Configuring TLS Settings for Messages Entering IMSVA Parent topic

Procedure

  1. Navigate to AdministrationIMSVA ConfigurationSMTP RoutingConnections.
    The Connections screen appears.
  2. Select Enable Incoming Transport Layer Security.
    This option allows the IMSVA SMTP Server to provide Transport Layer Security (TLS) support to SMTP clients, but does not require that clients use TLS encryption to establish the connection.
  3. Select Only accept SMTP connection by TLS for IMSVA to only accept secure incoming connections.
    This option enables the IMSVA SMTP server to accept messages only through a TLS connection.
  4. Click a Browse button next to one of the following:
    • CA certificate: A CA certificate is usually used for verifying SMTP clients. However, IMSVA does not verify the client and only uses the CA certificate for enabling the TLS connection.
      Only upload this file if it is provided to you together with the public key. Otherwise, this file is not mandatory for enabling a TLS connection.
    • Private key: The SMTP client encrypts a random number using the IMSVA SMTP server's public key and an encryption key to generate the session keys.
      The IMSVA SMTP server then uses the private key to decrypt the random number in order to establish the secure connection.
      This key must be uploaded to enable a TLS connection.
    • SMTP server certification: The IMSVA SMTP server's public key made available to the SMTP clients for generating the session keys.
      This key must be uploaded to enable a TLS connection.
  5. Click Save.