Please enable JavaScript to view this site.

CopiaFacts™ Reference Manual

Navigation: Appendices > Appendix N: Secure E-Mail

Using a Sectigo Certificate in the SMTP Gateway

Scroll Prev Top Next More

Commercially-available Sectigo (formerly Comodo) SSL Certificates can be used to implement inbound TLS Secure E-Mail in the CopiaFacts SMTP Gateway.  Depending on which type of SSL certificate you select there may be a validation procedure to complete before the certificate can be issued. Sectigo certificates are also available from Sectigo resellers.

Before acquiring the certificate, consider whether you may need TLS support for more than one domain.  The CopiaFacts SMTP Gateway can currently install only a single certificate, but it can be either for a single domain (e.g. fax.company.com) or a 'wild-card' certificate (e.g. covering all sub-domains of the form *.company.com).

If you need to give an administration e-mail address to the supplier, do not use the domain of the SMTP gateway for which you are purchasing the certificate. You may need to be able to acquire the certificate and respond to notifications from the supplier before you have completed the setup of the Copia gateway.

The certificate will be issued and installed in your browser.  Follow the instructions in one of the earlier topics in this section to export the certificate and save it as a .PFX file, with a password.  Make a note of the expiration date of your certificate, because you may not receive a reminder about this from Sectigo.  Save the certificate in a local folder on the machine running CFGATEWAY.

In GWMANAGER, enter the certificate pathname and password.  When you save the settings, the certificate will be test-loaded to check that the password and path are correct.

To test the certificate, send an e-mail to the gateway and check that the SMTP_TLS_USED variable is set to 'yes' in the generated FS file.  If you send an e-mail from your normal e-mail client, it is possible that TLS will be dropped somewhere along the path taken by the e-mail to your server, so preferably send a CopiaFacts e-mail using FFCLIENT with $email_options usetls defined on the Setup page.  The SENT FS file will then also report TLS_USED as a $var_def to confirm that TLS has been used.

For more details of the above procedure, see the Implementation Checklist for secure Gateway operations.