13.07.2015 Views

Kerio Connect - Administrators Guide - Kerio Software Archive

Kerio Connect - Administrators Guide - Kerio Software Archive

Kerio Connect - Administrators Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Securing <strong>Kerio</strong> <strong>Connect</strong>Password policyFor information on passwords, read article Password policy in <strong>Kerio</strong> <strong>Connect</strong>.Configuring secure connection to <strong>Kerio</strong> <strong>Connect</strong><strong>Kerio</strong> <strong>Connect</strong> can secure:• user authentication• whole communicationFor settings, go to section Configuration → Security → tab Security Policy (Configuration →Advanced Options → tab Security Policy for <strong>Kerio</strong> <strong>Connect</strong> 8.1 and older).You can define a group of IP addresses which will be allowed to authenticate insecurely (e.g.from local networks).Securing user authentication<strong>Kerio</strong> <strong>Connect</strong> will always require secure user authentication:• CRAM-MD5 — password authentication by using MD5 digests• DIGEST-MD5 — password authentication by using MD5 digests• NTLM — use only with Active Directory.• SSL tunnel (if no other authentication method is used)If users’ passwords are saved in the SHA format:• do not apply CRAM-MD5, DIGEST-MD5, NTLM• do not map users from a directory serviceEncrypting user communicationClient applications will connect to any service using encrypted connection (the communicationcannot be tapped).SSL must be allowed to all protocols on all client stations.Many SMTP servers do not support SMTPS and STARTTLS. To provide sufficient security, theSMTP server requires secure user authentication.98

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!