|
ITS Knowledge Base
About the ITS Help
Desks
Search:
Other
Topics:
|
|
Reconfiguring Email for POP Using Secure
Socket Layer (SSL)
Important
Reminders:
Added 1/28/2005
-
Because SSL configurations are client-based
(i.e Eudora, Mac Mail, Outlook), you MUST change your setting on all of your
machines that use ITS mail. This includes your machine(s) at home, machines
used for travel and portable devices.
In addition, if you use more than one email
client (with the exception of WebMail), you must also change your settings on
each of your email clients on each of your machines as well.
-
If you are using Yahoo.com to check your ITS
email, please be advised that beginning February 1, 2005, you will NO longer be
able to do this. You will only be able to FORWARD your email to
Yahoo.com.
|
The Internet is not a secure place. When you
perform online banking or other sensitive transactions over the web, your
information is encrypted to prevent someone from stealing your personal data.
Currently when you check email using an email client such as Eudora or Outlook,
your userid and password are sent over the internet and could potentially be
stolen. Someone who knows your access account userid and password can read your
email, view your grades, access personal financial data, and even change your
classes.
To protect your Penn State access account
userid and password from being sent as clear text, Information Technology
Services (ITS) is implementing SSL encryption on the email servers. (This is
the same type of encryption used on secure web pages.) SSL is available now and
will become mandatory in January 2005.
If you use Penn State WebMail, Kerberos
(KPOP) or an email server other than email.psu.edu or mail.psu.edu
exclusively, this will not affect you. On the other hand, if you have received
an email message from the ITS Help Desks regarding your email account, you
have checked your email on either the email.psu.edu or mail.psu.edu
server and will need to follow the instructions below for your email
client.
Below are the instructions for configuring
SSL for incoming email for the most popular email clients.
| Windows |
Mac OS 9 and Above |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Important Notes for Mac
Users:
-
We recommend that Mac 8.x users use Kerberos
Authentication instead of SSL. Information and instructions can be found on
our Kerberos for Macintosh Web page at
http://helpdesk.psu.edu/kerberos/mac/kerberos.html.
-
Mac OS 10.x users below 10.2 need to upgrade their operating
systems to Mac 10.2 before reconfiguring their email client.
Windows
- Start Eudora.
- In the Tools menu, click Options.
- Go to the Checking Mail category.
- Set Secure Sockets when Receiving to
Required, Alternate Port.
- Click OK.
Note: If you have
multiple personalities set up in Eudora for your Penn
State email (email.psu.edu OR mail.psu.edu), you will need to
configure each Penn State email personality for SSL using the following
instructions:
- Under Tools, select Personalities.
- In the Personalities window on the left hand
side of the screen, right click on the personality
for Penn State email that needs to be
configured.
- Select Properties.
- In the Account Settings window that appears,
select the Incoming Mail tab.
- Set Secure Sockets when Receiving to
Required, Alternate Port.
- Click OK.
- Start Mozilla Mail.
- In the Edit menu, click Mail & Newsgroups
Account Settings.
- Expand your account details by clicking on the +
(plus) or the > (arrow) sign.
- Next, click on Server Settings.
- Click on the box to the left of Use secure
connection (SSL).
- The Port number should automatically change to
995.
- Click OK.
- Start Outlook Express.
- Next, select Tools->Accounts.
- Click on the Mail tab.
- Next, select your account.
- Click on Properties.
- Click on the Advanced tab on the
Properties window.
- Click on the box to the left of This server requires
a secure connection (SSL) immediately below
the Incoming Server heading.
NOTE: Make
sure that you have not checked Outgoing Server. The Outgoing
Server check box should be left blank or unchecked.
- The Incoming mail (POP3) server port number
should automatically change to 995.
- Click OK.
- Start Outlook.
- Next, select Tools-> Email Accounts
- Select View or Change Existing Accounts.
- Click the Next button.
- Select your email account.
- Click Change.
- Click on More Settings.
- When the Internet E-mail Settings dialog box
opens, click on the Advanced tab.
- Click on the box to the left of This server requires
a secure connection (SSL) under Incoming Server.
- The Incoming mail (POP3) server port number
should automatically change to 995.
- Click OK.
- Click Next.
- Click Finish.
- Start Outlook.
- Next, select Tools-> Email Accounts
- Select View or Change Existing Accounts.
- Click the Next button.
- Select your email account.
- Click Change.
- Click on More Settings.
