27.11.2012 Views

IronPort - advanced configuration guide

IronPort - advanced configuration guide

IronPort - advanced configuration guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 5 Email Authentication<br />

OL-25137-01<br />

Note When you create domain profiles, be aware that a hierarchy is used in determining the profile to associate<br />

with a particular user. For example, you create a profile for example.com and another profile for<br />

joe@example.com. When mail is sent from joe@example.com, the profile for joe@example.com is<br />

used. However, when mail is sent from adam@example.com, the profile for example.com is used.<br />

Step 12 Submit and commit your changes.<br />

Step 13 At this point (if you have not already) you should enable DomainKeys/DKIM signing on an outgoing<br />

mail flow policy (see Enabling Signing for Outgoing Mail, page 5-6).<br />

Creating New Signing Keys<br />

Note If you create both a DomainKeys and DKIM profile, AsyncOS performs both DomainKeys and<br />

DKIM signing on outgoing mail.<br />

To create a new signing key:<br />

Step 1 Click Add Key on the Mail Policies > Signing Keys page. The Add Key page is displayed.<br />

Step 2 Enter a name for the key.<br />

Step 3 Click Generate and Select a key size.<br />

Larger key sizes are more secure; however, larger keys can have an impact on performance. Cisco<br />

recommends a key size of 768 bits, which should provide a good balance between security and<br />

performance.<br />

Step 4 Click Submit. The key is generated.<br />

Step 5 Click the Commit Changes button, add an optional comment if necessary, and then click Commit<br />

Changes to finish adding the new signing key.<br />

Note If you have not done so already, you may need to edit your domain profile to assign the key.<br />

Exporting Signing Keys<br />

When you export signing keys, all of the keys currently existing on your Cisco <strong>IronPort</strong> appliance are<br />

exported together in a single text file. To export signing keys:<br />

Step 1 Click Export Keys on the Signing Keys page. The Export Signing Keys page is displayed:<br />

Figure 5-9 Export Signing Keys Page<br />

Step 2 Enter a name for the file and click Submit.<br />

Cisco <strong>IronPort</strong> AsyncOS 7.6 for Email Advanced Configuration Guide<br />

5-11

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!