Connect. Communicate. Collaborate. Securely.

Home » Kerio User Forums » Kerio Connect » mailserver.cfg (Where do I find mailserver.cfg?)
  •  
RossmanSchool

Messages: 5
Karma: -1
Send a private message to this user
I am having PCI compliance issues and just received this:

Here is the list of known incompatibilities:

Vulnerability to TLS CBC attack

Solution: In Kerio Connect 8.0.0 and higher set the "SSLDontInsertEmptyFragments" configuration value to "0" in mailserver.cfg file.

Details: Kerio Outlook Connector (Offline edition) users on Windows XP system may not be able to connect to the server or synchronize the data.
Vulnerability to SSL BEAST attack

Solution: In Kerio Connect 8.0.1 and higher set the "DisableRC4SHA" configuration value to "0" in mailserver.cfg configuration file.

Details: RC4 cipher may be considered by some other security scans as insecure due to known attack vectors to this algorithm. Some US government organizations and agencies must follow FIPS-140-2 standard, which forbids RC4 ciphers.

But I do not know where to find mail server.cfg. Sad
  •  
sthiessen

Messages: 4
Karma: 0
Send a private message to this user
We are also having a PCI compliance issue with the BEAST vulnerability. Where are you finding Kerio 8.0.1 information? That DisableRC4SHA config option is just what we're looking for.

BTW, In our Windows environment the mailserver.cfg file is located in the C:\Program Files\Kerio\Mailserver directory. It can be edited with Notepad.
  •  
RossmanSchool

Messages: 5
Karma: -1
Send a private message to this user
I received an email this morning: I am signed up to receive email alerts when something new is added to Kerio's Knowledge Base.
I just signed up and it has been very helpful. The article is kb.kerio.com/article.php?id=1301

Thanks for the info; I am a Mac girl, but I am sure I can find it now.
  •  
Bill_E

Messages: 4
Karma: 1
Send a private message to this user

where do you find Kerio Connect 8.0.1 ???
  •  
Lucian Maly (Kerio)

Messages: 136
Karma: 8
Send a private message to this user
Kerio Connect v8.0.1 is not released for public yet. Beta version will be available at http://www.kerio.com/betas/connect at the end of January/beginning of February. Stay tuned!

Kerio Technologies AU Pty Ltd.
Previous Topic: Upload Mails to server
Next Topic: Access into Administration is disabled.
Goto Forum:
  


Disclaimer:
Kerio discussion forums are intended for open communication between forum members and may contain information and material posted by members which may be useful in learning about Kerio products. The discussion forums are not intended to provide technical support for any specific product. Any information implied or expressed in the discussion forums is that of the posting member. Kerio is in no way responsible for the information posted in the forums, or its accuracy. Kerio employees may participate in the discussions, but their postings do not represent an offical position of the company on any issues raised or discussed. Kerio reserves the right to monitor and maintain the forums to promote free and accurate exchange of information.

Current Time: Sat Nov 18 16:38:08 CET 2017

Total time taken to generate the page: 0.00391 seconds
.:: Contact :: Home ::.
Powered by: FUDforum 3.0.4.