Using TLS Encryption with Microsoft Outlook 2007 This guide is meant to be used with Microsoft Outlook 2007. While the instructions are similar, the menu layouts and options have changed since the previous version. If you are using Outlook 2003, please click here. It is also assumed that you have previously set up or imported an account into Outlook. If you have not, you can set one up using the Account Wizard found in the Tools > Account Setting menu using either stu.beloit.edu or beloit.edu as your POP3 server, depending on where your account is located, and bcmail.beloit.edu as your SMTP server. Setting up an account does not enable authentication and encryption, which are required if you want to send mail from an off campus location. Authentication and encryption are not required for use on campus, although ISR strongly recommends enabling it. 1. Open the Account Preferences by going to the Tools menu and selection Account Settings...From the account options screen highlight your Beloit College email account and click the Change button. 2. This opens up the Change Email Account window. Under Server Information, change the Outgoing Mail Server (SMTP) to bcmail.beloit.edu. Next, click the More Settings button.
3. The Internet Email Settings window will open up. Click on the tab called Outgoing Server to configure the SMTP server for authentication. Check the box My outgoing server (SMTP) requires authentication and select the Logon using option below it. Enter your Beloit College user name in the User Name field. Do not select Use the same settings as my incoming mail server.
4. Select the Advanced tab to configure encryption options. Under server port numbers and Incoming Server (POP3), check the box This Server requires an encrypted connection (SSL). The default port will change from 110 to 995 automatically, so you will not need to change that. If you are going to use bcmail to send mail from an off campus location, ISR strongly recommends that you change the port number from 25 to 2525 because many local ISPs block port 25. The default port 25 works for on campus mailing so if you only wish to send mail from bcmail on campus, you can leave the default port alone. Finally, select TLS as the encryption method from the drop down menu next to Use the following type of encrypted connection. If you get errors saying that the server does not support encryption when you send mail, change this to Auto. Do not select SSL or you will get errors and be unable to send mail until you correct the encryption type problem.
5. Click OK to close the Internet Email Settings window. Click next and then finish to close the Account Settings window. Send yourself a test email message. The first thing that will pop up is an Internet Security warning screen. In order to minimize warning messages about trusting Beloit College servers, ISR highly recommends installing the college CA certficate to your system. Follow the addendum at the bottom of this how-to before proceeding to the next step. 6. Click Yes at this screen to continue sending your mail. You will then be prompted for your user name and password. This is the same password as the one used to receive mail and use web mail. After your test message has been sent, check your incoming mail. You may be warned about the SSL certificate again and you may also be asked for your password again. You should see the test message you sent earlier as well as any mail you may have received since the last time it was checked. Outlook 2007 is now configured to use bcmail.beloit.edu with authentication and encryption.
Installing the Beloit College CA certificate using Windows To resolve the certificate warnings that appear in Microsoft Outlook when checking and receiving mail, you must install the Beloit College CA certificate. To download the certificate, right click here and select Save As. Save the file to your desktop. 1. Right click the file called cacert.cer and select Install Certificate to start the Import Certificate wizard. 2. In the Import Wizard window, click next to continue. This will open the Certificate Store screen. Click Place all certificates in the following store and then click the browse button to open the store location selector.
3. In the Select Certificate Store window, click Trusted Root Certificate Authorities and then click ok. Click next in the Certificate Import Wizard and then Finish to import the certificate
4. A Security Warning window will appear warning that the computer cannot validate the certificate. Click Yes to continue to import the certificate. A window will pop up indicating that Windows has successfully imported the certificate. Upon reopening your mail client, the Internet Security Warning windows should be gone.