Start a conversation

Articles

Best-practices for securing Kerio Connect, SSL certificate queries

  • Re-Issuing SSL Certificates in Kerio Connect

    Overview At times, administrators may have issues renewing the SSL certificate using a new CRT file provided by the Certification Authority (CA). This article shares the process of re-issuing the SSL ...

  • Installing Intermediate SSL certificates

    Overview If your Certification Authority (CA) provides additional files with a .crt extension, also known as intermediate certificates, you can install them into Kerio Connect separately from the main...

  • Changing SSL/TLS Configuration

    Overview Kerio Connect supports configuration of SSL/TLS behavior via GUI (from version 9.4 onward) or via its mailserver.cfg file (for older and current versions). One important capability is enforci...

  • Configuring SSL and TLS Variables in Kerio Connect

    Overview While performing SSL protocol security scans, the SMTP and email Encryption settings can be modified using mailserver.cfg file. The file allows configuring Server, Client TLS protocols, custo...

  • Configuring Anti-Spoofing in Kerio Connect

    Overview Spammers can spoof email addresses and send messages that appear as if they are sent from legitimate email addresses. To prevent this, users can configure and enable anti-spoofing in Kerio Co...

  • Importing Renewed SSL Certificates into Kerio Connect

    Overview If you have renewed your expired SSL certificate with your certificate provider and received a .crt file, you must import the renewed certificate into Kerio Connect. This article provides the...

  • Resetting Kerio Connect SSL/TLS Configuration

    Overview Kerio Connect uses different variables for the SSL/TLS protocols configuration. You can reset the current SSL/TLS configuration to the default settings at any time if needed. Note: This proce...

  • Clickjacking vulnerability in Kerio Connect 8 and 9 (CVE-2017-7440)

    Answer Overview The reported vulnerability is a Clickjacking vulnerability and is present in the email preview feature of Kerio Connect version 8 and version 9. The vulnerability is a risk to users th...

  • Installing .pfx certificate

    Overview Some Certification Authorities, such as DigiCert, may generate a .pfx file containing a private SSL certificate key. In such scenarios, you need to convert the file to a suitable format (.crt...

  • Error with Renewing Let's Encrypt SSL Certificate in Kerio Connect versions before 9.4

    Overview When renewing the Let's Encrypt SSL certificate using the./certbot-auto renew command, below errors are seen: All renewal attempts failed. The following certs could not be renewed:/etc/letsen...