Products: IMail Server Premium, IMail Server

POODLE Vulnerability

« Go Back

Information

 
Description
This article discusses the POODLE vulnerability and gives step-by-step instructions to resolve it.
Products: IMail Server (SMTP, POP3, IMAP4, Web Mail, Web Admin, EAS, and WorkgroupShare server
)
Versions: IMail version 12.3 and later only.

 
Solution
The POODLE attack involves a downgrade attack to SSL 3.0 and a subsequent attack against the SSL 3.0 protocol itself. For more information, see:
 
To protect against this attack, it is recommended that you disable SSL 3.0 for all services and clients using SSL/TLS.
 
Important Notes:
You must be running IMail version 12.3 or newer.  If you are running an older version you will need to upgrade to one of these versions.
 
Following these instructions may present compatibility problems for users on old platforms and browsers, where there is no support for TLS 1.0 or higher.It is recommended that you test these configuration changes and carefully monitor the production system after making any changes, so that you are prepared to handle any impacts.
 
Disabling SSLv3 for IMail services (SMTP, POP3, IMAP4)
 
Note:  This step is only required if you have SSL/TLS enabled for the IMail Services.
  1. Open Regedit
  2. Navigate to HKLM\Software\Wow6432Node\Ipswitch\IMail\SSL (HKLM\Software\Ipswitch\IMail\SSL on a 32 bit OS)
  3. If DisableSslV3_0 does not exist, add a new "DWord (32 bit) Value and name it DisableSslV3_0
  4. Set the value of DisableSslV3_0 to 1
  5. Restart SMTP, Queue Manager, POP3, and IMap4 Services in IMail
Disabling SSLv3 for IMail WorkgroupShare service:
 
Note:  This step is only required if you use the Workgroupshare service to synchronize collaboration data to Microsoft Outlook and have SSL enabled as a connection option.
  1. Download the appropriate zip file for the version of IMail that you are running:
  2. Ensure DisableSslV3_0 is set to 1 as noted above.
  3. Stop the WorkgroupShare service.
  4. Rename the following files in ...\IMail\Workgroupshare
    1. cswskav7.dll
    2. IpswitchLicense.dll
    3. WSAdmin.exe
    4. WSAdminResources.dll
    5. WSService.exe
    6. WSServiceResources.dll
  5. Unzip the new files into the WorkgroupShare folder
  6. Restart the Workgroupshare service.
Disabling SSLv3 for IMail Web Mail, EAS,and Web Admin 
 
Note:  This step is only required if you use the IMail Web Mail, EAS or Web Admin web services and have secure connections enabled within IIS.
  1. Open Notepad.exe
  2. Copy the following text into Notepad
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0\Client]
"DisabledByDefault"=dword:00000001
"Enabled"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0\Server]
"Enabled"=dword:00000000
"DisabledByDefault"=dword:00000001
  1. File > Save, then select All Files from the Type drop-down, and save the file with a name like DisableSSLv3.reg making sure it has a .reg extension.
  2. Double-click the reg file you just saved and click Yes to import it into the registry.
  3. Reboot Server.
Version12.3; 12.4
Attachment 

 
Customer Service Softwaresalesforce.comHome | Product