Please enable JavaScript to view this site.

CopiaFacts™ Reference Manual

The steps described below are necessary to implement TLS security for the SMTP Gateway.  See also the separate implementation checklist if you also wish to implement S/MIME Signing/Encryption for the Gateway operations.

Copia Support staff will work with you to navigate the procedures. The following sequence of actions will be recommended:

1. Set Up CopiaFacts SMTP Gateway

If you do not already have the CopiaFacts Gateway set up, you must first configure this and test it for non-encrypted operations.  In the examples below, we assume that your main e-mail domain is company.com, and that you have set up a subdomain fax.company.com and the necessary A and MX records in your DNS settings to enable e-mails to be sent to this domain.

The fax.company.com domain must then be set up as a recipient domain on the main Service tab of GWMANAGER.

It is essential that you test that normal Gateway operations are working satisfactorily before adding TLS security

Basic TLS operations are included in the standard CopiaFacts license.

2. Obtain a Domain SSL Certificate

The vast majority of domain certificates are issued for Web servers. Most of these are also suitable for an SMTP mail server, but in some cases the company issuing your certificate may assume you have a web server that they can access to confirm that you own the domain. Copia Support staff will advise on certificate providers who have provided users with suitable certificates.

There are three basic choices for suitable SSL domain certificates:

•A commercial certificate such as Sectigo PositiveSSL. This type of certificate is normally delivered as a group of certificate files which you can import into the Windows Certificate store, or is downloaded and installed into your browser.  However we have seen some certificates incorrectly selected and issued ready for installation in a Linux web server, which are hard to convert for use on Windows.  It is essential that your certificate is then exported from the certificate store or browser as a .PFX or .P12 file, with a password. The choice of file extension is usually made by the browser: the CopiaFacts SMTP Gateway can accept either one.  See Appendix N for screen shots and instructions for exporting the certificate file and setting a password.

•A free certificate such as LetsEncrypt.  In this case the price of a free certificate is that it is a little trickier to set up the first time and that it lasts only 90 days.  However it is possible to create a batch file to run a program to renew the certificate automatically, which can be scheduled using a CopiaFacts worker-box FS file or by Windows task scheduler.  The procedure to obtain a LetsEncrypt certificate is set out in Appendix N.

•It is also possible to have the Gateway generate a 'self-signed' certificate.  This is done if TLS is selected in GWMANAGER and no certificate file name and password are entered.  This will cause TLS security to be enabled, but a number of e-mail senders will decline to send e-mail to a server which uses a self-signed certificate.  Unless all your e-mail senders are in-house and are known to accept this type of certificate, this option is not recommended.

We suggest that you save the domain password file (for example for domain fax.company.com as faxcompany.pfx or faxcompany.p12, where the choice of file extension depends on the browser from which you export it.  The recommended folder to save your private key files is the GWRecipientDomains folder, normally in COPIA\FAXFACTS.

3. Configure the Certificate in GWMANAGER

Select one of the TLS options in GWMANAGER. The choices are:

Optional will allow non-TLS connections, ensuring that the Gateway can accept e-mail from all the senders whom you permit to send mail.
Required will reject incoming e-mail if TLS is not used, so that only servers which support TLS can send e-mail to the Gateway. The e-mail will be saved in the 'rejected messages' folder, and the MSG file can be opened by most e-mail client programs (some may need it renamed to .EML).

After checking the box, enter the path name of your certificate file, and its password:

When you apply or save the changes the certificate will be loaded to test that the path and password are valid.

4. Save the Password in the CFHWL Password Vault

The SSL Certificate password is saved encrypted in the registry, so using an encrypted variable for this password is not essential; however we recommend that you save it with your other passwords used in CopiaFacts in the CFHWL password vault.  If SECRET1 is already in use for an S/MIME Digital ID password, you could save the SSL Certificate password in SECRET2.

Follow the instructions to set up encrypted passwords in the CFHWL topic.

5. Test the TLS security

TLS security in the CopiaFacts gateway only affects the last leg of the route taken by an incoming e-mail.  If you send a test e-mail from your normal e-mail client to the Gateway, it may be delivered by a server that does not support TLS.  If you have a Gmail account, a test e-mail sent from there to the Gateway will always use TLS if offered.  Sending an e-mail from CopiaFacts can also specify the useTLS in $email_options, and will by default connect using the MX record of your gateway.

To determine if TLS was used by CFGATEWAY for the test e-mail you sent, open the .MIF file in Notepad and look for the line UsedTLS=1.  If your test e-mail sent in a document to be faxed, you can also open the FS file which sent the fax in STATUS and look for a command:

$var_def SMTP_USED_TLS yes