How to Use Netsh to Remove an Older Certificate Before Adding Another on a DDC

Use ” delete sslcert ”

This deletes SSL server certificate bindings and the corresponding client certificate policies for an IP address and port.

delete sslcert [ipport=]IP Address:port

Parameters

**[ipport=]**IP Address:port

Specifies the IPv4 or IPv6 address and port for which the SSL certificate bindings will be deleted.

Examples

delete sslcert ipport=1.1.1.1:443

delete sslcert ipport=0.0.0.0:443

delete sslcert ipport=[::]:443

Related:

  • No Related Posts

SMSMSE too many Administrator email notifications

I need a solution

Hello

we’ve got a DAG with 6 Exchange servers.

when a rule/threshold or whatever is reached the notifcation is sent multiple times with the same message to the administrator email (this is a distribution list containing 3 users).

It can occurs from the same server or from different server.

This notification was sent thrice to the same email address by the same server:

email subject : “Administrator Alert:  Symantec Mail Security detected an error (SYM:xxx442769)”

“Location of the message:  SMTP

        Sender of the message: user1@domain.com

        Subject of the message:  mail subject

        The attachment(s) “20200-01.pdf” and/or the message was Logged Only.

        This was done due to the following Symantec Mail Security settings:

        Scan: Auto-Protect

        Rule: Encrypted File Rule

 Server Name: Server01″

Any idea ?

Ty

David

0

Related:

ShareFile Custom SMTP

ShareFile SMTP IP Address Information

Please see the following KB article for whitelist information.


User Requirements

  • An employee user with the Allow this user to modify account-wide policies permission

Microsoft Office 365 Users

If you are a Microsoft Office 365 user and would like to utilize Custom SMTP, view this set up guide from Microsoft.

Setting up Custom SMTP

  1. Navigate to Admin > Advanced Preferences > Email Settings > Configure SMTP Settings
  2. On the Custom SMTP Configuration page, enter the appropriate information to enable this feature.
  3. Ensure that the Enable checkbox is checked before saving.

User-added image

Required fields

Enable Custom SMTP – This must be selected if you wish to use these settings.

Email Address – This will be the “from” email address of sent emails.

Server – This is the host name of the email server that will be used to send emails.

Port – This is the port number to be used. Port 25 is the default. We allow the following ports: 26, 443, 465, 587, 2525.

Username – This should be the username needed to access the server.

Password – This should be the password needed to access the server.

Notify Email on Failure – This email address will be sent notices if ShareFile is unable to send an email with the given settings.

Optional fields

Use SSL – Choose between Implicit, Explicit, or Off.

Failback to ShareFile –If selected, messages that fail to send using the custom settings will prompt ShareFile to send future emails through standard ShareFile email settings

Authentication Method – Select an authentication method here if a particular one is required by your server


Troubleshooting Your SMTP Setup

“Email Notifications / Messages are Delayed”

This issue may occur when you are utilizing certain filter services or programs processing messages on your local mail servers. Before contacting ShareFile about delays in our system, please verify that your messages are not being delayed by local filter services. One means of verifying that information is to review the full header details of a message and reviewing the time messages send between services or filters.

“Email Notifications / Messages Do Not Arrive”

This issue may occur if you have IP restrictions or policies on your local mail servers. Please click here to make sure you have whitelisted the Custom SMTP IPs. Likewise, please review your mail server authentication methods to ensure that ShareFile can communicate with your servers.

“Too many connections from your host”

This issue may occur when you have exceeded the maximum allowed connections on your SMTP server. To resolve this, you must update or increase your max allowed connections in your SMTP configuration, or use Consolidated Notifications to limit the number of connections you receive on a typical basis.

