11.07.2015 Views

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

10.1 <strong>Kerio</strong> MailServer CertificateFigure 10.1Security Alert• The certificate was not issued by a company defined as trustworthy in your configuration.This is caused by the fact that the certificate is self-signed. This warning will not bedisplayed if you install the certificate (you can do this because you know the certificate’sorigin).• The certificate date is valid (the certificate is valid for a certain limited period, usually 1-2years).• The name of the certificate does not correspond with the name of the server. The certificateis issued for a certain server name (e.g. mail.company.com), which you must also use inthe client (this certificate has been issued for a fictitious name keriomail).Now, there are two options. One is to keep in <strong>Kerio</strong> MailServer the self-signed certificate generatedduring the mailserver’s installation, the other option is to get a certificate authorized bya certification authority. It should be possible to install both types of certificates on client stations.In both cases, it is necessary that the certificate is maintained in the <strong>Kerio</strong> MailServer’sConfiguration → SSL certificates section (see figure 10.2).In SSL certificates, it is possible to create certificates, generate certificate demands for certificationauthorities as well as export certificates. Here is an overview of all options:New...Click on New to specify information about your server and your company. When confirmed,the server.crt and server.key files are created under sslcert.The certificate you create will be original and will be issued to your company by yourcompany (self-signed certificate). This certificate ensures security for your clients as itexplicitly shows the identity of your server. The clients will be notified by their webbrowsers that the certification authority is not trustworthy. However, since they knowwho created the certificate and for what purpose, they can install it. Secure communicationis then ensured for them and no warning will be displayed again because your85

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!