Postfix PCI Compliance in ZCS

Revision as of 19:17, 1 December 2009 by Cfremon (talk | contribs) (Adding Article Footer and Categories)
The printable version is no longer supported and may have rendering errors. Please update your browser bookmarks and please use the default browser print function instead.

Working towards PCI Compliance for Zimbra 5.0.x

Reconfigure the Postfix SSL/TLS settings

1. Make a backup of /opt/zimbra/postfix/conf/ in case you need to rollback or refer to after an upgrade.

2. Log in as root in the command line utility. Switch to the zimbra user account.

su - zimbra

3. Type the following commands:

postconf -e smtpd_tls_mandatory_protocols="SSLv3, TLSv1"
postconf -e smtpd_tls_mandatory_ciphers="medium, high"

The SSL/TLS settings are now reconfigured. The changes will take effect immediately.

4. To ensure that your changes are not overwritten by a future Zimbra upgrade, you can set them in the local config.

zmlocalconfig -e smtpd_tls_mandatory_protocols="SSLv3, TLSv1"
zmlocalconfig -e smtpd_tls_mandatory_ciphers="medium, high"

Verified Against: unknown Date Created: 11/30/2009
Article ID: Date Modified: 2009-12-01

Try Zimbra

Try Zimbra Collaboration with a 60-day free trial.
Get it now »

Want to get involved?

You can contribute in the Community, Wiki, Code, or development of Zimlets.
Find out more. »

Looking for a Video?

Visit our YouTube channel to get the latest webinars, technology news, product overviews, and so much more.
Go to the YouTube channel »

Jump to: navigation, search