Koozali.org: home of the SME Server

SME POP3S- SSL

Offline ber

  • *****
  • 239
  • +0/-0
SME POP3S- SSL
« on: July 29, 2008, 04:49:13 AM »
Hi, have looked extensively in the user manuals and cant find any info regarding disabling SSL on the POP3 protocol.
Is this feature able to be disable and run pop3 protocol without encryption?

Thanks

Offline warren

  • *
  • 293
  • +0/-0
Re: SME POP3S- SSL
« Reply #1 on: July 29, 2008, 09:22:38 AM »

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: SME POP3S- SSL
« Reply #2 on: July 29, 2008, 05:33:57 PM »
Hi, have looked extensively in the user manuals and cant find any info regarding disabling SSL on the POP3 protocol.
Is this feature able to be disable and run pop3 protocol without encryption?

You don't need to disable POP3S, just use POP3 rather than using POP3S. Note that POP3 is usually not available from outside your local LAN. You would need to use the config command to set the 'access' property to 'public' to enable global access to pop3 - but that is not recommended, as your usernames and passwords would be accessible to sniffing.

Why do you want to disable POP3S?

Offline ber

  • *****
  • 239
  • +0/-0
Re: SME POP3S- SSL
« Reply #3 on: July 29, 2008, 10:23:07 PM »
HI the server is hosting multiple domains for clubs and organizations.
The SSL config prompts our clients every time they download there emails through outlook or express.
This is a nuisance, I understand the security feature, is there a way of memorizing SME certificate so that there email client doesn't prompt for confirmation of certificate?
Thanks

Offline ber

  • *****
  • 239
  • +0/-0
Re: SME POP3S- SSL
« Reply #4 on: July 29, 2008, 10:24:19 PM »
also access for emails are outside the local network via internet.

Offline janet

  • *****
  • 4,812
  • +0/-0
Re: SME POP3S- SSL
« Reply #5 on: July 30, 2008, 08:34:35 AM »
ber

Quote
The SSL config prompts our clients every time ...... is there a way of memorizing SME certificate so that there email client doesn't prompt for confirmation of certificate?

I'm assuming you are using the self signed certificate issued by sme server.
When they configure the email client, tell them to use the appropriate servername for Incoming and Outgoing servers eg
servername.yourdomain.com
instead of
mail.yourdomain.com

...and of course get them to add the certificate to their browser the first time they access using https://...

Please search before asking, an answer may already exist.
The Search & other links to useful information are at top of Forum.

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: SME POP3S- SSL
« Reply #6 on: July 30, 2008, 04:07:16 PM »
The SSL config prompts our clients every time they download there emails through outlook or express.
This is a nuisance, I understand the security feature, is there a way of memorizing SME certificate so that there email client doesn't prompt for confirmation of certificate?

That depends on what client they use. Outlook and OE (which should *not* be used) can be told to remember a certificate which would otherwise not be trusted. But I see mary has already told you that.

If you want no warnings from any client, then you need to buy a certificate signed by one of the big companies trusted by the client software. But you will still need to tell people to use a hostname in their configuration which matches what is stored in the certificate. However, if you are clever about the way you make the certificate, it can include multiple hostnames. Search the web for "Subject Alternative Names" or "Subject AltNames" for more details.


Offline warren

  • *
  • 293
  • +0/-0
Re: SME POP3S- SSL
« Reply #7 on: July 30, 2008, 06:57:48 PM »
Quote
Outlook and OE (which should *not* be used)....

Charlie, out of curiosity- ignorance, whats wrong in using OE ?  :?

Offline byte

  • *
  • 2,183
  • +2/-0
Re: SME POP3S- SSL
« Reply #8 on: July 30, 2008, 07:29:19 PM »
Charlie, out of curiosity- ignorance, whats wrong in using OE ?  :?

They are M$ products  :lol:
--[byte]--

Have you filled in a Bug Report over @ http://bugs.contribs.org ? Please don't wait to be told this way you help us to help you/others - Thanks!

Offline warren

  • *
  • 293
  • +0/-0
Re: SME POP3S- SSL
« Reply #9 on: July 30, 2008, 07:43:12 PM »
Quote
They are M$ products 
:lol:

Walked Slap Bang into that one   :-)

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: SME POP3S- SSL
« Reply #10 on: July 30, 2008, 09:05:56 PM »
Charlie, out of curiosity- ignorance, whats wrong in using OE ?  :?

It's probably the most egregious vector of viruses known to man. And it also eats mail folders.