GFI Software

Welcome to the GFI Software community forum! For support please open a ticket from https://support.gfi.com.

Home » GFI User Forums » Kerio Connect » SSL Login Problem
SSL Login Problem [message #149056] Thu, 19 November 2020 09:36 Go to next message
teco64
Messages: 14
Registered: October 2017
Hello,
I have a problem with a new Konica MFC.
Scan to Email is not working. Every time I get the following error:

Failed SMTP login from KONICAMFC with SASL method NTLM.

We have by default only SMTP via SSL enabled. All 5 Authentification Methods are enabled.

Kerio Version: 9.2.12

Any idea how to fix this Login error?

Thank you in advance.

Re: SSL Login Problem [message #149057 is a reply to message #149056] Thu, 19 November 2020 10:10 Go to previous messageGo to next message
ian.bugeja is currently offline  ian.bugeja
Messages: 666
Registered: March 2017
Location: Malta
Can you share a screenshot of the Konica configuration please?

Ian Bugeja
GFI Software
Re: SSL Login Problem [message #149058 is a reply to message #149057] Thu, 19 November 2020 10:51 Go to previous messageGo to next message
teco64
Messages: 14
Registered: October 2017
Please find setting page attached. German language only.

There is not much to select.

Company internal information are hidden.
Re: SSL Login Problem [message #149061 is a reply to message #149058] Thu, 19 November 2020 13:41 Go to previous messageGo to next message
ian.bugeja is currently offline  ian.bugeja
Messages: 666
Registered: March 2017
Location: Malta
What options does the SSL/TLS dropdown allow?

Also can you check what TLS versions are enabled on Kerio Connect?
Check the following variable in mailserver.cfg
<variable name="ServerTlsProtocols">SSLv3,TLSv1,TLSv1.1,TLSv1.2</variable >


Ian Bugeja
GFI Software
Re: SSL Login Problem [message #149065 is a reply to message #149061] Thu, 19 November 2020 14:40 Go to previous messageGo to next message
teco64
Messages: 14
Registered: October 2017
SSL Will be activated/deactivated with "SSL/TSL-Einstellungen" Current setting means " SMTP over SSL"
Portnummer = Port without SSL
Portnummer (SSL) = Port with SSL


Kerio Settings:

<table name="Security">
<variable name="ServerTlsProtocols"></variable>

<table name="SmtpSecurity">
<variable name="ServerTlsProtocols"></variable>

Re: SSL Login Problem [message #149068 is a reply to message #149065] Thu, 19 November 2020 17:01 Go to previous messageGo to next message
ian.bugeja is currently offline  ian.bugeja
Messages: 666
Registered: March 2017
Location: Malta
Does the printer support TLS1.2? It might be that it needs TLS1.1 or lower.

Ian Bugeja
GFI Software
Re: SSL Login Problem [message #149070 is a reply to message #149068] Fri, 20 November 2020 08:29 Go to previous messageGo to next message
teco64
Messages: 14
Registered: October 2017
The printer is 2 Months old. There are not information in the documentation which TLS Version is supported.

It works currently with Hmailserver. This server is restricted to work only with TLS 1.2. Logbook shows that the printer can talk with TLS 1.2

The only possible difference is, that Hmail supports many ciphers as below

ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:EC DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE- RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM: ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA- AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:EC DHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES 256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES 128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA- AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:ECDHE-RSA-RC4 -SHA:ECDHE-ECDSA-RC4-SHA:AES128:AES256:RC4-SHA:HIGH:!aNULL:! eNULL:!EXPORT:!DES:!3DES:!MD5:!PSK;

Which Debug log from Kerio would be helpfull?
Re: SSL Login Problem [message #149075 is a reply to message #149070] Fri, 20 November 2020 16:17 Go to previous messageGo to next message
ian.bugeja is currently offline  ian.bugeja
Messages: 666
Registered: March 2017
Location: Malta
Check Debug log

Enable these Messages (by right-clicking on log view, select Messages and tick the following)
SMTP Server
User Authentication
Network Connections and SSL


Regarding Cipher list this might help
https://support.kerioconnect.gfi.com/hc/en-us/articles/36001 5191320-Configuring-SSL-TLS-Variables-in-Kerio-Connect

More specifically have a look at ServerTlsCiphers


Ian Bugeja
GFI Software
Re: SSL Login Problem [message #149089 is a reply to message #149075] Tue, 24 November 2020 09:30 Go to previous messageGo to next message
teco64
Messages: 14
Registered: October 2017
Hi,

Please find below a copy from the debug log (company details removed, larger parts will be send as pm or email only.):

