Answer the question
In order to leave comments, you need to log in
How to enable SMTP SSL on MS Exchange port 465?
Good afternoon.
On the mail server MS Exchange 2019 added an SSL certificate and I'm trying to set up encrypted connections.
WEB, ActiveSync, POP and IMAP chain the certificate and work fine. POP and IMAP work over both SSL and TLS (995 and 110, 993 and 143, respectively). But I could only run SMTP on TLS 587. When a client (for example, ThunderBird) tries to connect via SMTP SSL 465, the connection timeouts.
Googling (including in English) leads to two options:
1) setting (which seems to be fully completed);
2) recommendations to use SMTP TLS 587.
Enabling SSL is critical because there are many clients who are not good at TLS.
Connector for port 465 created, tried toggling the checkboxes, the port is open in the firewall (PortScaner shows that the port is open and listening on the Microsoft Exchange smtpd service.
But the clients are not authorized.
What can I do? What did I miss?
upd: the certificate is loaded and assigned to the service SMTP What annoys me: all the certificates that are in the system are assigned to the SMTP service and I can’t remove the assignment.The system has a certificate *.mydomain.com, mail.mydomain.com and a self-signed Microsoft Exchange Server Auth Certificate.
Answer the question
In order to leave comments, you need to log in
1. Try to enable Protocol logging ( https://docs.microsoft.com/en-us/exchange/mail-flo... and see what's in the logs
2. I'm afraid to make a mistake, but it seems that Microsoft has abandoned the use of "SSL" in 2019 and replaced it with "TLS", implying it's the same thing. At least it's written here:
Secure Sockets Layer (SSL) is being replaced by Transport Layer Security (TLS) as the protocol that's used to encrypt data sent between computer systems
https://docs.microsoft.com/en-us/exchange/clients/...
REBOOT!
This is written on Microsoft, I don’t remember where, you apparently really updated consistently. The bottom line is that the directory hangs.
-----
Clearly, you have a new certificate, wait a couple of days.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question