- When the Internet E-mail Settings dialog box
opens, click on the Advanced tab.
- Click on the box to the left of This server requires
an encrypted connection (SSL) under Incoming Server.
- The Incoming mail (POP3) server port number
should automatically change to 995.
- Click OK.
- Click Next.
- Click Finish.
- Start Outlook .
- Next, select Tools-> Account Settings
- Click on the Email tab.
- Select your email account .
- Click Change .
- Click on More Settings .
- When the Internet E-mail Settings dialog box opens, click on the Advanced tab.
- Click on the box to the left of This server requires an encrypted connection (SSL) under Incoming Server .
- The Incoming mail (POP3) server port number should automatically change to 995 .
- Click OK .
- Click Next .
- Click Finish .
- Start Thunderbird Mail.
- In the Tools menu, click Account
Settings.
- Expand your account details by clicking on the +
(plus) sign.
- Next, click on Server Settings.
- Click on the box to the left of Use secure
connection (SSL).
- The Port number should automatically change to
995.
- Click OK.
Mac OS 9 and Above
Important Notes:
-
If you are using OS 7.x, we do not have a
solution for configuring your Eudora for SSL.
-
If you are usingg OS 8.x, you will need to use
Kerberos Authentication instead of SSL. Information and instructions can
be found on our Kerberos for Macintosh Web page at
http://helpdesk.psu.edu/kerberos/mac/kerberos.html.
In addition, we have found that Eudora 5.1 seems to work the best with OS
8.x.
-
If you are running OS X and wish to use SSL
when checking mail, you must have OS X 10.2 or later installed. To be
safe, always have all OS X updates from Apple installed.
-
You must also use Eudora version 5.2 or
later although we recommend users upgrade to 6.x. Previous versions
are incompatible with Eudora's use of SSL. Upgrading to Eudora 6.x is
especially important for users running OS X as we have seen numerous
issues with trying to configure Eudora 5.2 on this operating system.
-
If you are running Panther (the Mac OS 10.3)
there might be an error. Please look at Eudora's web page at
http://www.eudora.com/techsupport/kb/2492hq.html
on the Web.
- Start Eudora.
- Next, click on Special > Settings.
- Select SSL from the list on the left (towards
the bottom).
- You will need to change to the following
settings:
| SSL for POP: |
Required (Alternate Port) |
| Standard Port SSL Negotiation: (Eudora 6.x only) |
Maximum Compatibility |
| Alternate Port SSL Negotiation: (Eudora 6.x only) |
Maximum Compatibility |
Note: If you
have multiple personalities set up in Eudora for your
Penn State email (email.psu.edu OR mail.psu.edu), you will need to
configure each Penn State email personality for
SSL.
- Click OK to save the settings.
Important Note: Some
people have had a problem checking email after enabling SSL. It seems to be a
problem involving the Keychain and an SSL certificate.
We recommend users enable the Keychain first.
The instructions for enabling the Keychain and
installing an SSL certificate are:
For Version 1.3.9:
- Launch Mail.
- Next, select Preferences from the Mail
menu.
- In the Preferences window, click the
Accounts button.
- Next, select your account in the list on the
left.
- Next, select the Advanced tab on the top of the
Preferences on the right.
- Check the Use SSL checkbox at the bottom of the
window.
- Then choose Password in the
Authentication popup menu.
- Click OK.
For versions prior to
Version 1.3.9:
- Launch Mail.
- Next, select Preferences from the Mail
menu.
- In the Preferences window, click the
Accounts button.
- Next, select your account.
- Click Edit.
- Next, select the Advanced tab on the top of the
Account Information window.
- Check the Use SSL checkbox.
- Then choose Password in the
Authentication popup menu.
- Click OK.
- From within Mozilla Mail, open the account
settings window.
- Go to Edit > Mail and Newsgroup Account
Settings.
- Expand your account details by clicking on the +
(plus) sign.
- Click on Server Settings.
- Click on the box to the left of Use secure
connection(SSL).
- The Port number should automatically change to
995.
- Click OK.
- Start Entourage.
- Select Tools menu.
- Next, select Accounts.
- In the Account Dialog box, click the
Mail tab.
- Double click on your account.
- Under the Receiving Mail category, click on
Click here for advanced receiving options.
- Check the box for This POP service requires a secure
connection (SSL).
- The POP port will change to 995.
- Click in the small close box in the upper left
corner of the small window.
- Click OK in the Accounts window.
|
|