[19/Nov/2020 08:54:56][5820] {smtps} Task 578 handler BEGIN
[19/Nov/2020 08:54:56][5820] {conn} Connection from ---.---.---.---:56912 to ---.---.---.---:465, socket 296760.
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL handshake started: before/accept initialization
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:before/accept initialization
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 Client requests does not contain SMTP server name
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 read client hello A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 write server hello A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 write certificate A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 write key exchange A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 write server done A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 flush data
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:error in SSLv3 read client certificate A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:error in SSLv3 read client certificate A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 read client key exchange A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 read certificate verify A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 read finished A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 write session ticket A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 write change cipher spec A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 write finished A
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL_accept:SSLv3 flush data
[19/Nov/2020 08:54:56][5820] {conn} SSL debug: id 000000000CDFDAB0 SSL handshake done: SSL negotiation finished successfully
[19/Nov/2020 08:54:56][5820] {conn} Established secure SMTP server connection from ---.---.---.---:56912 to ---.---.---.---:465 using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384, id 0000000024440A58
[19/Nov/2020 08:54:56][5820] {smtps} Task 578 handler starting
[19/Nov/2020 08:54:56][5820] {smtps} SMTPS server session begin; client connected from KM10859B:56912
[19/Nov/2020 08:54:56][5820] {smtps} Sent SMTP greeting to KM10859B:56912
[19/Nov/2020 08:54:56][5820] {smtps} Command EHLO [---.---.---.---]
[19/Nov/2020 08:54:56][5820] {smtps} Sent reply to EHLO: 250 xxxxxxxxxxx ...
[19/Nov/2020 08:54:56][5820] {smtps} Command AUTH NTLM TlRMTVNTUAABAAAABQQAoAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==
[19/Nov/2020 08:54:56][5820] {smtps} Started authentication method NTLM
[19/Nov/2020 08:54:56][5820] {auth} NTLM: Continuing authentication.
[19/Nov/2020 08:54:56][5820] {auth} NTLM: error while accepting security context - logon denied (-2146893044)
[19/Nov/2020 08:54:57][5004] {conn} SSL debug: id 000000000D04CF40 SSL3 alert write:warning:close notify
[19/Nov/2020 08:54:57][3348] {conn} SSL debug: id 0000000007CF8350 SSL3 alert write:warning:close notify
[19/Nov/2020 08:54:57][756] {conn} SSL debug: id 0000000007CF8660 SSL3 alert write:warning:close notify
[19/Nov/2020 08:54:57][3348] {conn} Closing socket 286480
[19/Nov/2020 08:54:57][756] {conn} Closing socket 306820
[19/Nov/2020 08:54:57][5004] {conn} Closing socket 204696

Re: SSL Login Problem [message #149092 is a reply to message #149089] Tue, 24 November 2020 10:56 Go to previous messageGo to next message
ian.bugeja is currently offline  ian.bugeja
Messages: 666
Registered: March 2017
Location: Malta
Thanks

from what I can see this is not a TLS/Chiper issue but an authentication issue.

Is this SSO with ActiveDirectory? Did you try entering username with domain name? like username@domain ?


Ian Bugeja
GFI Software
Re: SSL Login Problem [message #149094 is a reply to message #149092] Tue, 24 November 2020 12:37 Go to previous messageGo to next message
teco64
Messages: 14
Registered: October 2017
No active directory. Kerio is independent from AD.

Username is written as username@domain


Re: SSL Login Problem [message #149095 is a reply to message #149094] Tue, 24 November 2020 15:57 Go to previous messageGo to next message
ian.bugeja is currently offline  ian.bugeja
Messages: 666
Registered: March 2017
Location: Malta
what is your configuration in the Security Policy? Are all authentication methods enabled?

/index.php?t=getfile&id=5183&private=0
  • Attachment: sp.png
    (Size: 33.11KB, Downloaded 1117 times)


Ian Bugeja
GFI Software
Re: SSL Login Problem [message #149096 is a reply to message #149095] Tue, 24 November 2020 16:26 Go to previous messageGo to next message
teco64
Messages: 14
Registered: October 2017
All authentication methods are enabled. Please see image below/attached.

[img]/index.php?t=getfile&id=5184&private=0[/img]
Re: SSL Login Problem [message #149101 is a reply to message #149096] Wed, 25 November 2020 13:02 Go to previous messageGo to next message
ian.bugeja is currently offline  ian.bugeja
Messages: 666
Registered: March 2017
Location: Malta
I got feedback to try using the "POP3 before SMTP" option and changing NTLM to CRAM-MD5 as an alternative if your printer supports it.

If this does not work can you list the exact printer model you have and maybe link to the online manual so that we can investigate what settings are available?


Ian Bugeja
GFI Software
Re: SSL Login Problem [message #149105 is a reply to message #149101] Wed, 25 November 2020 14:15 Go to previous messageGo to previous message
teco64
Messages: 14
Registered: October 2017
CRAM-MD5 was the goal.

POP3 before SMTP was not needed.

Thank you for your help.
Previous Topic: MS365 Outlook - messages shown as plaintext, but they are html
Next Topic: How to setup Kerio Api
Goto Forum:
  


Current Time: Tue May 30 22:04:08 CEST 2023

Total time taken to generate the page: 0.05705 seconds