Configuring SSL/TLS in Kerio Connect

NOTE

New in Kerio Connect 8.5!

Kerio Connect allows you to enable or disable specific security protocols and cipher sets manually for:

  • Kerio Connect server in general
  • SMTP services separately (for SMTP on port 25 and SMTPS on port 465)

You might need to adjust the security settings when a flaw in a security protocol is found or to get a good security rating for your server. (You can test your server, for example, at Qualys SSLlabs test site).

Changing the SSL/TLS configuration

Kerio Connect uses different variables for the SSL/TLS protocols configuration. To change the configuration:

  1. Stop the Kerio Connect engine.
  2. Open the configuration file mailserver.cfg for editing. For more information refer to Configuration files.
  3. Change the settings in the Security or SmtpSecurity sections. See the list of variables below.
  4. Save the file.
  5. Start Kerio Connect.

Resetting the SSL/TLS configuration

To reset the SSL/TLS configuration in the configuration file:

  1. Stop the Kerio Connect engine.
  2. Open the configuration file mailserver.cfg for editing. For more information refer to Configuration files.
  3. Delete any variable in the Security or SmtpSecurity sections.
  4. Save the file.
  5. Start Kerio Connect.

Kerio Connect sets the default values of all the SSL/TLS variables.

  • 1 Users Found This Useful
Was this answer helpful?

Related Articles

Securing Kerio Connect

You can secure your Kerio Connect by: Restricting communication on firewall to necessary...

Configuring anti-spoofing in Kerio Connect

About Anti-spoofing Spammers can "spoof" your email address and pretend their messages are...

Password policy in Kerio Connect

To secure users and their passwords in Kerio Connect: Advise users to create strong...

Authenticating messages with DKIM

DomainKeys Identified Mail (DKIM) signs outgoing messages from Kerio Connect with a special...

Configuring DNS for DKIM

Adding a DKIM record to your DNS The process of adding a DKIM record to your DNS may vary...