EcoStruxure IT forum
Schneider Electric support forum about installation and configuration for DCIM including EcoStruxure IT Expert, IT Advisor, Data Center Expert, and NetBotz
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-03 08:23 AM . Last Modified: 2024-04-08 03:53 AM
Hi team
During a DCO 8.0.1 installation project, the customer has stated that they would be requiring to us secure SMTP communications. I can see the "Secure SMTP" checkbox, but what does the "Requires STARTTLS extension" involve to enable this functionality?
Regards
Jim Davis - NIE Melbourne/AU
(CID:110006039)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-03 08:24 AM . Last Modified: 2024-04-08 03:53 AM
Answer provided by Sean Macey
Although port 587 doesn't mandate requiring STARTTLS, the use of port 587 became popular around the same time as the realisation that SSL/TLS encryption of communications between clients and servers was an important security and privacy issue and encryption extensions were being defined for sMTP. So shortly after port 465 was defined, it was revoked with the expectation that clients would move to using STARTTLS over port 587
The result is that in most cases, systems that offer message submission over port 587 require clients to use STARTTLS to upgrade the connection and also require a username and password to authenticate.
In short, when using STARTTLS use port 587.
(CID:110007854)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-03 08:23 AM . Last Modified: 2024-04-08 03:53 AM
Dear Jim,
It all depends upon the SMTP Server.
To protect SMTP communications, servers can use transport-layer security (TLS), more commonly known as SSL encryption, to provide privacy and authentication.
Some servers support SSL for SMTP communications by sending and receiving SMTP traffic through the SSL port (port 465 by default) only. However, because this requires that both the sending and receiving servers support SMTP over SSL, this solution isn't always practical.
To provide SSL security for SMTP transfers over TCP/IP, IBM® Lotus® Domino® supports the use of negotiated SSL. In a negotiated SSL scheme, the sending and receiving hosts each use the SMTP STARTTLS extension, defined in RFC 2487, to signal their readiness to negotiate an SSL connection. The receiving server displays the STARTTLS keyword in response to the sending server's EHLO command. The sending server issues the STARTTLS command to request the creation of a secure connection. After the initial TLS handshake completes successfully, the two parties proceed to set up an SSL channel between them. Both the sending and receiving server must possess SSL certificates.
For More info, please refer: https://www.ibm.com/support/knowledgecenter/SSKTMJ_8.0.1/com.ibm.help.domino.admin.doc/DOC/H_SUPPORT...
If the SMTP Server requires STARTTLS extension, then you can check the option while configuring the SMTP Server for email settings.
Please do ask the Customer's SMTP Server team to provide the following details for successful email configuration in DCO.
I hope this helps.
Regards,
Bala
(CID:110006046)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-03 08:24 AM . Last Modified: 2024-04-08 03:53 AM
Hi, I'm the client Jim is supporting. we are still having a issues with smtp connection. the server we are connecting to belongs to an ISp (Spark XTRA) via send.xtra.co.nz port 465, this server requires authentication using SSL. FYI I have tested the network and firewall correctness by configuring thunderbird email and proving that app worked, however so far I am not able to get the DCO 8.0.1 to send.
(CID:110007186)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-03 08:24 AM . Last Modified: 2024-04-08 03:53 AM
would you be able to confirm correct actuions required in DCO and Centos in order to configure?
(CID:110007187)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-03 08:24 AM . Last Modified: 2024-04-08 03:53 AM
Answer provided by Sean Macey
Although port 587 doesn't mandate requiring STARTTLS, the use of port 587 became popular around the same time as the realisation that SSL/TLS encryption of communications between clients and servers was an important security and privacy issue and encryption extensions were being defined for sMTP. So shortly after port 465 was defined, it was revoked with the expectation that clients would move to using STARTTLS over port 587
The result is that in most cases, systems that offer message submission over port 587 require clients to use STARTTLS to upgrade the connection and also require a username and password to authenticate.
In short, when using STARTTLS use port 587.
(CID:110007854)
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2020-07-03 08:24 AM . Last Modified: 2023-10-22 01:40 AM
This question is closed for comments. You're welcome to start a new topic if you have further comments on this issue.
Link copied. Please paste this link to share this article on your social media post.
Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.