Related:

Management Center failed to send emails due to authentication errors

I need a solution

Dears,

I’ve an issue with management center appliance ( v2.2.1.1), as i cannot send emails when a job finished it’s task, in the time SMTP configuration (Mail Settings) is as follow:

Mail Server: Mail Server IP

Mail Server Port: 587 (Custom Port)

From Address: BlueCoat.MC@qnbalahli.com

Notes:

– This SMTP Server with customer port (587) uses a secure connection.

– On mail server a policy is created with MC IP address not to require authentication from that IP.

– We imported exchage server certificate on management center.

When we use default port 25 (not secure port) it works well.

– When checking MC logs we found the following error 

caused by: org.springframework.mail.MailAuthenticationException: Authentication failed; nested exception is javax.mail.AuthenticationFailedException: 535 5.7.3 Authentication unsuccessful

0

Related:

You don’t have permission to book this resource error [QUICK FIX]

A number of users have reported seeing the error message You don’t have permission to book this resource whenever they try to book a room (or other assets), by using the Outlook Exchange.

This issue is caused by migrating the room mailbox from an on-premises location to the Outlook Exchange Online service. When the move is performed, the permissions of the server need to be assigned again to avoid this issue.

This error message can cause a lot of confusion, as the initial settings of the local room mailbox seem to be in order at first glance. Even though that is the case, these features become inactive for security reasons. This protects the information stored on the servers from any third-party that wants to extract that information.

For these reasons in this article, we will explore several troubleshooting methods to deal with this issue. Please follow the steps described in this guide closely to avoid any other issues.

How to fix You don’t have permission to book this resource error?

1. Assign corresponding permissions of the room mailbox to your Exchange Online account

  1. Log into the Exchange Admin Center with your administrator account.Microsoft Office 365 admin - You don't have permission to book this resourceMicrosoft Office 365 admin - You don't have permission to book this resource
  2. Navigate to Recipient -> Resources.Microsoft Office 365 admin - You don't have permission to book this resourceMicrosoft Office 365 admin - You don't have permission to book this resource
  3. Double-click the room mailbox.
  4. Inside the pop-up window that appears, select Mailbox Delegations.
  5. Add your administrator account inside the Full Access blank space.
  6. Click on the Save button.
  7. Open Room Mailbox again and check to see if the issue persists.

Note: It is recommended that when performing these above steps, you use a private browsing session. Press CTRL+SHIFT+P for Mozilla Firefox, Microsoft Edge, and Internet Explorer. For Google Chrome press CTRL+SHIFT+N.


Send emails like a pro with these great email clients!



2. Add your account to Open Room MailboxExchangeOnline - You don't have permission to book this resourceExchangeOnline - You don't have permission to book this resource

  1. Log into your Open Room mailbox account.
  2. Select Options -> Resource Schedule page -> Add your account to the list.
  3. Inside your Outlook (with admin access) -> right-click Calendar -> select Data Properties.
  4. Inside the Permissions tab -> add the users with the appropriate access level -> click Save.Microsoft Office permissions - you don't have permission to book this resourceMicrosoft Office permissions - you don't have permission to book this resource
  5. Try to see if the issue persists.

Another possible reason for this error message could be caused by users trying to book rooms with 1 year before the preset time limit. This information can be checked by going to Portal ->Exchance -> Recipients -> Calendar -> Edit booking options.

In this article we explored a quick fix for the error You don’t have permission to book this resource when trying to reserve a room or other assets on Exchange Online.

Because this issue is caused by porting the data storage from local to cloud, the problem can be fixed by re-allowing the access for each of the users inside your Microsoft Exchange Admin Center.

Please feel free to let us know if this guide helped you solved your problem, by using the comment section found below.

READ ALSO:

Desktop Email Encryption with Godaddy Mail Service

I need a solution

Good Morning,

We have the need to encrypt emails end-to-end and I have the doubt if I can use Desktop Email Encryption having the mail service of Godaddy that is on the internet, it is POP3 type. In other words, we do not have Exchange or Lotus but checking the requirements there appear.

