Mailing List CGatePro@mail.stalker.com Message #99707
From: Technical Support <support@stalker.com>
Subject: Re: TLS and Certificates - Updated
Date: Thu, 11 Mar 2010 20:27:36 +0300
To: CommuniGate Pro Discussions <CGatePro@mail.stalker.com>
Hello,

Matthew Black wrote:
On Fri, 05 Mar 2010 23:25:26 +0300
 Technical Support <support@stalker.com> wrote:
Hello,

dhazzard@yoursummit.com wrote:
Okay, scratch my previous post.  I'll be more specific.

As I mentioned below we have two mail servers.  For TLS to function
properly do I need one certificate with the Common Name set to
xyz.com and installed on both servers?  Or will this not work?

The certificate common name should match the host name on which the server will be contacted. Say, you serve the domain xyz.com with two hosts

$ORIGIN xyz.com
     IN MX  5 mail
     IN MX 10 smtp
mail IN A     10.20.30.40
smtp IN A     10.20.30.50

The IPs 10.20.30.40 and 10.20.30.50 should be assigned in the CgPro configuration to CgPro Domain objects where mail.xyz.com and smtp.xyz.com are either names or alias names to those objects.

In this case you will need certificates for mail.xyz.com and smtp.xyz.com, or can use a wildcard certificate *.xyz.com on both servers.


Wildcard certificates are NOT the way to go for large enterprises. They present a whole set of security problems because some sites offer dozens of services, each with its own certificate. Our university operates hundreds of servers. If a wildcard certificate gets compromised, EVERY service loses its security.

Why can't CommuniGate figure out how to configure multiple certificates, say one for each service (IMAP, POP, WebUser) and a different set for each domain? Apache has been doing this for a very long time.

You can create different domains with different certificates, all but one of those domains will be without accounts and set to route unknown names for mail, signal amd access to the only domain that holds the accounts.

matthew black
e-mail postmaster
california state university, long beach

#############################################################
This message is sent to you because you are subscribed to
 the mailing list <CGatePro@mail.stalker.com>.
To unsubscribe, E-mail to: <CGatePro-off@mail.stalker.com>
To switch to the DIGEST mode, E-mail to <CGatePro-digest@mail.stalker.com>
To switch to the INDEX mode, E-mail to <CGatePro-index@mail.stalker.com>
Send administrative queries to  <CGatePro-request@mail.stalker.com>

--
Best regards,
Dmitry Akindinov

=======================================================================
When answering to letters sent to you by the tech.support staff, make
sure the original message you have received is included into your
reply.
Subscribe (FEED) Subscribe (DIGEST) Subscribe (INDEX) Unsubscribe Mail to Listmaster