Configuring the transport layer security modes

Prev Next

You can configure the transport layer security receiving mode and default delivery mode by using the Email Security - Server appliance Web UI or CLI:

You specify the following receiving mode and default delivery mode options for TLS configuration.

Field

Description

None

Enabled in both receiving mode and default delivery mode, no connections are configured with TLS.

Opportunistic

Enabled in receiving mode, the connection accepts emails that are either TLS-encrypted or not TLS-encrypted based on the upstream configuration. Enabled in default delivery mode, emails are delivered over connections that are either TLS-encrypted or not TLS-encrypted to the remote MTA.

Mandatory

Enabled in both receiving mode and default delivery mode, TLS configuration is required for all connections. Enabled in receiving mode, if TLS is not supported on the upstream device, emails are not accepted and they remain on the upstream device until the connection accepts emails that are not TLS-encrypted. Enabled in default delivery mode, if the next-hop does not support TLS, emails are not delivered and remain deferred on the appliance for five days or until TLS is supported in the remote MTA.

Verify

Enabled in default delivery mode, validation of the next-hop MTA server certificate and the imported certificate authority (CA) are required before the TLS connection is established.

Verify mode is required for compliance with Common Criteria certification.

For information about TLS certificate configuration and TLS CA configuration, see the Email Security — Server System Administration Guide.

Prerequisites

  • An established connection between the Email Security - Server appliance and the Internet.

  • You are logged in to the Email Security - Server appliance CLI as an Admin or Operator.