If the answer is affirmative, is it mandatory to install Symantec Encryption Management Server to manage it …? They are only a few clients, maximum five.

Regards.

0

Related:

DLP use case

I need a solution

Hello,

How can we achieve below use case in DLP Endpoint (Discover & Prevent). I requires this to be tested in enviroment..

use case 1:

If file is encrypted via Symantec encryption is it’s header is encrypted. Concern is that we create a custom script to read multiple value of file, If it’s match then DLP will block that file.

If header is encrypted how DLP will read file header.

use case 2:

To block outlook mail which contains keywords like “ financial “ ,” credit card”, etc.

Outlook mail client ver 2007.

Use case 3:

To block file uploads in cloud apps such as box & Dropbox.

Thanks in advance.

0

Related:

7021568: Session “High Water Mark” Tracking in Verastream Host Integrator

Note the following:

  • Data is available in a daily informational message for email, SNMP, or logging. The message is generated around midnight each day.
  • The message includes peak “active” concurrent sessions used by clients, and peak “total” concurrent sessions connected to the host (including initialized idle sessions in session pools).
  • The peak values are tracked since the session server was started. The values are reset when the session server service is restarted. For historical peak data over time, you should retain the daily messages.

Email Notification

You can configure Host Integrator to send a nightly email message. Example:

From: Verastream Host Integrator Server (MyVhiServer) <vhiadmin@mycompany.com>

To: vhiadmin@mycompany.com

Subject: Host Integrator Notification



Date: 8/11/10

Time: 12:01:01 AM

Severity: Informational

Message ID: 143

Session ID: N/A

Request ID: N/A

Username: N/A

Address: N/A

Model/Pool: N/A

Text: Peak concurrent sessions: Active = 6; Total = 20.

Follow the configuration steps for your product version.

Version 7.0 or Higher

To configure email notification in version 7.0 or higher:

  1. Open Administrative Console from the installed shortcut (Start > All Programs > Attachmate Verastream > Host Integrator > Administrative Console).
  2. Connect to your management server with administrative credentials ("admin" user with password set during installation, or user in the Administrator security profile).
  3. If the Session Server Explorer pane is not visible, click Perspective > Host Integrator > Session Servers.
  4. Under Installation > Servers, right-click your server and Properties.
  5. In the Properties dialog, in the left category tree, open Notifications > E-mail Settings.
  6. In the right pane, select Enable Email Notification and configure the other options for email address(es), your email server, etc. For more information, see http://docs2.attachmate.com/verastream/vhi/7.6/en/topic/com.attachmate.vhi.vmc.help.online/tasks/vhi_mc_config_email.xhtml.

Note: In version 7.6 or earlier, you must specify an internal SMTP mail server name or IP address. ISP mail servers that require SMTP authentication are not supported.

  1. Click Apply to save changes.
  2. Click Test Message and verify successful receipt of the test notification message. (Its format is similar to the example above, except the Text line reports This message is the result of an email test.)
  3. In the left category tree, click Messages.
  4. In the message group tree, open All Messages > Info/warning messages and select "0143 - LogPeakSessionCount." (Refer to Figure 1 below.)
  5. Under Notification Settings, enable the "Send email notification" option.
  6. Click OK.
Figure 1. Version 7.x Administrative Console: Message 143 enabled for email notification

Tip: To also generate immediate notification when maximum concurrent session limits are exceeded (which produces errors for attempted client connections), you can enable notification for the following additional Server Management errors: 2892, 2894, 2898, and 2643.

Version 6.6

To configure email notification in version 6.6:

  1. Open the Administrative WebStation console.

Local Windows installation: Use the Administrative WebStation shortcut installed in the Start programs folder.

Local UNIX installation: Use a web browser to open <vhi>/bin/VHI_Administrative_WebStation_Login.html where <vhi> represents your Verastream Host Integrator installation directory.

