Search found 112 matches

by mikedibella
2018-11-07 03:20
Forum: Off-topic discussions
Topic: ALternative to Office 365 Message Encryption capabilities
Replies: 7
Views: 555

Re: ALternative to Office 365 Message Encryption capabilities

For the use case I describe below, the portal needs to be published, but it doesn't store the encrypted PDF. The portal is used to generate the one-time password (OTP) to decrypt the PDF. The basic flow of an starts when an email sent to the gateway is decomposed and the body and attachments are pub...
by mikedibella
2018-11-07 01:42
Forum: Off-topic discussions
Topic: ALternative to Office 365 Message Encryption capabilities
Replies: 7
Views: 555

Re: ALternative to Office 365 Message Encryption capabilities

I did get Ciphermail working again for PDF encryption. Let me know if you want to compare notes.
by mikedibella
2018-11-01 18:11
Forum: Off-topic discussions
Topic: ALternative to Office 365 Message Encryption capabilities
Replies: 7
Views: 555

Re: ALternative to Office 365 Message Encryption capabilities

It has been a while since I evaluated it. I just looked at my VCB archive and the last image I took of the appliance was in 2015. So it is very possible the project as evolved/morphed into the Ciphermail appliance. I definitely remember it was offered as a virtual appliance. The UI looks a lot clean...
by mikedibella
2018-10-31 19:47
Forum: Off-topic discussions
Topic: ALternative to Office 365 Message Encryption capabilities
Replies: 7
Views: 555

Re: ALternative to Office 365 Message Encryption capabilities

I looked at Djigzo a while back...http://freshmeat.sourceforge.net/projects/djigzo

I found the recipient UI too crude, might have matured since then.
by mikedibella
2018-10-09 22:17
Forum: General discussions
Topic: Having issues getting SSL certificate to work
Replies: 15
Views: 772

Re: Having issues getting SSL certificate to work

Change connection security on port 25 from STARTTLS Required to STARTTLS Optional.
by mikedibella
2018-10-09 01:38
Forum: General discussions
Topic: Having issues getting SSL certificate to work
Replies: 15
Views: 772

Re: Having issues getting SSL certificate to work

I also use Let's Encrypt and have had success with the instructions on this website: https://www.sslforfree.com/ The site will generate the keys for you securely on your own machine using browser extensions, so it is safe to use. Read the section about validation carefully because you can't generate...
by mikedibella
2018-10-08 19:24
Forum: General discussions
Topic: Having issues getting SSL certificate to work
Replies: 15
Views: 772

Re: Having issues getting SSL certificate to work

The key pair generated must be used to generate the CSR that is submitted to request the certificate. The error message indicates that the private key does not match the public key in the certificate. You will need to regenerate the certificate, carefully following the steps provided in articles on ...
by mikedibella
2018-10-05 22:32
Forum: General discussions
Topic: Having issues getting SSL certificate to work
Replies: 15
Views: 772

Re: Having issues getting SSL certificate to work

The certificate file you point to in the hMailServer configuration must have intermediates first and the leaf (server) certificate last. Assuming both of the files received from your CA are Base64 format (they have BEGIN CERTIFICATE sections), append the contents of mail_tgserver_com.crt to the end ...
by mikedibella
2018-10-04 20:00
Forum: General discussions
Topic: Having issues getting SSL certificate to work
Replies: 15
Views: 772

Re: Having issues getting SSL certificate to work

Are you trying to enable connection security for MTA-to-MTA communications or for client-to-server communications? If you want to enable for MTA interconnections, change connection security on port 25 to STARTTLS. If you want to enable for client connections, either change connection security on por...
by mikedibella
2018-09-28 17:36
Forum: General discussions
Topic: Making LetsEncrypt Certificates usable for hMail
Replies: 6
Views: 2529

Re: Making LetsEncrypt Certificates usable for hMail

download openssl.exe and run the following command: openssl.exe pkcs12 -in file.pfx -nodes -out pem.txt Edit pem.txt and separate the sections into a certificate files and key files. Put all the certificate sections into one file with the intermediates first and leaf (server) certificate last. Put t...
by mikedibella
2018-08-31 23:16
Forum: General discussions
Topic: question about AD logins and UPNs
Replies: 7
Views: 323

Re: question about AD logins and UPNs

One thing to keep in mind, when you enable the "Active Directory account" option, you are mapping the mailbox identity to the "Domain" and "User name" values provided. When the client negotiates authentication, it will provide the mailbox identity and password, and HMS will use the mapped Domain and...
by mikedibella
2018-08-31 22:15
Forum: General discussions
Topic: question about AD logins and UPNs
Replies: 7
Views: 323

