Questions on Security & Authentication Features in SmarterMail
Problem reported by Pusparaj Raut - Today at 12:32 AM
Submitted

We have a SmarterMail Enterprise deployment and have a few security and authentication-related queries:

1. Mailbox Data Encryption:

  • Does SmarterMail support encrypting mailbox data at rest — either via full-disk encryption or per-mailbox encryption?

  • Is there support for Hardware Security Modules (HSMs) for key management?


2. Audit Logging:

  • Does SmarterMail maintain a detailed audit trail of both administrator and user activities?

  • If yes, what level of granularity is available (e.g., login attempts, configuration changes, message access, etc.)?

3. Authentication:

  • Is RADIUS authentication supported for user or administrator logins?

  • If so, could someone share configuration details or known limitations?

4. Session Management:

  • Is there any enforced limit on concurrent user or administrator sessions?

  • Is it possible to define session timeout durations for security purposes?

Any official documentation links or experiences from others who have implemented these features would be greatly appreciated.

Gabriele Maoret - SERSIS Replied
I can give you some tentative answers, but for an official response you'll have to wait for SmarterTools...


1. Mailbox Data Encryption:
SmarterMail doesn't have any built-in encryption tools. You'll have to rely on third-party tools (e.g., BitLocker).


2. Audit Logging:

  • Does SmarterMail maintain a detailed audit trail of both administrator and user activities?

Yes, you can find it in the Administrative LOGS and in the LOGS of the various protocols (POP3, IMAP, SMTP, MAPI, EWS, EAS, etc.)

  • If yes, what level of granularity is available (e.g., login attempts, configuration changes, message access, etc.)?

It's quite granular, and you can set the log levels between Exceptions Only, Normal, and Detailed.
However, it's up to you to decide if they're complete enough; there's no exhaustive documentation.
In my opinion, most of the logs are complete enough, but others (especially the ability to see user activity such as deleting/moving/etc. on emails) are a bit less comprehensive than I'd like and are confusing (compared to other products like Kerio Connect or MailEnable).


3. Authentication:
SmarterMail has limited integration with LDAP or AD, but I don't believe RADIUS.

4. Session Management:

  • Is there any enforced limit on concurrent user or administrator sessions? NO

  • Is it possible to define session timeout durations for security purposes? YES for webaccess, NO for others

Gabriele Maoret - Head of SysAdmins and CISO at SERSIS Currently manages 6 SmarterMail installations (1 in the cloud for SERSIS which provides services to a few hundred third-party email domains + 5 on-premise for customers who prefer to have their mail server in-house)
Pusparaj Raut Replied
Hi Gabriele, 
could you please guide me on how we can define a web session?

Gabriele Maoret - SERSIS Replied
Hi Pusparaj!

I'm not a SmarterTool technician; I'm a customer like you, who purchased SmarterMail and uses it at my company...

At this time, I can't offer you a web session to resolve your SmarterMail questions... You'll need to contact SmarterTools for that...

My response was just to help you and give you some advice as a forum user, since I've been using SmarterMail for a while and know a few things...

But if you need further information, since I'm a customer like you, I'm not the right person. It's best to contact the vendor directly.
Gabriele Maoret - Head of SysAdmins and CISO at SERSIS Currently manages 6 SmarterMail installations (1 in the cloud for SERSIS which provides services to a few hundred third-party email domains + 5 on-premise for customers who prefer to have their mail server in-house)

Reply to Thread

Enter the verification text