<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<!-- Start of secure.htm --><!-- delayed after doctype-->
<html>
<head>
<link rel="stylesheet" type="text/css" href="../../css2/netwin.css">
	<script type="text/javascript" src="template/js2/netwin.js"></script>
<!--
	<script type="text/javascript" src="template/js2/dbg.js"></script>
-->

<!--
	<link rel="stylesheet" type="text/css" href="template/css2/netwin.css">

	<link rel="stylesheet" type="text/css" href="template/css2/test.css">
	<link rel="stylesheet" type="text/css" href="template/css2/sw.css">
	<link id ="cnr_css" rel="stylesheet" type="text/css" href="template/css2/cnr4.css">
-->

<!--[if lt IE 7]>
	<link rel="stylesheet" href="template/css2/ie6.css" type="text/css" />
<![endif]-->


<!-- Back to secure.htm -->

<!-- #BeginEditable "Headerstuff"-->
<title>Securing SurgeMail</title>
<META NAME="keywords" CONTENT="">
<META NAME="description" CONTENT="">
<meta http-equiv="Content-Type" content="text/html;">


<!-- #EndEditable -->
</head>
<body class="s_body">


<div id="width_limit_div" class="width_limit" style="padding-bottom:0;">

<!-- HEADER CONTENT -->
<div class="header">
  <div class="search_box"><table valign="center" cellSpacing="0" cellPadding="0" border="0">
	<form id="form1" name="form1" method="GET" action="http://www.google.com/custom">

	  <input type=hidden name=domains id=search_domains value="netwinsite.com">
	  <input type=hidden name=sitesearch id=search_sitesearch value="netwinsite.com">
	  <input type=hidden name=cof VALUE="LW:135;L:http://www.netwinsite.com/img2/logo_med_onwhite.png;LH:44;AH:center;S:http://www.netwinsite.com;AWFID:773914251fd85055;">

	  <tr valign="center">
		<td valign="center" style="padding-right:5px;"><span id="search_description" style="font-family:Verdana,Arial,Helvetica; font-size:9pt; ">Search website:</span>
		</td>
		<td valign="center">
			<input size="15" maxLength="80" name="q" style="font-family: Tahoma, Arial; font-size: 8pt">
		</td>
		<td valign="center">
			<input TYPE="image" src="template/img2/search.gif" alt="Search Netwinsite.com!" Name="I1" style="width:17px;height:17px;margin-left:5px;border:0;">
		</td>
	  </tr>
	</form>
  </table></div>

  <div class="page_logo"><table valign="center" border="0" cellpadding="0" cellspacing="10" >
	  <tr>
		<td style="padding-left:20px;">
		  <a href=""><img border="0" src="template/img2/logo_med_onwhite.png" height="44px" vspace="5" id="main_logo"> </a>
		</td>
		<td>
		  <div style="padding-top:14px;">
			<span class="s_header_text">Advanced Server Software<span>
		  </div>
		</td>
	  </tr>
  </table></div>
</div>

<!-- MENU CONTENT -->
<div class="bar_padding" onmousemove="stopEvent(event);return false;">
	<div class="bar" style="text-align:center">
		<table id="page_menu" class="t menu" onmousemove="menu_handler(event);" style="margin:auto"><tr>
	<td valign=top><table class="top_item" mid="menu_home"><tr><td class="btn_l"><td class="btn_c"><a href="http://netwinsite.com/index.htm" class="pad">Home</a><td class="btn_r"></table>
	<td valign=top><table class="top_item" mid="menu_products"><tr><td class="btn_l"><td class="btn_c"><a href="http://netwinsite.com/products.htm" class="pad">Products</a><td class="btn_r"></table>
	<td valign=top><table class="top_item" mid="menu_download"><tr><td class="btn_l"><td class="btn_c"><a href="http://netwinsite.com/download.htm" class="pad">Download</a><td class="btn_r"></table>
	<td valign=top><table class="top_item" mid="menu_buy"><tr><td class="btn_l"><td class="btn_c"><a href="http://netwinsite.com/prices.htm" class="pad">Buy&nbsp;Now</a><td class="btn_r"></table>
	<td valign=top><table class="top_item" mid="menu_support"><tr><td class="btn_l"><td class="btn_c"><a href="http://netwinsite.com/support.htm" onmouseup="x()" class="pad">Support</a><td class="btn_r"></table>
	<td valign=top><table class="top_item" mid="menu_company"><tr><td class="btn_l"><td class="btn_c"><a href="http://netwinsite.com/company.htm" onmouseup="x()" class="pad">Company</a><td class="btn_r"></table>
		</table>
	</div>