Remote system: In a web browser, open http://<hostname>:9642/apptrieve where <hostname> represents the system running the Verastream Host Integrator Administrative WebStation service.

  1. Log on to the Administrative WebStation using an Administrator profile.
  2. In the top navigation bar, click Config.Mode.
  3. In the left navigation tree, click Servers > [your server] > Server Configuration > Email Configuration > Email Notification.
  4. In the right pane, select Enable Email Notification and configure the other options for email addresses, your email server, etc. For more information, refer to the help documentation.

Note: You must specify an internal SMTP mail server name or IP address. ISP mail servers that require SMTP authentication are not supported.

  1. Click Save (or Submit and Save).
  2. Click Test Message and verify successful receipt of the test notification message. (Its format is similar to the example above, except the Text line reports This message is the result of an email test.)
  3. In the left navigation tree, click Servers > [your server] > Server Configuration > Email Configuration > Email Messages > Info/warning messages. (Refer to Figure 2 below.)
  4. In the right pane, scroll down and enable Log Message ID 143, as shown in Figure 2 below.
  5. Scroll up and click Save (or Submit and Save).

Tip: To also generate immediate notification when maximum concurrent session limits are exceeded (which produces errors for attempted client connections), you can enable notification for the following additional Server management errors: 2892, 2894, 2898, and 2643.

SNMP

You can configure your SNMP network management station to use the VHI MIB for monitoring, or configure the session server to send an SNMP Trap to the management station for specific messages.

Session Server Log

The session server can be configured to Log All Messages (and optionally also add the messages to the operating system log). You can later query the log for message ID 143. For more information on session server logging, see Technical Note 40032.

Note: When logging all messages, the increased disk write activity may impact performance in environments with heavy client load.

Related:

Outgoing email encryption not working (SMTP)

I need a solution

Hello,

I have a problem with sending out encrypted emails using Outlook 2016 and Symantec Encryption Desktop. The odd thing is that I can receive and decrypt emails without any issues, but outgoing emails are blocked.

Outlook is configured to use ports 25 for SMTP and 143 for IMAP. Ougoing server requires authentication and uses the same settings as incoming server.

Symantec Encryption Desktop is configured with email proxy enabled and ports 465 for SMTP and 993 for IMAP, as mail server requires SSL/TLS. 

Outlook error message states that the connection was interupted without any further details. Verbose Symantec logs show:

Email Verbose Connection accepted

Email Verbose Found exisiting account list entry for [IP]

Email Verbose Existing entry is [email address]

Email Verbose Proxying SMTP

Email Verbose Attempting to connect to server at [IP]

Email Verbose Attempteing tunneled TLS connection on port 465

Email Verbose Successfull connect on port 465

Email VerboseTLS session established with [mailserver]

Email  Error Cannot connect server socket to [IP]

Email Warning Tunneled TLS negotiation with server failed.

When I change the port 25 to 465 in Outlook I can send out emails fine, but I loose the ability to encrypt them.

As this is a test machine – there is no AV software onboard which could be blocking it. Windows Defender and Firewall are disabled completely.

Any ideas what might be causing this error?

Software versions:

OS is Windows 10 Pro N,

Symantec Encryption Desktop 10.4.1 

Tahnk you,

0

Related:

PGP Server – primary SMTP issue

I need a solution

Hello,

We are using Symtantec Encryption Server ver. 3.3.2 (build 15238).

We have strange issue with some users how have multiple SMTP email address setup in their “reply address” settings. All of them have mailboxes on MS Exchange 2013.

When we are adding new internal user’s equipped with internal user’s key with primary SMTP email address setup on his Exchange mailbox, we can see that due to unknown reason Enryption Server is omitting this entry and selects secondary or third email address from list. Sometimes we can see that there are not all email addresses defined on user’s mailbox in ECP console as Symantec Encryption Server console shows only 1-2 email address from list intstead of 4-5 entries.

Kindly please for help!

Best regards,

JB

0

Related: