Email services. Anders Wiehe IT department Gjøvik University College



Similar documents
Exim4U. Server Solution For Unix And Linux Systems

Web. Anti- Spam. Disk. Mail DNS. Server. Backup

Advanced 100 GB storage space. Unlimited monthly bandwidth. Pro 150 GB storage space. Unlimited monthly bandwidth. Horde Squirrelmail Round Cube Mail

Hosted CanIt. Roaring Penguin Software Inc. 26 April 2011

If your response to any of the questions above was Yes, then SmarterMail Enterprise Edition may be right for you.

ECE Mail System Overview. Pablo J. Rebollo ECE Network Operations Center

A D M I N I S T R A T O R V 1. 0

Microsoft Exchange in the College of Engineering. Jerry Ciolkosz Senior Systems Analyst Electronic and Computing Services October 16, 2003

BUILT FOR YOU. Contents. Cloudmore Exchange

ORF ENTERPRISE EDITION 1. Getting the Most Out of ORF

The Leading Security Suites

How to Configure edgebox as an Server

Softnix Messaging Server (SMS)

. Service Option Description. Deltacom Product Management - updated 9/17/2007 1

Release Notes. for Kerio Connect 8.0.0

Guardian Digital Secure Mail Suite Quick Start Guide

Security. Help Documentation

POP3 Connector for Exchange - Configuration

Professional Edition vs. Enterprise Edition

Hosted Managed by Specialists

Alinto Mail Server Pro

A Modular Architecture Using Open Source Components

Configuring Your Gateman Server

debops.postfix documentation

Mail Services. Easy-to-manage Internet mail solutions featuring best-in-class open source technologies. Features

Personalised package Details

VPOP3 Your post office Getting Started Guide

Government of Canada Managed Security Service (GCMSS) Annex A-5: Statement of Work - Antispam

Ficha técnica de curso Código: IFCAD241

Domains Help Documentation This document was auto-created from web content and is subject to change at any time. Copyright (c) 2016 SmarterTools Inc.

AlwaysMail. Sector 5. Cloud

Policy Patrol 7 Upgrade Guide

Reliable & Secure . Professional, Dependable, Complete Easy to Learn, Use and Grow

Setup Local Mail Server Using Postfix, Dovecot And Squirrelmail On CentOS 6.5/6.4

Introduction. How does filtering work? What is the Quarantine? What is an End User Digest?

Implementing MDaemon as an Security Gateway to Exchange Server

Renewal of the Services

ESET Mail Security 4. User Guide. for Microsoft Exchange Server. Microsoft Windows 2000 / 2003 / 2008

suitability for groupware, and performance on powerful hardware. Axigen Mail Server

GRAYWALL. Introduction. Installing Graywall. Graylist Mercury/32 daemon Version 1.0.0

MDaemon configuration recommendations for dealing with spam related issues

MDaemon Vs. Microsoft Exchange Server 2013 Standard

Frequently Asked Questions for New Electric Mail Administrators 1 Domain Setup/Administration

Parallels Plesk Automation

quality hosting solution. we manage your hosting. so that you can manage your business.

AXIGEN Mail Server. Quick Installation and Configuration Guide. Product version: 6.1 Document version: 1.0

Collax Mail Server. Howto. This howto describes the setup of a Collax server as mail server.

Installing Policy Patrol with Lotus Domino

OpenSRS Service DNS Configuration Guide

Emergic. A Complete Messaging & Security Suite A COMPLETE MESSAGING AND SECURITY SUITE

Feature Comparison Guide

753 Broad Street Phone: Suite 200 Fax: Augusta, GA Copyrights

English Translation of SecurityGateway for Exchange/SMTP Servers

Cloud Firewall. 1. Introduction. a. What is Spam?

Training Guide eprism Security Appliance 4.0

Gateways Using MDaemon 6.0

Solutions IT Ltd Virus and Antispam filtering solutions

eprism Security Appliance 6.0 Intercept Anti-Spam Quick Start Guide

Comodo KoruMail Software Version 4.0

Using WinGate 6 . Concepts, Features, and Configurations.

