Video Screencast Help
Search Video Help Close Back
to help

Exchange 2003, Brightmail and TLS

Created: 14 Sep 2012 | Updated: 18 Sep 2012 | 17 comments
Jun1or's picture
0 0 Votes
Login to vote
This issue has been solved. See solution.

Hello All

We have a request for inbound and outbound email encryption and our client uses TLS.

We have TWO exchang 2003 servers with one SMTP connector forwarding email traffic to Brightmail (192.168.55.10)

I have Created a second connector with TLS enabled and pointing to the Brightmail (192.168.55.10) for domain abc.com on cost 2, however the primary connector on exchange changes from active to retry? Any ideas?

We are not licensed for Content Encrytion on Brightmail and are not able to use this feature, is there a trial key and can download and use?

 

Thank You

Discussion Filed Under:

Comments 17 CommentsJump to latest comment

oykunsatis's picture

Hello,

First off all you need to accept mails from the second connector. If second connector have different ip then the first one,you need to enter it to Brightmail. (Administration/Configuration/SMTP/Outbound/Non-Local Mail Acceptance)

Second, if domain like you mentioned abc.com is not in the list of Brightmail domains,Brightmail will reject. So add the domain if not in the list.(Protocols/Domains)

Finally,you need to create a self-signed certificate or import a public certificate to Brightmail for sending and accepting emails with TLS.(Administration/Certificates)

After you created also you need select the certificate for inbound and outbound connections(Administration/Configuration/SMTP/Inbound|Outbound/Use TLS) 

And also there some other options about TLS under Administration/Configuration/SMTP/Advanced.

 

By the way please check Message Audit Logs to see what happened the messages from Brightmail side.

 

Regards,

Oykun

 

0
Login to vote
  • Actions
Jun1or's picture

The second connector has the same IP address and it forwarding to Brightmail.

the domain abc.com is in protocols>Domains

We have purchased a certificate from Global sign, do we need to apply this to brightmail? We don't have the content encryption license for Brightmail and that's why i am trying to configure Exchange 2003.

I assume if i have Content encryption license on Brightmail, i don't need to do anything on exchange?

0
Login to vote
  • Actions
oykunsatis's picture

Hello,

You can use TLS in Brightmail. Content Encryption is different thing and not related with TLS.

So you can use it in Brightmail if you don't need to start TLS from Exchange.

0
Login to vote
  • Actions
Jun1or's picture

I need a certificate for inbound, do i only purchase this for the domain i am going to send from (abc.com)?

0
Login to vote
  • Actions
Cricket17's picture

You buy one for the domain your scanner helo/ehlo's as.

So I have a certificate for smtp1.example.com which matches the MTA Hostname of smtp1.example.com under Admin, Config, SMTP, Advanced Settings.

Test will a self-signed certificate and look at http://www.checktls.com/  to validate.

0
Login to vote
  • Actions
Jun1or's picture

Thanks Cricket17.

We have 2 sets of MX record one for LIVE and ONE for DR.

Mail1.abc.com (Pointed to LIVE Scanner)

Mail2.abc.com (Points to DR Scanner)

Will I need one for Mail1.abc.com and one for Mail2.abc.com

0
Login to vote
  • Actions
TSE-JDavis's picture

Yes, each scanner needs a certificate that matches its hostname

+1
Login to vote
  • Actions
Jun1or's picture

I have now created a self signed Certificate and configured the scanner for TLS, however when run a test using checktls.com I see the attached (see attached screenshot), there are failures on the certificate, do all these need to be green for mail2.??

 

TLS.JPG
0
Login to vote
  • Actions
TSE-JDavis's picture

You don't want to perform TLS with a self-signed certificate. You need a certificate authority signed cert.

+1
Login to vote
  • Actions
Jun1or's picture

I have generated a csr from certificate>https/tls on brightmail, when I paste the csr in globalsign I receive an error

Key length error

What type of cert do I need? Domain SQL?

0
Login to vote
  • Actions
Jun1or's picture

I have generated a csr from certificate>https/tls on brightmail, when I paste the csr in globalsign I receive an error

Key length error

What type of cert do I need? Domain SSL?

do I need to configure anything on exchange?

Really appreciate your input guys

0
Login to vote
  • Actions
TSE-JDavis's picture

Just a plain old SSL cert

+1
Login to vote
  • Actions
oykunsatis's picture

By the way if you have a certificate for *.abc.com ,you can also use that.

 

Regards,

 

Oykun

0
Login to vote
  • Actions
Jun1or's picture

Thank you for your help on this guys.

I have now created a certficate and uploaded to the Scanner, however when i enable TLS in SMTP inbound and outbound no one in the organisation is able to send emails?

Seems like its trying to send all emails encrypted? I have checked the advanced options and try sending all emails TLS is not enabled/checked.

Please advise?

0
Login to vote
  • Actions
TSE-JDavis's picture

Are you running SMG version 10.0.0-6? If so, you need to upgrade to 10.0.0-7.

+1
Login to vote
  • Actions
Jun1or's picture

We are on Version 9.5.3.3

0
Login to vote
  • Actions
Jun1or's picture

Just in case someone has a similar issue.

After spending several hours trying to figure out why the SMTP connector was going to retry status in the end it was Symantec configuration. Logged a call with Symantec and one of the tech guys had a look but didn't have a clue.

So last night after creating an smtp connector in Exchange, enabling TLS none of this worked.

In Administrations>Configuration>Hostname>SMTP

) Even though i had TLS enabled on all THREE tabs (Inbound/Outbound/Authentication, i didn't enable 'Request Client Certificate and 'Request TLS Encryption'....now both enabled and no failures.

I used checktls.com to send an outbound email, this failed even though i had enabled TLS for the domain in Protocols>Domains

I created an inbound/outbound content policy

If text in From/To/Cc/Bcc Address part of the message contains 1 or more occurrences of "xyz.com"

Action: Attempt to deliver message with TLS encryption (Attempt TLS Encryption)

And this worked!

Thank you for your input.

SOLUTION
0
Login to vote
  • Actions