Top Banner
www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. [email protected] Danita Zanrè Senior Consultant Caledonia Network Consulting [email protected] Michael Bell Software Developer Armana Software [email protected]
29

Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. [email protected] Danita Zanrè Senior Consultant Caledonia.

Dec 24, 2015

Download

Documents

Sabina Thornton
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

www.novell.com

Securing Your GroupWise® SystemSecuring Your GroupWise® System

Morris BlackhamSoftware EngineerNovell, [email protected]

Danita ZanrèSenior ConsultantCaledonia Network [email protected]

Michael BellSoftware DeveloperArmana [email protected]

Page 2: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

Vision…one NetA world where networks of all types—corporate and public, intranets, extranets, and the Internet—work together as one Net and securely connect employees, customers, suppliers, and partners across organizational boundaries

MissionTo solve complex business and technical challenges with Net business solutions that enable people, processes, and systems to work together and our customers to profit from the opportunities of a networked world

Page 3: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.
Page 4: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

Session Objectives

• Understand pre-requisites and configuration for:

• SSL WebAccess, GWIA, MTP, MTA/POA HTTP

• Server certificates Generating CSRs, obtaining certificates—third-party

or Novell Certificate Server

• GWIA Securing connections Preventing GWIA from being an open relay

Page 5: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

Session Objectives (cont.)

• Securing Internet post offices without a VPN Reduce infrastructure costs without sacrificing

security

• Antivirus/content filtering Protect your system from the flood of e-mail

viruses

• LDAP authentication to the GroupWise® mailbox Single password for Novell eDirectory™, the

GroupWise Client, and WebAccess

Page 6: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

SSL and Certificates

• GroupWise agents use OpenSSL implementation

• Generating Certificate Signing Request (CSR) GWCSRGEN.EXE with GroupWise 6 SP1 OpenSSL—create CSR or self-signed certificates

• Obtaining certificates Third-party Certificate Authorities Verisign, Thawte Novell Certificate Server

Page 7: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

Using GWSCRGEN

* Note: All fields MUST be filled in

Filenames must be 8.3 format

Use 2 char abbreviation

Do not use abbreviation

Fully qualified DNS hostname of server

Page 8: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

Novell Certificate Server

Page 9: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

Novell Certificate Server (cont.)

Page 10: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

Novell Certificate Server (cont.)

Page 11: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

Reducing Your Network Costs

WAN $$ Corporatenetwork

Page 12: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

Reducing Your Network Costs (cont.)

GroupWise 6Internet Corporate

network

Page 13: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

Securely Using the Internet as a WAN: Prerequisites

• GroupWise 6 SP1 agents at all WAN nodes MTA-MTA (Domain-to-Domain) MTA-POA (Domain-to-Post Office)

• Signed certificates imported to all WAN node agents

GWCSRGEN.EXE available for generating CSRs

• Agent with certificate is now SSL-enabled for message transfer

Page 14: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

SSL-Enabling the MTA*

required

recommended

* the POA is done exactly the same way…

Page 15: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

GWIA—Securing Your Connections

• Secure SMTP transactions using STARTTLS Connecting SMTP host must also support STARTTLS (you can test by sending to

myrealbox.com)

• Secure POP3/IMAP4 Support on ports 995 (POP3) and 993 (IMAP4) Also support STARTTLS method with ports 110 and

143

• HTTPS connection for HTTP monitoring

Page 16: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

GWIA—Preventing Relaying

• GWIA 6 Relaying is disabled by default Relaying is now denied at a SMTP daemon level Relay exceptions can be IP addresses or address range Added SMTP AUTH, if POP/IMAP clients use authentication

on outbound SMTP, relay access control is bypassed

• GWIA 5.5 and 5.5EP Apply latest support pack or FTF to eliminate

[email protected]” from being relayed

Page 17: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

Anti-Virus—Spam Control

• Anti-virus solutions Protection available at

• GWIA• MTA• Desktop

Page 18: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

GWIA Anti-Virus Solutions

• Use of SMTP home directory (Third-party directory)

Intercepts all incoming and outgoing e-mail

See TID 10065630 for configuration details

Two products available• Guinevere—http://www.openandhome.com• FootNote—http://www.stack.co.uk

Page 19: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

GWIA Anti-Virus Solutions

• Other anti-virus solutions using relay host Not specific to GroupWise GWIA relays third-party host for virus checking MX record references virus checking host,

relays inbound messages to GWIA Products include

• Symantec—Norton Anti-Virus for Gateways• McAfee—Webshield• Trend Micro—Interscan• MailSweeper for SMTP

Page 20: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

MTA Anti-Virus Solution

• MTA level virus protection Intercepts all mail routed through the domain Gateway messages, except WebAccess All inter-post office traffic

• Product: GWAVA http://www.beginfinite.com

Related Session: TUT225

Page 21: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

Securing WebAccess

• No WebAccess specific steps needed

• Enable WebServer for SSL connection NES—Uses Novell Server Certificate IIS—Uses NT/2000 Certificate Apache—Open SSL certificate

Page 22: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

LDAP Authentication To GroupWise

Post Office agent

GroupWise6 SP1

LDAP server

eDirectory 8.5

(or any LDAP v3 Directory)

Login request Credentials

Results

GroupWise client

GroupWise

WebAccess

Results

Page 23: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

LDAP Authentication: Prerequisites And Limitations

• GroupWise 6 SP1 POA, WebAccess, and Client (Client and WebAccess required for interface support of

password expiration dialogs)

• eDirectory 8.5 LDAP Server, with GroupWise users in the eDirectory 8.5 tree

OR

• User object MAIL attribute synchronization between GroupWise and the LDAP server of choice

• For full password expiration functionality, the POA must be forced to BIND

Page 24: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

LDAP Authentication: Post Office Configuration

required

recommended

leave blank636

Page 25: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

LDAP Configuration: Why Leave the LDAP User Name Blank?

• Credential behavior with the LDAP user name and password

POA will use this user name and password to connect, and then do a ‘compare’ of the user-provided credentials against the LDAP directory

‘Compare’ does not support expiration of passwords

• Credential behavior without the LDAP user name and password

POA will use the user-provided credentials to attempt to bind to the LDAP server

Password expiration is supported for a BIND connection

Page 26: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

LDAP Configuration: SSL Certificate Use and Requirements

• Why Use SSL? Without SSL, LDAP credentials are passed in the clear

• This is unacceptable, even within your firewall

• SSL certificate must be a Trusted Root Certificate for the LDAP directory

This is the way the standard is written—it’s an LDAP requirement

• The LDAP SSL port is 636

Page 27: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

Exporting the Trusted Root Cert

Detail screen of a server certificate object, Trusted Root CertExport the Trusted Root in .DER format

Page 28: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.

Exporting the Trusted Root Cert (cont.)

Page 29: Www.novell.com Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. mblackham@novell.com Danita Zanrè Senior Consultant Caledonia.