Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Astaro Gateway Products > Mail Security: SMTP, POP3, Antispam and Antivirus

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 06-14-2009, 02:56 PM
Super Moderator
 
Join Date: Feb 2009
Location: In a galaxy far far away
Posts: 760
Default [7.403]Question: EMAIL Encryption

Hi All

I've read the relevant kb for the email encryption and I've just finished the configuration...well i think!

1)It it true that for email encryption(encrypt outgoing mail) to work you have to have your own mail server (smtp proxy)?
2)Do you have to have either S/MIME or Open pgp defined for a user or can you use still use both(if both are used,which one is used)?
3)Under the C/MIME Authorities, I have no authority imported so far so I guess I am working with open PGP,right?
4)I am using PGP directory to locate public PGP for users but I can;t find them. Even If I have the fingerprint, I still can't

Could someone help me validate the settings? (ie. Exchange keys and send him a dumb email to check whether it's signed/ encrypted etc)

My understanding is that I don't have to configure the email clients.I am hoping that the above make sense!

Thanks
__________________

Running Astaro ASG virtual appliance | Home power user 100 IP license
Intel Dual Core 2.4GHz (800MHz) | 4GB (2 x 2GB) PC2-6400 800Mhz 5-5-5-18 | WD 160GB |3 x Intel Pro/1000

Last edited by wingman; 06-14-2009 at 09:41 PM.
Reply With Quote
  #2 (permalink)  
Old 06-14-2009, 09:08 PM
Super Moderator
 
Join Date: Feb 2009
Location: In a galaxy far far away
Posts: 760
Default

Just a quick update on the thread I've opened

It seems that on version 7.403 Astaro is unable to automatically import the C/MIME certificate (I had to manually import it)
__________________

Running Astaro ASG virtual appliance | Home power user 100 IP license
Intel Dual Core 2.4GHz (800MHz) | 4GB (2 x 2GB) PC2-6400 800Mhz 5-5-5-18 | WD 160GB |3 x Intel Pro/1000
Reply With Quote
  #3 (permalink)  
Old 06-15-2009, 10:31 AM
Member
 
Join Date: Jul 2008
Posts: 60
Default

Hi,

I´m using encryption since 7.2x and it works fine.
Trying to answer your questions:

Quote:
Originally Posted by wingman View Post
Hi All


1)It it true that for email encryption(encrypt outgoing mail) to work you have to have your own mail server (smtp proxy)?
Im using a own mailserver and the astaro as an smtp prox, but i think it must be working too, if you´re using the astaro as pop/imap server.

Quote:
2)Do you have to have either S/MIME or Open pgp defined for a user or can you use still use both(if both are used,which one is used)?
I´m using Open PGP for the users, that means creating an user within astaro and change the pgp keys with the external sender/receiver, which has to be defined.
Quote:
3)Under the C/MIME Authorities, I have no authority imported so far so I guess I am working with open PGP,right?
no clue about this, but i think so.
Quote:
4)I am using PGP directory to locate public PGP for users but I can;t find them. Even If I have the fingerprint, I still can't

Could someone help me validate the settings? (ie. Exchange keys and send him a dumb email to check whether it's signed/ encrypted etc)
yes, whenever you want, we can test it
Quote:
My understanding is that I don't have to configure the email clients.I am hoping that the above make sense!
thats quite right, no change to the clients.
__________________
--------------------------------
2xASG 220 HA Cluster mode, V7.x,
SMTP Proxy, Webproxy, Mail-Spam/virus/encryption enabled.

Last edited by tkaufi; 06-15-2009 at 10:34 AM.
Reply With Quote
  #4 (permalink)  
Old 06-15-2009, 02:40 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 4,954
Default

I had some anomalies with importing certs and keys in 7.403. The problems were resolved with a reboot. This was the first reboot since Up2Dating from 7.402 to 7.403.

Astaro, I think there's a problem with some failure to load everything after a restore or an Up2Date. The temporary fix seems to be to reboot afterwards. The fact that rebooting solves this problems is not a reason to ignore its existence.

Cheers - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
  #5 (permalink)  
Old 06-15-2009, 02:57 PM
Member
 
Join Date: Jul 2008
Posts: 42
Default

Quote:
2)Do you have to have either S/MIME or Open pgp defined for a user or can you use still use both(if both are used,which one is used)?
You can use both. To send encrypted mails, you need to import the recipient's public key. The ASG will always use the protocol, for which it finds a public key, so it will depend on the recipient.
If you have S/MIME and PGP keys for a recipient, S/MIME will be preferred over PGP.
Reply With Quote
  #6 (permalink)  
Old 06-15-2009, 08:33 PM
Super Moderator
 
Join Date: Feb 2009
Location: In a galaxy far far away
Posts: 760
Default

thx for the answers everyone. I don't have an internal mail server and thus I am not using SMTP at all. I am using pop proxy though.
__________________

Running Astaro ASG virtual appliance | Home power user 100 IP license
Intel Dual Core 2.4GHz (800MHz) | 4GB (2 x 2GB) PC2-6400 800Mhz 5-5-5-18 | WD 160GB |3 x Intel Pro/1000
Reply With Quote
  #7 (permalink)  
Old 06-15-2009, 11:06 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 4,954
Default

I think, since you have your own domain, and thus control over sending from it, you can output SMTP email from your Astaro. That should allow you to sign & encrypt emails from that domain.
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
  #8 (permalink)  
Old 06-15-2009, 11:22 PM
Super Moderator
 
Join Date: Feb 2009
Location: In a galaxy far far away
Posts: 760
Default

well that's what i thought but I can't see any indication whatsoever that I am using either signed or encrypted email
__________________

Running Astaro ASG virtual appliance | Home power user 100 IP license
Intel Dual Core 2.4GHz (800MHz) | 4GB (2 x 2GB) PC2-6400 800Mhz 5-5-5-18 | WD 160GB |3 x Intel Pro/1000
Reply With Quote
  #9 (permalink)  
Old 06-15-2009, 11:42 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 4,954
Default

Can you show a pic of the 'Authenticated relay' and 'Host-based relay' sections of the 'Relaying' tab of SMTP? At the bottom of the 'Advanced' tab, show your 'Smarthost settings'.

Cheers - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
  #10 (permalink)  
Old 06-15-2009, 11:47 PM
Super Moderator
 
Join Date: Feb 2009
Location: In a galaxy far far away
Posts: 760
Default

I don't have SMTP proxy enabled at all!!!

I assume that all emails I want to be signed should be relayed b the smtp proxy right?

Unfortunately, My when I send an email my IP is DUL (trend micro engine). I think it's BT 's issue
__________________

Running Astaro ASG virtual appliance | Home power user 100 IP license
Intel Dual Core 2.4GHz (800MHz) | 4GB (2 x 2GB) PC2-6400 800Mhz 5-5-5-18 | WD 160GB |3 x Intel Pro/1000

Last edited by wingman; 06-15-2009 at 11:55 PM.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 02:57 PM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.