	<div id="menu_home" class="xmenu hidden" onmouseup="menu_hide_ex(event,'menu_home')" onmouseout="menu_action_mouseout(event,'menu_home')" onmouseover="menu_action_mouseover(event,'menu_home')" style="width:220px; display:none;">
	</div>

	<div id="menu_products" class="xmenu hidden" onmouseup="menu_hide_ex(event,'menu_products')" onmouseout="menu_action_mouseout(event,'menu_products')" onmouseover="menu_action_mouseover(event,'menu_products')" style="width:220px;">
		<a href="http://netwinsite.com/surgemail/" class="menu_row pad2"><div class="menu_icon_surgemail"></div>
			SurgeMail<span class="menu_extra"></span><br><span class="menu_info">Fully featured email server </span></a>
		<a href="http://netwinsite.com/surgeftp/" onmouseup="x()" class="menu_row pad2 divider"><div class="menu_icon_surgeftp"></div>
			SurgeFTP<span class="menu_extra"></span><br><span class="menu_info">High performance FTP server </span></a>
		<a href="http://netwinsite.com/dbabble/index.html" onmouseup="x()" class="menu_row pad2"><div class="menu_icon_dbabble"></div>
			DBabble <span class="menu_extra"></span><br><span class="menu_info">Instant messenging server </span></a>
		<a href="http://netwinsite.com/surgeweb/" onmouseup="x()" class="menu_row pad2 divider"><div class="menu_icon_surgeweb"></div>
			SurgeWeb<br><span class="menu_info">Modern Ajax web email client</span></a>
		<a href="http://netwinsite.com/products.htm" onmouseup="x()" class="menu_row divider">
			All products...</a>
	</div>

	<div id="menu_download" class="xmenu hidden" onmouseup="menu_hide_ex(event,'menu_download')" onmouseout="menu_action_mouseout(event,'menu_download')" onmouseover="menu_action_mouseover(event,'menu_download')" style="width:220px">
		<a href="/cgi-bin/keycgi.exe?cmd=download&product=surgemail&" onmouseup="x()" class="menu_row"><div class="menu_icon_surgemail"></div>
			Surgemail<span class="menu_extra"></span></a>
		<a href="/cgi-bin/keycgi.exe?cmd=download&product=surgeftp&" onmouseup="x()" class="menu_row"><div class="menu_icon_surgeftp"></div>
			SurgeFTP<span class="menu_extra"></span></a>
		<a href="http://netwinsite.com/dbabble/download.htm" onmouseup="x()" class="menu_row"><div class="menu_icon_dbabble"></div>
			DBabble <span class="menu_extra"></span></a>
		<a href="/cgi-bin/keycgi.exe?cmd=download&product=surgemail&" onmouseup="x()" class="menu_row divider"><div class="menu_icon_surgeweb"></div>
			SurgeWeb</a>
		<a href="http://netwinsite.com/surgemail/help/install.htm" onmouseup="x()" class="menu_row">
			Installing Surgemail</a>
		<a href="http://netwinsite.com/download.htm" onmouseup="x()" class="menu_row">
			Download any product...</a>
	</div>