Re: question about AD logins and UPNs

Let me make sure I get this. You are saying that Outlook won't authenticate against HMS is unless the account configuration Email Address under User Information is the same as User Name under Login Information?
by mikedibella
2018-08-31 19:29
Forum: General discussions
Topic: question about AD logins and UPNs
Replies: 7
Views: 323

Re: question about AD logins and UPNs

Let me make sure I understand the requirement. You have existing Outlook users that were using explicit credentials (not Kerberos or Integrated authentication) to log into Exchange. The explicit credentials included a user ID that matched the Active Directory UPN for the user and the user's AD passw...
by mikedibella
2018-08-31 17:44
Forum: General discussions
Topic: question about AD logins and UPNs
Replies: 7
Views: 323

Re: question about AD logins and UPNs

Are you familiar with Alternative UPN Suffixes? See http://www.tutorialspoint.com/articles/ ... ory-domain.
by mikedibella
2018-03-23 21:52
Forum: General discussions
Topic: SSL Certificate
Replies: 7
Views: 709

Re: SSL Certificate

If you don't own, and exercise authoritative control over, a domain, no public CA will generate a certificate for you for that domain.
by mikedibella
2018-03-23 20:21
Forum: General discussions
Topic: SSL Certificate
Replies: 7
Views: 709

Re: SSL Certificate

if you want a wildcard that matches hostname.ex.geektek.com then you would enter *.ex.geektek.com in the "enter your website to secure" field and create a new TXT record with the _acme-challenge Name in the ex.geektek.com domain. Set the TTL of the record to 1 second. Wait for your secondaries to be...
by mikedibella
2018-03-23 01:28
Forum: General discussions
Topic: SSL Certificate
Replies: 7
Views: 709

Re: SSL Certificate

CA: https://letsencrypt.org

I use this website for manual certificate issuance: https://www.sslforfree.com/

But I suggest you generate your own CSR locally if you aren't sure if your browser can support local key generation.
by mikedibella
2018-03-22 23:20
Forum: General discussions
Topic: SSL Certificate
Replies: 7
Views: 709

Re: SSL Certificate

Is ex.geektek.com the mail domain (i.e. for the MX record Name attribute) or the server's hostname (for the MX record Data attribute)? The wildcard must match the hostname. If ex.geektek.com is the mail domain and mail.ex.geektek.com is the hostname, then you need a wildcard *.ex.geektek.com to matc...
by mikedibella
2018-03-14 22:04
Forum: General discussions
Topic: Suddenly nothing works!
Replies: 12
Views: 1108

Re: Suddenly nothing works!

Maybe:

Updates force reboot
4.1 starts first and binds port
5.6 starts can't bind
HMS starts and comms with 4.1
Disaster

Make sure you at least Disable 4.1 in SCM
by mikedibella
2018-03-02 03:50
Forum: Off-topic discussions
Topic: Windows Service Weirdness
Replies: 7
Views: 1278

Re: Windows Service Weirdness

I notice that the time between postings in the successful run is 3/100s of a second, but in the abnormal run the time differential is 1 minute and 29/100s of a second. Maybe there was some kind of failure that produced abend output?
by mikedibella
2018-03-02 00:13
Forum: Off-topic discussions
Topic: Windows Service Weirdness
Replies: 7
Views: 1278

Re: Windows Service Weirdness

Check each directory in your %PATH% for an executable named NET.EXE. If there is another executable named NET.EXE in a directory before %SYSTEMROOT%\System32, that program will be executed in your script. To fix, fully qualify the file (i.e. net -> %SYSTEMROOT%\System32\NET.EXE).
by mikedibella
2018-03-01 22:20
Forum: General discussions
Topic: Help with Exchange and hmailserver
Replies: 5
Views: 661

Re: Help with Exchange and hmailserver

It is possible to configure an Exchange 2010 Send Connector to use TLS (not STARTTLS).

See RequireTLS: https://technet.microsoft.com/en-us/lib ... .141).aspx
by mikedibella
2018-02-27 23:40
Forum: General discussions
Topic: How to execute a script in regular intervals
Replies: 4
Views: 502

Re: How to execute a script in regular intervals

I would create an external script using VBScript or JScript that does the following task: Creates an instance of the hMailserver COM Object Logs in For each Domain object in the Domains collection For each Account object in the Domain's Accounts collection If QuotaUsed is greater than a threshold va...
by mikedibella
2018-02-12 21:21
Forum: General discussions
Topic: Small Business Server 2011
Replies: 5
Views: 847

Re: Small Business Server 2011

Port 587 typically uses STARTTLS connections, which start as unencrypted and switch to TLS using the STARTTLS SMTP verb. Port 465 typically requires TLS to be negotiated but any SMTP protocol is conducted. The attached article is for that type of connection. If your ISP isn't using a Public CA certi...
by mikedibella
2018-01-26 20:54
Forum: General discussions
Topic: Basic SMTP relay
Replies: 7
Views: 873

Re: Basic SMTP relay

I search though some older code I had saved locally an see two references. One call when the generated eml filename already exists (SMTPConnection.cpp line 1194) and one when the filename or file could not be generated (not sure which, line 1657).
by mikedibella
2018-01-17 18:46
Forum: Off-topic discussions
Topic: MS-Exchange 2010/2013/2016 is such a moron
Replies: 4
Views: 1056

Re: MS-Exchange 2010/2013/2016 is such a moron

If you aren't planning to back up Exchange using an Exchange-aware backup tool, you should enable circular logging: https://technet.microsoft.com/en-us/library/dn756374(v=exchg.150).aspx Exchange transaction logs only get purged after successful backup, and will eventually consume all space on the l...
by mikedibella
2018-01-15 22:48
Forum: General discussions
Topic: Intermitent problem with SSL comunication
Replies: 31
Views: 2757

Re: Intermitent problem with SSL comunication

If you are certain only the configuration of the server was changed and not the clients, you could try a System Restore to a checkpoint when the server was functional.

Beyond that, I'd probably use a packet trace to see the TLS negotiation traffic.
by mikedibella
2018-01-15 22:39
Forum: General discussions
Topic: SSL certificate help needed
Replies: 12
Views: 890

Re: SSL certificate help needed

Depending on the client, an attempt may be made to autodiscover the account's server addresses based on the account sender address. So you may be seeing the sender's domain used as the incoming or outgoing server address as a product of the client's specific autodiscover process.
by mikedibella
2018-01-15 20:36
Forum: General discussions
Topic: Intermitent problem with SSL comunication
Replies: 31
Views: 2757

Re: Intermitent problem with SSL comunication

You might want to run a report on the TLS configuration of the IMAP interface. Comodo has an online checker at https://sslanalyzer.comodoca.com/ that you can use. Another idea is to run a cipher test yourself. Here is the script I use: #!/usr/bin/env bash # OpenSSL requires the port number. SERVER=$...
by mikedibella
2018-01-15 18:55
Forum: General discussions
Topic: Intermitent problem with SSL comunication
Replies: 31
Views: 2757

Re: Intermitent problem with SSL comunication

Do you know what update caused the problem to occur? Can you rollback or uninstall that update?

I looks to me like the either cipher list or cipher order has been modified on one of the endpoints and a mutual cipher can no longer be negotiated.
by mikedibella
2018-01-15 00:27
Forum: General discussions
Topic: SSL certificate help needed
Replies: 12
Views: 890

Re: SSL certificate help needed

download and install openssl if you don't already have it and use the following command to generate a protocol trace for your server's IMAP port: openssl.exe s_client -connect your.server.hostname:143 -starttls imap -showcerts Review the protocol trace carefully. You are looking to see that multiple...
by mikedibella
2018-01-13 20:08
Forum: General discussions
Topic: mail delivery problem - verification failed from remote server
Replies: 21
Views: 1831

Re: mail delivery problem - verification failed from remote server

It is not required that the SSL certificate match the recipient domain. It is required that the subject Common Name of the SSL certificate match the DNS name used to connect to the server. This is the hostname returned as the "mail exchanger =" portion of the MX record query response. It is also bes...
by mikedibella
2018-01-12 18:41
Forum: General discussions
Topic: mail delivery problem - verification failed from remote server
Replies: 21
Views: 1831

Re: mail delivery problem - verification failed from remote server

The destination server is doing a callback validation based on the sender address and it is failing. This callback validation is typically done by looking up the sender address domain MX and making and connection to send mail, and passing or failing based on the MX response to RCPT TO verb. To pass,...
by mikedibella
2018-01-08 23:27
Forum: General discussions
Topic: Increase Spam score
Replies: 3
Views: 434

Re: Increase Spam score

OK, i think I solved my problem this way:

C1: sender contains bad domain
AND
C2: X-hMailServer-Reason-Score > 0
THEN delete
by mikedibella
2018-01-08 21:27
Forum: General discussions
Topic: Increase Spam score
Replies: 3
Views: 434