HGC SUPERHUB HOSTED EXCHANGE / 2007 SMART PANEL USER GUIDE

602LAN SUITE 5.0 Groupware

Good Practice use of Outlook, Thunderbird and HORDE Webmail

XGENPLUS SECURITY FEATURES...

1 Accessing accounts on the Axxess Mail Server

Vodafone Hosted Services. Getting your . User guide

GREEN HOUSE DATA. Services Guide. Built right. Just for you. greenhousedata.com. Green House Data 340 Progress Circle Cheyenne, WY 82007

Quick-Start Guide

Djigzo encryption. Djigzo white paper

Linux Administrator (Advance)

EFFECTIVE SPAM FILTERING WITH MDAEMON

Mail system components. Electronic Mail MRA MUA MSA MAA. David Byers

Getting an ipath server running on Linux

DJIGZO ENCRYPTION. Djigzo white paper

Quick Start Policy Patrol Spam Filter 9

Architecture of a scalable mail system. Joel Jaeggli for PACNOG2 June 2006

Domain Name. Domain Registrar. Web Site cpanel URL: Username: Password: Username: Password:

Configuring MDaemon for Centralized Spam Blocking and Filtering

Migration Manual (For Outlook 2010)

Kerio MailServer 6. Administrator s Guide. Kerio Technologies

WHY USE ILLUMIN8 MARKETING FOR HOSTING YOUR WEB SITE?

Deployment Guides. Help Documentation

SuSE Solutions Based on

Spam Handling in Heterogeneous Environments

INSTALLATION AND CONFIGURATION GUIDE (THIS DOCUMENT RELATES TO MDAEMON v ONWARDS)

Configuring Outlook for IMAP. Creating a New IMAP Account. Modify an Existing Account

Web Hosting. CMS Development. Domain registrations. DNS Pointing. Website Publishing. SMB Starter Package. Static Website Development

Celframe - Easy Linux - Lesson 8 - Server

Parallels Plesk Automation

Start Thunderbird and follow its prompts to configure it for your Yale Central account.

User guide Business Internet features

HOSTED MICROSOFT EXCHANGE

How To Configure Forefront Threat Management Gateway (Forefront) For An Server

MailEnable Scalability White Paper Version 1.2

Help for System Administrators

Quick Start Policy Patrol Mail Security 9

anomaly, thus reported to our central servers.

Lesson Plans Configuring Exchange Server 2007

Simplicity Value Documentation 3.5/5 5/5 4.5/5 Functionality Performance Overall 4/5 4.5/5 86%

Transcription:

Email services Anders Wiehe IT department Gjøvik University College

Topics Lessons learnt Planning a new email system Lab: Basic configuration Lab: SMTP:Postfix configuration Lab: POP3/IMAP:Dovecot configuration Lab: Webmail:SquirrelMail Lab extra: LDAP:OpenLDAP The current email system at GUC The next generation email system at GUC

Lessons learnt Automatic routines! Account and address creation, communication with other systems Configure new users clients with the correct servers, email address and address lookup less support Sending and receiving available from everywhere - TLS and SMTP authentication (VPN)

Planning a new (large) email system SMTP/POP3/IMAP/Webmail Authentication, user information Availability Server side filtering Mailbox format Filesystem Quota Backup and restore

Lab: Basic configuration Two CentOS virtual machines will become two email systems tar zxf centos-sysadm.tar.gz into two different locations and power them on Set hostnames in /etc/hosts, for example: <ip> vincent.hig.no <ip> vic.hig.no Challenge: configure bind Add two users: vincent on vincent, and vic on vic

Lab: Postfix yum install postfix, service postfix start, chkconfig level 35 postfix on Take a look at /etc/postfix, especially /etc/postfix/main.cf inet_interfaces=all, smtp_host_lookup=native Challenge: configure to receive email for domains configured in bind Extra1: Address lookup via LDAP Extra2: Antispam Extra3: TLS and SMTP authentication, no open relays or unencrypted passwords!

Lab: Dovecot yum install dovecot (/etc/dovecot.conf) Extra1: TLS (s_client) Extra2: Various mailbox formats (Postfix, dbox?) Extra9: Features in version 1.0/1.1): Mailbox indexing while delivering Quota plugin Sieve: Mail filtering Mail forwarding Vacation

Lab: SquirrelMail yum install squirrelmail, service httpd start Point your browser to http://<server IP 1>/webmail/ and send email to the other email system,... Configuration is also possible: /etc/squirrelmail/config.php Extra1: Configure it Extra2: Look at the possibilities with plugins: address lookup, vacation, spam filtering, forward,...

Lab extra: OpenLDAP yum install openldap openldap-clients openldap-servers database bdb suffix "dc=hig,dc=no" rootdn "cn=manager,dc=hig,dc=no" rootpw <output from slappasswd> sizelimit unlimited ldapadd -x -D "cn=manager,dc=hig,dc=no" -W -f <file> LDAP Browser/Editor (Java, freshmeat.net)

The current email system at GUC Outgoing email Internet MX 4 ratbert ratbert.hig.no Outgoing email ratbert.hig.no: MX for hig.no pat.hig.no: Mailboxes and relay for employees studenter.hig.no: Mailboxes and relay for students studenter.hig.no pat.hig.no

ratbert.hig.no (I) Software: Linux, Postfix 2.1.5, ClamAV 0.88.2, MySQL 3.23.58 Hardware: 2x2,8Ghz Pentium 4, 1GB RAM, 18GB mail spool ~15000 emails or 800-1000MB per day All antispam methods run on ratbert Load < 0.1

ratbert.hig.no (II) Uses AD LDAP searches to determine if an address is valid and the delivery address: 001234@hig.no -> 001234@studenter.hig.no fornavn.ettern@hig.no -> 001234@studenter.hig.no Uses AD LDAP searches to determine group members: s-imt@hig.no -> 001234@studenter, 002345@studenter... This may be changed soon! Mailman (Local file and) AD LDAP searches to determine employee addresses: anders.wiehe@hig.no -> anderswi@pat.hig.no

ratbert.hig.no (III) alias_maps = hash:/etc/aliases, ldap:/etc/postfix/aliases-ldap-student,... version=3 server_host=ldaps://hig1.hig.no:636 ldaps://hig2.hig.no:636 tls_ca_cert_file=/usr/share/ssl/inu.cer tls_require_cert=yes search_base=dc=hig,dc=no query_filter=proxyaddresses=smtp:%s@hig.no result_attribute=mail special_result_attribute=member exclude_internal=yes recursion_query_filter=(!(useraccountcontrol=514)) bind_dn=<ad read account DN> / bind_pw=<password>

pat.hig.no Software: Linux, Postfix 2.1.5, Dovecot 0.99.11 Hardware: 2Ghz Xeon, 1GB RAM Both POP3 and IMAP available ~250 users Email relay for employees, supports SMTP authentication over TLS POP3S and IMAPS with a signed certificate

studenter.hig.no Software: Windows 2003, Exchange 2003 SP1, Symantec AV for Exchange Hardware: 2,8Ghz Xeon, 4GB RAM Some other stuff also run on this server, domain controller Supports both POP3 and IMAP, other Exchanges functions are not used Relay server for students, supports SMTP authentication TLS communication now operational!

Antispam: RBL Real Time Black lists Organizations/persons/automatic routines maintain a list of IP addresses which are black listed List criteria: open relay, known spammer, doesn't follow standards,... ratbert checks incoming email against: ORDB, DSBL, Spamhaus, Abuseat, Njabl, Spamcop Few known false positives per year

Antispam: Greylisting ratbert runs gps, a grey list implementation for Postfix Stores envelope from address, envelope to address and the senders IP address, triplet Temporarily rejects triplets never seen before Later delivery attempts will be accepted Uses MySQL for triplet storage Few whitelisted IP addresses per year Generates some support

Antispam: ClamAV ClamAV is a GPL licensed antivirus software Can be plugged into Postfix to detect and remove viruses in emails Maintained virus definitions, around 163000 virus definitions today Many viruses are stopped by greylisting Also some support because of ClamAV, not perfectly configured

(Hopefully) The next generation email system at GUC Open, standards Platform independent Employees and student use the same system Uses FEIDE for authentication and user information New default client and webmail with automatic configuration, calendar Automatic routines: Forward, vacation, filtering, individual spam filter configuration,...

Email services Questions? Ask now or email me at anders.wiehe@hig.no The end!