11.07.2015 Views

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 36 Support for ActiveSync• Symbian S60 3rd Edition,• Palm OS (synchronization is available for email only),• Java MIDP 2.0 (synchronization is available for email only),For details on RoadSync and supported devices, see the DataViz website athttp://www.dataviz.com/.36.4 SSL encryptionFor the traffic, ActiveSync uses the HTTP or the HTTPS protocol.Warning: For security reasons, it is recommended to synchronize only by the HTTPS protocol,since ActiveSync uses only unencrypted user login data for authentication at the server.For description on encryption of services running in <strong>Kerio</strong> MailServer, see chapter 10. Thismethod requires a valid SSL certificate installed on the device.The following conditions must be met to make certificates valid:• The certificate must be issued by a trustworthy certification authority. Trustworthy meansthat the mobile device needs to know the server’s root certificate. Windows Mobile includesroot certificates of several certification authorities. List of these authorities can be foundat the Microsoft Corporation website.• Date of the certificate must be valid and correct date and time must be set in the device.• The certificate must include a valid name of the email domain for which <strong>Kerio</strong> MailServeris used.Valid certificates for encrypted traffic can be either certificates issued by trustworthy certificationauthorities (these certificates can be quite expensive, however, they avoid possible installationdifficulties) or a certificate issued by an internal certification authority or a so-calledself-signed certificate generated in <strong>Kerio</strong> MailServer (for details, see chapter 10).In case of certificates issued by a trusted certification authority, no settings or installations arerequired. In cases of internal certificates or self-signed certificates, the root certificate mustbe installed on the device.Windows Mobile requires certificate encoded in the DER X.509 format. The .cer extension isrequired. The simpliest method to get and install a certificate is to download it to the deviceby a browser.<strong>Kerio</strong> MailServer’s self-signed certificate in the required format is available athttp://server_name/server.cerOn devices with Windows Mobile 2002, traffic can be performed only by HTTPS. The unencryptedversion of the protocol is not supported. It is also necessary that <strong>Kerio</strong> MailServerauthenticates with a certificate authorized by a trustworthy certification authority. This canbe either a certificate authorized by a supported commercial certification authority (certificatesissued by VeriSign, CyberTrust, Thawte and Entrust are supported) or a root certificateof the authority which issued the certificate for <strong>Kerio</strong> MailServer can be installed on the device(for details, see section Allowing installation of a root certificate in WM 2002).368

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!