Re: Increase Spam score

Or, as an alternative, can I check the Spam Score within the Global Rule processing? In the logs I see DNSBL tests are completed before the rule is invoked. Is the score added to a Header value by the time a Global Rule is processed?
by mikedibella
2018-01-08 20:28
Forum: General discussions
Topic: Increase Spam score
Replies: 3
Views: 434

Increase Spam score

Anyone have any ideas how I can increase a message spam score via a global rule action? I'm seeing a pattern of messages coming from a single sender domain that are for the moment exclusively spam. They are passing some of the spam tests and not meeting the delete threshold, so I'm just using a glob...
by mikedibella
2017-12-23 22:42
Forum: General discussions
Topic: How can I add "hMailServer service dependency" after I have installed hMailServer
Replies: 5
Views: 630

Re: How can I add "hMailServer service dependency" after I have installed hMailServer

you need a space after the equal sign:

sc config hMailServer depend= RPCSS/MSSQL$MSSQL_INSTANCE01
by mikedibella
2017-12-06 20:55
Forum: User-submitted tutorials
Topic: HOW TO: get gMail certificates to validate
Replies: 11
Views: 3689

Re: HOW TO: get gMail certificates to validate

Crud...I was doubly wrong. I should have tested first. Manual installation of the intermediate certificates was required, but I did confirm on my own implementation that Matt's procedure work as expect. Second, I was unable to get a .STL file to install as expected on Windows Server 2012. The file t...
by mikedibella
2017-12-06 19:43
Forum: User-submitted tutorials
Topic: HOW TO: get gMail certificates to validate
Replies: 11
Views: 3689

Re: HOW TO: get gMail certificates to validate

Hmmm...I just realized that hMailServer uses openssl libraries for some operations. Not sure if that changes the necessity to install the intermediate certificates manually. I will try to test that.
by mikedibella
2017-12-06 19:34
Forum: User-submitted tutorials
Topic: HOW TO: get gMail certificates to validate
Replies: 11
Views: 3689

Re: HOW TO: get gMail certificates to validate

I checked both gmail SMTP interfaces referenced in the OP and confirmed they are both correctly configured to send a complete chain.

https://www.sslshopper.com/ssl-checker. ... il.com:465
https://www.sslshopper.com/ssl-checker. ... il.com:465
by mikedibella
2017-12-06 19:28
Forum: User-submitted tutorials
Topic: HOW TO: get gMail certificates to validate
Replies: 11
Views: 3689

Re: HOW TO: get gMail certificates to validate

Couple of comments on this issue. First, only the root certificates should need to be installed into the Trusted Root Certification Authorities certificate store on the Window host running hMailServer. Gmail SSL/TLS interfaces should send to the connecting client a certificate chain during the Serve...
by mikedibella
2017-12-02 03:33
Forum: User contributed hMailServer 5 scripts
Topic: SETTINGS DIAGNOSTIC REPORT
Replies: 106
Views: 21143

Re: SETTINGS DIAGNOSTIC REPORT

Know that my efforts here are always good faith attempts to uphold the spirit of "community supported." I really appreciate the value I get from hMailServer and want to pay it forward...
by mikedibella
2017-12-02 03:22
Forum: User contributed hMailServer 5 scripts
Topic: SETTINGS DIAGNOSTIC REPORT
Replies: 106
Views: 21143

Re: SETTINGS DIAGNOSTIC REPORT

Oh and do you magic with hiding domain names on the certificate names and disk storage locations please... That's how I got the certificate file from the other case. If you don't intend for that to be possible, you should to obfuscate the both the file name and the subject of the certificate since ...
by mikedibella
2017-12-02 02:51
Forum: General discussions
Topic: ssmtp problem with joomla
Replies: 36
Views: 2838

Re: ssmtp problem with joomla

Only the key is sensitive. The certificate and chain is public data, exported from the published interface.
by mikedibella
2017-12-02 02:17
Forum: General discussions
Topic: ssmtp problem with joomla
Replies: 36
Views: 2838

Re: ssmtp problem with joomla

Here is the corrected certificate file.
by mikedibella
2017-12-02 01:53
Forum: General discussions
Topic: ssmtp problem with joomla
Replies: 36
Views: 2838

Re: ssmtp problem with joomla

Please check your configuration after making changes...

https://www.sslshopper.com/ssl-checker. ... iwm.gr:465 still shows an error in your config.

You will need to restart the hMailServer service after editing the file.
by mikedibella
2017-12-02 01:50
Forum: General discussions
Topic: ssmtp problem with joomla
Replies: 36
Views: 2838

Re: ssmtp problem with joomla

TLS or StartTLS (these are the same thing, just a naming variation) Respectfully disagree. I am talking about the Joomla-side configuration, and I believe setting SMTP security to TLS will cause the PHP mailer to initiate and SMTP connections over SSL/TLS and fail if secure channel cannot be negoti...
by mikedibella
2017-12-02 01:21
Forum: General discussions
Topic: ssmtp problem with joomla
Replies: 36
Views: 2838

Re: ssmtp problem with joomla

Your hMailServer host is semlab.teiwm.gr? Does your Joomla server validate certificate chains? When I query semlab.teiwm.gr using openssl (openssl.exe s_client -connect semlab.teiwm.gr:465 -showcerts), your hMailServer is sending only the leaf certificate (CN = semlab.teiwm.gr). You need the hMailSe...
by mikedibella
2017-12-01 23:13
Forum: General discussions
Topic: ssmtp problem with joomla
Replies: 36
Views: 2838

Re: ssmtp problem with joomla

In your original post you said you were using port 587. If there is an option under SMTP security for "StartTLS" you need to change to that to use port 587, otherwise use port 465. The way to have configured now, port 465 using TLS, should be correct.
by mikedibella
2017-12-01 23:01
Forum: General discussions
Topic: ssmtp problem with joomla
Replies: 36
Views: 2838

Re: ssmtp problem with joomla

You have port 587 configured for StartTLS, not SSL/TLS. How do you have SMTP security configured in Joomla, StartTLS or SSL/TLS?
by mikedibella
2017-10-27 00:59
Forum: Development & alpha discussions
Topic: Sub OnHELO(oClient) progress?
Replies: 122
Views: 26393

Re: Sub OnHELO(oClient) progress?

I think you will need to find some usable terminal condition to cause an exit from the loop, because if you get into the loop in a state where the .Save fails, you you will loop endlessly and that is probably what is cause the behavior you are seeing.
by mikedibella
2017-10-26 23:53
Forum: Development & alpha discussions
Topic: Sub OnHELO(oClient) progress?
Replies: 122
Views: 26393

Re: Sub OnHELO(oClient) progress?

If you assume you are entering the race condition because the .Save fails due to the presence of a duplicate Autoban entry created on a different thread, wouldn't you see that entry in the database when you restart the service? If the .Save is failing because a duplicate exists, you need to catch th...
by mikedibella
2017-10-18 01:46
Forum: Off-topic discussions
Topic: WIfi is broken
Replies: 2
Views: 892

Re: WIfi is broken

Both client and access point must be vulnerable for the exploit to work. Current Microsoft OS have been patch with October security cycle: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-13080 Apple has said patches are in beta. https://twitter.com/reneritchie/status/9199...
by mikedibella
2017-10-17 22:10
Forum: General discussions
Topic: Can't open more than two SMTP sessions from email client
Replies: 4
Views: 505

Re: Can't open more than two SMTP sessions from email client

Could this be the culprit? "The SmtpClient class implementation pools SMTP connections so that it can avoid the overhead of re-establishing a connection for every message to the same server. An application may re-use the same SmtpClient object to send many different emails to the same SMTP server an...
by mikedibella
2017-09-22 17:32
Forum: General discussions
Topic: Error "The property VerifyRemoteSslCertificate could not be found." on 5.6.6
Replies: 6
Views: 728

Re: Error "The property VerifyRemoteSslCertificate could not be found." on 5.6.6

Starting in build 2132 https://www.hmailserver.com/changelog?page=changelog&version=5.6&build=2132 , there is a UI check box to control certificate validation. Try toggling the setting and saving, then toggle again if necessary to restore the state you want. My hypothesis is that the error is caused...
by mikedibella
2017-07-21 01:53
Forum: General discussions
Topic: Filter IP address out of logs
Replies: 14
Views: 1860

Re: Filter IP address out of logs

Either of these help?

Using remote SMB mount in linux:

tail -f /mount-point/hmailserver_XXX.log | grep -v "192.168.1."

Using Powershell:

Get-Content hmailserver_XXX.log -wait | Select-String -pattern "192.168.1." -notmatch
by mikedibella
2017-07-10 19:18
Forum: General discussions
Topic: hmailserver sends emails on wrong IP
Replies: 4
Views: 658

Re: hmailserver sends emails on wrong IP

On a multihomed machine, the stack is going to pick the interface with the lowest metric having a route to a network containing the destination. In your configuration, you should have a default gateway on only one interface, and optionally static routes on the the other two. If the destination match...