong>Kerio</strong> MailServer to make NTLM authentication worksmoothly, refer to chapter 25.In the Account lockout section the following parameters can be defined (see figure 15.19):Enable account lockoutWhen this option is selected, user accounts will be locked based on the following rules.These settings protect the user accounts from being misused.161

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!