	<div id="menu_buy" class="xmenu hidden" onmouseup="menu_hide_ex(event,'menu_buy')" onmouseout="menu_action_mouseout(event,'menu_buy')" onmouseover="menu_action_mouseover(event,'menu_buy')" style="width:220px">
		<a href="http://netwinsite.com/prices.htm" onmouseup="x()" class="menu_row divider">
			Pricing</a>
		<a href="http://netwinsite.com/https://netwinsite.com/cgi-bin/keycgi.exe?cmd=buy_new&product=surgemail" onmouseup="x()" class="menu_row"><div class="menu_icon_surgemail"></div>
			Surgemail<span class="menu_extra"></span></a>
		<a href="http://netwinsite.com/https://netwinsite.com/cgi-bin/keycgi.exe?cmd=buy_new&product=surgeftp" onmouseup="x()" class="menu_row"><div class="menu_icon_surgeftp"></div>
			SurgeFTP<span class="menu_extra"></span></a>
		<a href="http://netwinsite.com/https://netwinsite.com/cgi-bin/keycgi.exe?cmd=buy_new&product=dbabble" onmouseup="x()" class="menu_row"><div class="menu_icon_dbabble"></div>
			DBabble <span class="menu_extra"></span></a>
		<a href="http://netwinsite.com/https://netwinsite.com/cgi-bin/keycgi.exe?cmd=buy_new&product=surgemail" onmouseup="x()" class="menu_row divider"><div class="menu_icon_surgeweb"></div>
			SurgeWeb</a>
		<a href="http://netwinsite.com/activate.htm" onmouseup="x()" class="menu_row">
			Activation guide</a>
		<a href="http://netwinsite.com/prices.htm" onmouseup="x()" class="menu_row">
			Purchase any product...</a>
	</div>

	<div id="menu_support" class="xmenu hidden" onmouseup="menu_hide_ex(event,'menu_support')" onmouseout="menu_action_mouseout(event,'menu_support')" onmouseover="menu_action_mouseover(event,'menu_support')" style="width:220px">
		<a href="http://netwinsite.com/documentation.htm" onmouseup="x()" class="menu_row divider">
			Online documentation<span class="menu_extra"></span></a>
		<a href="http://netwinsite.com/surgemail/post.htm" onmouseup="x()" class="menu_row">
			Contact support<span class="menu_extra"></span></a>
		<a href="http://netwinsite.com/support.htm#email_list" onmouseup="x()" class="menu_row">
			Standard email support<span class="menu_extra"></span></a>
		<a href="http://netwinsite.com/http://news.netwinsite.com:8119/webnews?group=netwin.surgemail&cmd=list" onmouseup="x()"  class="menu_row divider">
			Community forum <span class="menu_extra"></span></a>
		<a href="http://netwinsite.com/support.htm" onmouseup="x()" class="menu_row">
			Support overview...</a>
	</div>

	<div id="menu_company" class="xmenu hidden" onmouseup="menu_hide_ex(event,'menu_company')" onmouseout="menu_action_mouseout(event,'menu_company')" onmouseover="menu_action_mouseover(event,'menu_company')" style="width:220px">
		<a href="http://netwinsite.com/company.htm" onmouseup="x()" class="menu_row">
			About us<span class="menu_extra"></span></a>
		<a href="http://netwinsite.com/surgemail/customers.htm" onmouseup="x()" class="menu_row">
			Customers<span class="menu_extra"></span></a>
		<a href="http://netwinsite.com/support.htm#sales_questions" onmouseup="x()" class="menu_row divider">
			Contact us</a>
	</div>
	<div style="background:url(template/img2/white_small.png);height:8px;font-size:1px;"></div>
</div>
<!-- Back to secure.htm -->

<div class="content_outer">


<!-- Back to secure.htm -->
<div class="L2C2_column_left">
<!-- Back to secure.htm -->
<div style="width:160px;">
  <div id="floating_index" class="floating_index nav-menu _document_index" style="width:160px;">
	<h2 class="menu_top">Help Index</h2>
	<ul class="level-0">

