SSL Login Problem [message #149056] |
Thu, 19 November 2020 09:36  |
teco64
Messages: 14 Registered: October 2017
|
|
|
|
Hello,
I have a problem with a new Konica MFC.
Scan to Email is not working. Every time I get the following error:
Failed SMTP login from KONICAMFC with SASL method NTLM.
We have by default only SMTP via SSL enabled. All 5 Authentification Methods are enabled.
Kerio Version: 9.2.12
Any idea how to fix this Login error?
Thank you in advance.
|
|
|
|
|
|
Re: SSL Login Problem [message #149065 is a reply to message #149061] |
Thu, 19 November 2020 14:40   |
teco64
Messages: 14 Registered: October 2017
|
|
|
|
SSL Will be activated/deactivated with "SSL/TSL-Einstellungen" Current setting means " SMTP over SSL"
Portnummer = Port without SSL
Portnummer (SSL) = Port with SSL
Kerio Settings:
<table name="Security">
<variable name="ServerTlsProtocols"></variable>
<table name="SmtpSecurity">
<variable name="ServerTlsProtocols"></variable>
|
|
|
|
Re: SSL Login Problem [message #149070 is a reply to message #149068] |
Fri, 20 November 2020 08:29   |
teco64
Messages: 14 Registered: October 2017
|
|
|
|
The printer is 2 Months old. There are not information in the documentation which TLS Version is supported.
It works currently with Hmailserver. This server is restricted to work only with TLS 1.2. Logbook shows that the printer can talk with TLS 1.2
The only possible difference is, that Hmail supports many ciphers as below
ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:EC DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE- RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM: ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA- AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:EC DHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES 256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES 128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA- AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:ECDHE-RSA-RC4 -SHA:ECDHE-ECDSA-RC4-SHA:AES128:AES256:RC4-SHA:HIGH:!aNULL:! eNULL:!EXPORT:!DES:!3DES:!MD5:!PSK;
Which Debug log from Kerio would be helpfull?
|
|
|
|
Re: SSL Login Problem [message #149089 is a reply to message #149075] |
Tue, 24 November 2020 09:30   |
teco64
Messages: 14 Registered: October 2017
|
|
|
|
Hi,
Please find below a copy from the debug log (company details removed, larger parts will be send as pm or email only.):
[19/Nov/2020 08:54:56][5820] {smtps} Task 578 handler BEGIN
[19/Nov/2020 08:54:56][5820] {conn} Connection from ---.---.---.---:56912 to ---.---.---.---:465, socket 296760.
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL handshake started: before/accept initialization
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:before/accept initialization
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 Client requests does not contain SMTP server name
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 read client hello A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 write server hello A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 write certificate A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 write key exchange A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 write server done A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 flush data
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:error in SSLv3 read client certificate A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:error in SSLv3 read client certificate A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 read client key exchange A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 read certificate verify A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 read finished A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 write session ticket A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 write change cipher spec A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 write finished A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 flush data
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL handshake done: SSL negotiation finished successfully
[19/Nov/2020 08:54:56][5820] {conn} Established secure SMTP server connection from ---.---.---.---:56912 to ---.---.---.---:465 using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384, id 0000000024440A58
[19/Nov/2020 08:54:56][5820] {smtps} Task 578 handler starting
[19/Nov/2020 08:54:56][5820] {smtps} SMTPS server session begin; client connected from KM10859B:56912
[19/Nov/2020 08:54:56][5820] {smtps} Sent SMTP greeting to KM10859B:56912
[19/Nov/2020 08:54:56][5820] {smtps} Command EHLO [---.---.---.---]
[19/Nov/2020 08:54:56][5820] {smtps} Sent reply to EHLO: 250 xxxxxxxxxxx ...
[19/Nov/2020 08:54:56][5820] {smtps} Command AUTH NTLM TlRMTVNTUAABAAAABQQAoAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==
[19/Nov/2020 08:54:56][5820] {smtps} Started authentication method NTLM
[19/Nov/2020 08:54:56][5820] {auth} NTLM: Continuing authentication.
[19/Nov/2020 08:54:56][5820] {auth} NTLM: error while accepting security context - logon denied (-2146893044)
[19/Nov/2020 08:54:57][5004] {conn} SSL debug: id 000000000D04CF40 SSL3 alert write:warning:close notify
[19/Nov/2020 08:54:57][3348] {conn} SSL debug: id 0000000007CF8350 SSL3 alert write:warning:close notify
[19/Nov/2020 08:54:57][756] {conn} SSL debug: id 0000000007CF8660 SSL3 alert write:warning:close notify
[19/Nov/2020 08:54:57][3348] {conn} Closing socket 286480
[19/Nov/2020 08:54:57][756] {conn} Closing socket 306820
[19/Nov/2020 08:54:57][5004] {conn} Closing socket 204696
|
|
|
|
|
|
|
|
|