Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive Administrator's Guide - Kerio Software Archive

download.kerio.com
from download.kerio.com More from this publisher
11.07.2015 Views

Chapter 13 User accountsDescriptionUser description (e.g. a position in a company). The Description entry is for informativepurposes only. They can contain any type of information or they can be left blank.AuthenticationPossible authentication methods:• Internal user databaseUsers are only authenticated within Kerio MailServer. In this case a password mustbe entered in the Password and Confirm Password fields (the user can then changehis/her password in the Kerio WebMail interface).Warning: Passwords may contain printable symbols only (letters, numbers, punctuationmarks). Password is case-sensitive.• Windows NT domainUsers are authenticated in a Windows NT domain. The NT domain name must be enteredin the email domain properties (Windows NT domain in the Advanced tab). Thisauthentication method can be used only if Kerio MailServer is running on Windows2000/XP/2003. For details, see chapter 7.7.• Kerberos 5Users are authenticated in the Kerberos 5 authentication system.• PAM serviceAuthentication using the PAM service (Pluggable Authentication Module), availableonly in the Linux operating system.• Apple Open DirectoryAuthentication against Apple Open Directory database (only for mailservers installedon a Macintosh). The option can be selected only if the user is mapped from AppleOpen Directory.Password / Confirm PasswordOnly the local user password can be entered or changed. We strongly recommend tochange the password immediately after the account is created.If the password contains special (national) characters, users of some mail clients willnot be able to log in to Kerio MailServer. It is therefore recommend to use only ASCIIcharacters for passwords.Enable a default spam filter ...Upon creating a new user account, check this option to set the antispam rule. All incomingemails marked as spam will be automatically moved to the Junk mail folder. The rulecan be set up only during the process of user account creation. Filtering and rules forincoming email is addressed in Kerio MailServer, User’s Guide.Warning: It is not recommended to create this rule when the user accesses emails viaPOP3. In such case, only the INBOX folder is downloaded to the local client and the useris not able to check if the emails moved to the Spam folder are really spam emails.108

13.2 Creating a user accountStore password in high secure SHA format (recommended)By default, user passwords are encrypted by DES. The Store password in highly secureSHA format allows for a more secure encryption (SHA string). This option has one disadvantage— some methods of Kerio MailServer access authentication (APOP, CRAM-MD5and Digest-MD5) cannot be applied. The only methods available for this option are LOGINand PLAIN (it is highly recommended to use only SSL connection for authentication).If this option is enabled, it is necessary to change the user password. This can be doneeither by administrator or the user (e.g. by Kerio WebMail).Warning: Passwords saved in SHA are supported by Kerio MailServer 6.0.5 and later. Ifa configuration with SHA passwords is applied to an older version of Kerio MailServer,the authentication will not function.Account is disabledTemporary blocking of the account so that you do not have to remove it.Warning: This feature is not identical with account blocking set under Configuration →Advanced Options, on the Security Policy tab (see section 15.6). If the user enters aninvalid password too many times in row and the limit set on the Security Policy tab isreached, the account is blocked automatically. To unblock the accounts, use the Unlockall accounts now button on the Security Policy tab.Step 3 — Mail addressesIn this step, all required email addresses of the user can be defined. The other addresses arecalled aliases. The other addresses are called aliases. These can be defined either during theuser definition or in Domain Settings/Aliases. We recommend to use the first alternative — itis easier and the aliases are available through Active Directory.Note: If user accounts are maintained in Active Directory (see chapter 7.6), their aliases can bedefined in Active Directory Users and Computers. Global aliases (in Domain Settings → Aliases)cannot be defined this way.109

Chapter 13 User accountsDescriptionUser description (e.g. a position in a company). The Description entry is for informativepurposes only. They can contain any type of information or they can be left blank.AuthenticationPossible authentication methods:• Internal user databaseUsers are only authenticated within <strong>Kerio</strong> MailServer. In this case a password mustbe entered in the Password and Confirm Password fields (the user can then changehis/her password in the <strong>Kerio</strong> WebMail interface).Warning: Passwords may contain printable symbols only (letters, numbers, punctuationmarks). Password is case-sensitive.• Windows NT domainUsers are authenticated in a Windows NT domain. The NT domain name must be enteredin the email domain properties (Windows NT domain in the Advanced tab). Thisauthentication method can be used only if <strong>Kerio</strong> MailServer is running on Windows2000/XP/2003. For details, see chapter 7.7.• Kerberos 5Users are authenticated in the Kerberos 5 authentication system.• PAM serviceAuthentication using the PAM service (Pluggable Authentication Module), availableonly in the Linux operating system.• Apple Open DirectoryAuthentication against Apple Open Directory database (only for mailservers installedon a Macintosh). The option can be selected only if the user is mapped from AppleOpen Directory.Password / Confirm PasswordOnly the local user password can be entered or changed. We strongly recommend tochange the password immediately after the account is created.If the password contains special (national) characters, users of some mail clients willnot be able to log in to <strong>Kerio</strong> MailServer. It is therefore recommend to use only ASCIIcharacters for passwords.Enable a default spam filter ...Upon creating a new user account, check this option to set the antispam rule. All incomingemails marked as spam will be automatically moved to the Junk mail folder. The rulecan be set up only during the process of user account creation. Filtering and rules forincoming email is addressed in <strong>Kerio</strong> MailServer, User’s <strong>Guide</strong>.Warning: It is not recommended to create this rule when the user accesses emails viaPOP3. In such case, only the INBOX folder is downloaded to the local client and the useris not able to check if the emails moved to the Spam folder are really spam emails.108

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!