		<li class="group_hidden"><a href="#" onclick="index_toggle(event)">Getting Started</a><ul class="level-1">
			<li id="idx_surgemail.htm"><a href="surgemail.htm" target="_top">SurgeMail in a nutshell</a><ul class="level-2"></ul></li>
			<li id="idx_startingoff.htm"><a href="startingoff.htm" target="_top">Before you install</a><ul></ul></li>
			<li id="idx_install.htm"><a href="install.htm" target="_top">Installation &amp; Upgrading</a><ul></ul></li>
			<li id="idx_migration.htm"><a href="migration.htm" target="_top">Migration to SurgeMail</a><ul></ul></li>
			<li id="idx_updates.htm"><a href="updates.htm" target="_top">Change history</a><ul></ul></li>
			<li id="idx_postinstall.htm"><a href="postinstall.htm" target="_top">Post Installation</a><ul></ul></li>
			<li id="idx_faq.htm"><a href="faq.htm" target="_top">FAQ</a><ul></ul></li>
			<li id="idx_support.htm"><a href="support.htm" target="_top">Customer Support</a><ul></ul></li>
		</ul></li>

		<li class="group_hidden"><a href="#" onclick="index_toggle(event)">Anti Spam / Virus</a><ul class="level-1">
			<li id="idx_protected.htm"><a href="protected.htm#virusscanner">Virus Protection</a></li>
			<li id="idx_spam.htm"><a href="spam.htm">Spam Prevention</a></li>
			<li id="idx_protected.htm"><a href="protected.htm#mfilter">Mail Filtering</a> </li>
			<li id="idx_protected.htm"><a href="protected.htm#friends">Friendly Relations System</a></li>
			<li id="idx_rbl.htm"><a href="rbl.htm">Realtime Blackhole Lists</a></li>
		</ul></li>

		<li class="group_hidden"><a href="#" onclick="index_toggle(event)">Server Management </a><ul class="level-1">
			<li id="idx_status.htm"><a href="status.htm">Server Status</a></li>
			<li id="idx_log.htm"><a href="log.htm">Searching the log files</a></li>
			<li id="idx_report.htm"><a href="report.htm">Report generation</a></li>
			<li id="idx_accounts.htm"><a href="accounts.htm">Managing accounts</a></li>
			<li id="idx_tellmail.htm"><a href="tellmail.htm">Using the tellmail utility.</a></li>
		</ul></li>
		
		<li class="group_hidden"><a href="#" onclick="index_toggle(event)">SurgeMail Settings</a><ul class="level-1">
			<li id="idx_domain.htm"><a href="domain.htm">Domain specific settings</a></li>
			<li id="idx_global.htm"><a href="global.htm">Global settings</a></li>
			<li id="idx_webmail.htm"><a href="webmail.htm">WebMail settings</a></li>
		</ul></li>

		<li class="group_hidden"><a href="#" onclick="index_toggle(event)">Configuration Guides</a><ul class="level-1">
			<li id="idx_authent.htm"><a href="authent.htm">Authentication  Modules</a></li>
			<li id="idx_domains.htm"><a href="domains.htm">Virtual  Domains</a></li>
			<li id="idx_clustering.htm"><a href="clustering.htm">Clustering</a></li>
			<li id="idx_mirror.htm"><a href="mirror.htm">Mirror the server</a></li>
			<li id="idx_scalable.htm"><a href="scalable.htm">Performance &amp; Scalability</a></li>
			<li id="idx_lookandfeel.htm"><a href="lookandfeel.htm">Custom look and feel</a></li>
			<li id="idx_internal_email.htm"><a href="internal_email.htm">Custom internal emails </a></li>
			<li id="idx_language.htm"><a href="language.htm">Language translation</a></li>
			<li id="idx_redirection.htm"><a href="redirection.htm">Mail Redirection</a></li>
			<li id="idx_surgewall.htm"><a href="surgewall.htm">SurgeWall</a></li>
			<li id="idx_sms.htm"><a href="sms.htm">SMS</a></li>
			<li id="idx_lists.htm"><a href="lists.htm">Mailing lists and bulletins</a></li>
			<li id="idx_secure.htm"><a href="secure.htm">Securing the server</a></li>
			<li id="idx_webdav.htm"><a href="webdav.htm">WebDav</a></li>
			<li id="idx_incoming.htm"><a href="incoming.htm">Incoming MX servers</a></li>
			<li id="idx_load_balance.htm"><a href="load_balance.htm">Load balancing</a></li>
			<li id="idx_ndb.htm"><a href="ndb.htm">NDB NetWin folder format</a></li>
			<li id="idx_domainkeys.htm"><a href="domainkeys.htm">DomainKeys Support</a></li>
			<li id="idx_ipv6.htm"><a href="ipv6.htm">IPV6 Support</a></li>
			<li id="idx_amazon-ses.htm"><a href="amazon-ses.htm">Amazon-SES gateway</a></li>
			<li id="idx_examples.htm"><a href="examples.htm">Example configurations</a></li>
		</ul></li>
	</ul>
  </div>
  &nbsp;	<!-- required to render div -->
</div>
<script>window.do_scroll_menu=false</script>
<!-- Back to secure.htm -->
</div>

<!-- Back to secure.htm -->

<div class="L2C2_column_content">
<!-- Back to secure.htm -->
<!-- #BeginEditable "Body" -->

  <script language="JavaScript"> search_details('Search SurgeMail Manual:','http://netwinsite.com/surgemail/help'); </script>
  <script language="JavaScript"> display_crumbs_doc(['Home','Documentation','SurgeMail Help Index','Securing the Server'],3); </script>
  <script language="JavaScript"> index_select('idx_secure.htm'); </script>

  <h1>Securing the Server</h1>

<ul>
  <li><font face="Arial, Helvetica, sans-serif"><a href="secure.htm">SurgeMail
    SSL / TLS support</a> </font></li>
  <li><font face="Arial, Helvetica, sans-serif"><a href="#access">Restricting
    Access by IP Number</a></font></li>
  <li><font face="Arial, Helvetica, sans-serif"><a href="#access">Relay restrictions</a></font></li>
  <li><font face="Arial, Helvetica, sans-serif"><a href="#services">Restricting
    mail services per user</a></font></li>
  <li><font face="Arial, Helvetica, sans-serif"><a href="#cram">CRAM-MD5</a></font></li>
</ul>

  <h2><a name="SSLTLS"></a>SurgeMail SSL / TLS support</h2>
  <p><font face="Arial, Helvetica, sans-serif">SSL is fully supported on all protocols
    to ensure username and password are safely encrypted when sent over the internet
    so that they can't be stolen 'on the way past'. If you are running a mail
    server that doesn't support this feature then essentially anyone with access
    to your network can steal passwords. Almost all popular email clients now
    support SSL/TLS. Data is also encrypted, however be aware that when sending
    mail to other mail systems the data will be unencrypted on the journey, so
    only local Email is fully secure.</font></p>
  <blockquote>
    <p><font face="Arial, Helvetica, sans-serif"><b>POP: </b>Secure to regular
      port using STARTTLS, secure to dedicated port.</font></p>
    <p><font face="Arial, Helvetica, sans-serif"><b>SMTP: </b>Secure to regular
      port using STARTTLS</font></p>
    <p><font face="Arial, Helvetica, sans-serif"><b>HTTPS: </b>All web based administration
      tasks can be done either using secure HTTPS or standard HTTP.</font></p>
    <p><font face="Arial, Helvetica, sans-serif"><b>Mirrorring:</b> The in-built
      server mirrorring feature mirrors the server over a secure link.</font></p>
  </blockquote>

  <p>SurgeMail SSL/TLS Frequently Asked Questions</p>
  <ul>
    <li><font face="Arial, Helvetica, sans-serif"><a href="#what">What is SSL/TLS?</a></font></li>
    <li><font face="Arial, Helvetica, sans-serif"><a href="#ca">How to generate
      a Certification Signing Request to get a CA signed key</a></font></li>
  </ul>
  <font face="Comic Sans MS">
  <h3><a name="what"></a>What is SSL/TLS and how secure is it?</h3>
  </font>
  <p><font face="Arial, Helvetica, sans-serif">SSL/TLS is the same encryption
    system used by 'https' web pages. It is generally considered to be the most
    secure method for sending sensitive information across the internet, and is
    the basis of most ECommerce security systems used today. </font></p>
  <p><font face="Arial, Helvetica, sans-serif">You will need a server private
    key (do not give this to anyone) and a matching Certificate which the server
    sends to the clients upon SSL handshake. The intermediate step is the Certificate
    Signing Request (CSR). This is generated from your private key and used to
    generate the certificate.</font><font face="Comic Sans MS"> </font></p>

  <h3><a name="ca"></a>How to generate a Certification Signing Request to get a CA signed key</h3>
  <p><font face="Arial, Helvetica, sans-serif">SurgeMail automatically generates
    untrusted certificates when required. For high level security you should consider
    getting your own trusted server certificate. This means that clients can be
    sure that they are talking to 'your' server and not just someone pretending
    to be your server and means that warning messages do not get displayed when
    connected using a browser or mail client attempting to use secure connections.</font></p>
  <p><font face="Arial, Helvetica, sans-serif">CSR generation is now built in
    to the surgemail. Simply go to the &quot; SSL Certificates Configure&quot;
    link on the globals page of the web admin. From here you can check the state
    of the current certificates for your domains and create a CSR and update SurgeMail
    with your signed key. Press the New CSR button to generate a new private key
    and matching CSR and untrusted certificate. Copy the CSR text and send this
    to your certification authority. You should be sent back a signed certificate
    to replace the automatically generated certificate - just paste this in the
    SSL Certificate(s) pane and press save. You will need to restart SurgeMail
    to get SurgeMail to use the new certificate.</font></p>
  <p><font face="Arial, Helvetica, sans-serif">Some certifying authorities issue
    trusted certificates based on a trust chain that involves an intermediate
    certificate. It you are required to install an intermediate certificate by
    your signing authority you can just place this in the surge_cert.pem file
    as follows (SurgeMail 1.5e+):</font></p>
  <p>
  <pre>
    &lt;begin surge_cert.pem file&gt;
    # Issued certificate for yourdomain.com
    -----BEGIN CERTIFICATE-----
    MIIFZjCCBE6gAwIBAgIQS288jS2Kir5dBc5Br8QMlTANBgkqhkiG9w0BAQUFADCB
    ....
    czNTZWN1cml0eVNlcnZpY2VzXzIuY3JsMDqgOKA2hjRodHRwOi8vY3JsLmNvbW9k
    Q/az601d5VnPDDz8kpNduHp4cWpVu9x3byRqWbm+UiaYRtANl/nhk9xx
    -----END CERTIFICATE-----

	# Certifying authority intermediate certificate(s)
    -----BEGIN CERTIFICATE-----
    MIIEyDCCBDGgAwIBAgIEAgACmzANBgkqhkiG9w0BAQUFADBFMQswCQYDVQQGEwJV
    ...
    BBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMEYGA1UdIAQ/MD0wOwYMKwYBBAGyMQEC
    vA2AOurM+5pX7XilNj1W6tHndMo0w8+xUengDA==
    -----END CERTIFICATE-----
    &lt;end file&gt;
</pre>
  <p><font face="Arial, Helvetica, sans-serif">Some certification authorities
    you could use are:</font></p>
  <blockquote>
    <p><font face="Arial, Helvetica, sans-serif"><a href="http://www.digicert.com">
      DigiCert (www.digicert.com)<br>
      </a></font><font face="Arial, Helvetica, sans-serif"><a href="http://www.comodogroup.com/">http://www.comodogroup.com/</a>
      <br>
      <a href="http://www.abaecom.com/"> </a><a href="http://www.verisign.com/">http://www.verisign.com/</a>
      <br>
      <a href="http://www.abaecom.com/"> </a><a href="http://www.thawte.com/">http://www.thawte.com/</a><br>
      <a href="http://www.valicert.com/"> </a><a href="http://www.entrust.net/">http://www.entrust.net/</a><br>
      <a href="http://www.digsigtrust.com/"> </a><a href="http://www.e-certify.com/">http://www.e-certify.com/</a><br>
      <a href="http://www.entrust.net/"> </a><a href="http://www.equifax.com/"></a><a href="http://www.digsigtrust.com/">http://www.digsigtrust.com/</a><br>
      <a href="http://www.globalsign.com/"> http://www.globalsign.com/</a><br>
      <a href="http://www.tc-trustcenter.com/"> http://www.tc-trustcenter.com/</a><br>
      <a href="http://www.thawte.com/"> </a><a href="http://www.valicert.com/">http://www.valicert.com/</a>
      </font></p>
    </blockquote>
  <p><font face="Arial, Helvetica, sans-serif">As an alternative you can manually
    generate the the same files using the openSSL binary (not distributed with
    SurgeMail ):</font></p>
  <blockquote>
    <p> openssl req -new -nodes -keyout surge_priv.pem -out surge_csr.pem</p>
  </blockquote>


  <p><font face="Arial, Helvetica, sans-serif"><b>WARNING</b>: If using GoDaddy certificates,
  be aware of a reported naming convention clash. To get your intermediate certificate you will want to
  download the "bundle" and not the "intermediate certificate".</font></p>


  <h2 align="left"><a name="access"></a>Restricting Access by IP Number</h2>
  <p><font face="Arial, Helvetica, sans-serif">Many of SurgeMails features can
    be restricted to certain IP number ranges. This can be used to make the system
    more secure.</font></p>
  <p><font face="Arial, Helvetica, sans-serif">One feature that is that should
    probably be restricted is the <a href="global.htm#g_admin_ip">g_admin_ip</a>
    setting to limit the valid IP addresses for SurgeMail server admin users.
    </font></p>
  <p><font face="Arial, Helvetica, sans-serif">You should also look into the following
    settings that control which connections will use SSL:</font></p>
  <ul>
    <li><font face="Arial, Helvetica, sans-serif"><a href="global.htm#g_ssl_allow">g_ssl_allow</a>
      - connections to allow to SSL use</font></li>
    <li><font face="Arial, Helvetica, sans-serif"><a href="global.htm#g_ssl_require">g_ssl_require</a>
      - connections to allow to require SSL use</font></li>
    <li><font face="Arial, Helvetica, sans-serif"><a href="global.htm#g_ssl_require_out">g_ssl_require_out</a>
      - outbound connections requiring SSL use</font></li>
  </ul>

  <h2><a name="relay"></a>Relay restrictions</h2>
  <p><font face="Arial, Helvetica, sans-serif">It is important to ensure that
    your system is not setup as an &quot;open relay&quot;, as this is likely to
    result in spam being sent through your system and your mail server getting
    black listed by open relay databases.</font></p>
  <p><font face="Arial, Helvetica, sans-serif">SurgeMail &quot;out of the box&quot;
    is configured to not relay other than <a href="global.htm#g_relay_window">allow
    relay after POP login</a> which, in general is safe and allows people using
    old mail clients (that do not know how to do SMTP authentication) to still
    send through your server without making your server an open relay.</font></p>
  <p><font face="Arial, Helvetica, sans-serif">A setting you may want to enable
    is <a href="global.htm#g_relay_allow_ip">g_relay_allow_ip</a> for your mailserver's
    own IP address as this will enable other programs running on the system to
    send mail without needing to use SMTP authentication. Do not set this to *
    as this will make your system an open relay.</font></p>
  <p><font face="Arial, Helvetica, sans-serif">Other ways of enabling relaying
    is by destination domain (<a href="global.htm#g_relay_to">g_relay_to</a>)
    or known from address (<a href="global.htm#g_relay_allow_from">g_relay_allow_from</a>).</font></p>

  <h2><a name="services"></a>Restricting mail services per user</h2>
  <p><font face="Arial, Helvetica, sans-serif">Groups can be setup with rights
    to access POP, IMAP or SMTP services that will allow per user setting of access
    privileges. See <a href="accounts.htm">managing accounts</a> for more information.</font></p>

  <h2><font face="Arial, Helvetica, sans-serif"><a name="cram"></a>CRAM-MD5</font></h2>
  <p><font face="Arial, Helvetica, sans-serif">SurgeMail supports CRAM-MD5 SMTP
    authentication, but ONLY when using the NWAuth authentication module. To enable
    CRAM-MD5 set the <a href="global.htm#g_smtp_cram_enable">g_smtp_cram_enable</a>
    setting and restart SurgeMail. </font></p>
  <p><font face="Arial, Helvetica, sans-serif">This setting will cause NWAuth
    to begin converting the stored passwords from their existing format into one
    that can be used for CRAM-MD5, as such users will have to login once to pop
    or imap before they can use CRAM-MD5.</font></p>
  <p><font face="Arial, Helvetica, sans-serif"><b>WARNING</b>: The stored CRAM-MD5
    passwords are not as secure as NWAuth's default SSHA passwords, they are only
    marginally more secure than plain text. A better solution to password security
    is to use <a href="secure.htm">SSL / TLS</a>.</font></p>

  <h2><a name="convert"></a> Certificate file format conversion</h2>
  <p>
This has not been explicitly tested but I header from a customer you can convert pfx certificates to pem using the following openssl command:


<pre>
openssl pkcs12 -in {something}.pfx -out {something}.pem -nodes
</pre>

<p>
If the certificate is protected by a password, you will be prompted for the password. Enter your password and the export is done.



<!-- #EndEditable -->
<!-- CONTENT END -->
</div>

<!-- Back to secure.htm -->
</div>

<!-- Back to secure.htm -->

<div class="prefooter">&nbsp;</div>
<div id="footer" class="footer">
 <table align="center" CELLPADDING="0" CELLSPACING="0" WIDTH="900" HEIGHT="100" BORDER="0" >
  <tr>
    <td HEIGHT="100%" >
      <p align="center" style="margin-top: 8pt; margin-bottom: 2pt; margin-left: 8pt">
  	  <a href="http://netwinsite.com/sitemap.htm" class="footer_link">Site Map</a><span class="style2"> | </span>
  	      <a href="http://netwinsite.com/index.htm" class="footer_link">Home</a><span class="style2"> | </span>
	      <a href="http://netwinsite.com/products.htm" class="footer_link">Products</a><span class="style2"> | </span>
	      <a href="http://netwinsite.com/surgemail/post.htm" class="footer_link">Contact Netwin</a><span class="style2"> | </span>
	      <a href="http://netwinsite.com/company.htm" class="footer_link">Company</a><span class="style2"> | </span>
	      <a href="http://netwinsite.com/license_all.htm" class="footer_link">Licensing</a><span class="style2"> | </span>
	      <a href="http://netwinsite.com/links.htm" class="footer_link">Links</a><span class="style2">  </span>
		<br>
		<a href="/surgemail/" class="footer_link">Windows Mail Server Software</a><span class="style2"> |  </span> 
		<a href="/webmail/" class="footer_link">Linux Webmail</a><span class="style2"> | </span> 
		<a href="/surgemail/free_mail_server.htm" class="footer_link">Free Windows Mail Server</a>

        <table align=center width="370" border="0" style="margin-bottom: 2pt">
        <tr>
          <td width="32"><img src="template/img2/logo_small_ongray.png" height="25" hspace="1" vspace="1" align="bottom"></td>
          <td width="350"><p class="smaller" style="margin-top: 14pt;">Copyright &copy; 2011 Netwin Ltd. All rights reserved.
		  </td>
        </tr>
      </table>
	</td>
  </tr>
</table>
</div>
</div>

<br><br>
</body>

<!-- Back to secure.htm -->

</body>
</html>

<!-- End of secure.htm -->

