Clearswift SECURE Email Gateway 4.7.0 ReadMe

On installing this update, your Gateway will be updated to version 4.7.0.

Earlier updates that you have not already installed will be installed as part of this update. To see the readme file for earlier updates see the Gateway update ReadMes v4 section.

Important

This upgrade adds a number of new features and addresses a number of security issues. We strongly recommend that you upgrade as soon as possible to benefit from these new features and to ensure that you are fully protected.

 

If you are using mandatory TLS settings, when you upgrade, mail flow is stopped. Following the upgrade, you must modify the mandatory TLS settings in your Connection Profiles before you can enable mail flow.

If you have significant configuration changes to make on upgrade, one possible approach is to add an additional peer that won't carry traffic. Upgrade this peer and perform the configuration changes, then apply that configuration to each existing peer as it is upgraded.

Security Technical Implementation Guides (STIGs) contain technical guidance to "lock down" computer systems that might otherwise be vulnerable to a malicious computer attack. They are administered by the Defense Information Systems Agency (DISA) in the United States through the Information Assurance Support Environment (IASE). Clearswift Gateways are now compliant with a number of STIGs. You can access a whole-system report that details the compliance level of this release in the STIGs compliance report.

In addition, other security guides are available through the open source OpenSCAP framework and associated policies.

After installation or upgrade, if you would like to generate a manual system evaluation for STIGs compliance, you will need to contact Clearswift Technical Support.

Improvements and new features in version 4.7.0

Postfix replaces Sendmail

Postfix replaces Sendmail as the Clearswift Email Gateway's Message Transport Agent (MTA). This allows Clearswift the ability to more easily distribute Red Hat security fixes and implement features, such as TLS, that more closely match customer expectations on a more up-to-date MTA.

As part of this improvement, a number of changes have been made to the functionality and user interface of the Clearswift Email Gateway.

 

As the Message Transport Agent (MTA) provider has been changed from Sendmail to Postfix, the log format has also changed. If you are exporting logs to a third-party syslog tool, Clearswift recommends installing this release in a sandbox environment initially to review the log format and update your syslog environment before upgrading.

Inbound and outbound TLS

As a global setting, there is now a single option for enabling opportunistic inbound and outbound TLS. Mandatory TLS is configured on Connection Profiles for inbound TLS, and routing for outbound TLS. Connection Profiles include a list of Client Hosts, which can be IP addresses or host names, and Sender Domains. In this version, the Clearswift Email Gateway uses Sender Domain names to select a profile for TLS but not for relay control or SMTP Authentication.

Outbound TLS configuration is no longer based on the IP address of the receiving MTA and instead is based on the destination email domain.

Inbound and outbound TLS settings within Connection Profiles have been restructured and simplified.

The High cipher list has been updated as part of this release.

Queue management

Two new message queues - SMTP Inbound and SMTP Outbound - have been added to the Message Center Home page. These queues are integral to Postfix and, while this increases the number of queues to a total of five, the queue directories are more detailed than Sendmail's directories. On upgrade, any messages in the Dispatch Retry queue are moved to the SMTP Outbound queue.

Message tracking

You can track messages from the 4.7.0 Gateway to selected peers of any version.

New DKIMClosedDomainKeys Identified Mail signing option

If you have enabled DKIM signing on outbound messages in the SpamLogic Settings page, you can optionally choose whether to enable If the message sender is empty, sign using the key for the domain of the From address in the DKIM signing on outbound messages section. The DKIM signature is added per sender domain, which previously excluded out-of-office replies as the default, expected behavior. This new option now allows you to apply DKIM signing to out-of-office replies and similar messages that have empty message sender fields.

Additional improvements

There are a number of new features included in this release:

For more detail on these new features and how you can use them, see What's New in 4.7.0 in the online help.

What's different?

There are also a number of changes included in this release:

Server Console changes and STIGs compliance

Cryptographic Message Syntax

S/MIME Signature Algorithm

Message tracking

Logging Levels

Queue management

Inbound and outbound TLS

SMTP authentication

Email routing

Retention Time extension

Address Rewriting

%LOCALDATE% token

Before you install or upgrade the product

 

We strongly recommend that you follow the installation steps outlined in the Clearswift SECURE Email Gateway Installation & Getting Started Guide. These instructions enable you to install the product correctly and safely.

If you are migrating from a previous version of the Clearswift SECURE Email Gateway, you must:

  1. Apply any pending configuration changes.
  2. Back up your system and latest configurations before installing.
  3. Clear the inbound queues.

If you are upgrading from an earlier version 4 release to version 4.7.0, you need to also:

  1. Check if you are using custom Sendmail configuration files. These are customin.m4 and customout.m4 files in /etc/mail. You are advised to contact Clearswift Support to discuss how to migrate these settings.
  2. Check if you are using mandatory TLS settings. These settings will need to be modified after the upgrade. If you are using mandatory TLS settings, when you upgrade, mail flow is stopped. You must:
    • Configure mandatory Outbound TLS settings on individual Connection Profiles. Specify the Connection Profile for each routing table entry in the Email Routing page that requires a mandatory TLS connection.
    • Ensure that for Outbound TLS, SAN/CN matching values do not include whitespace characters.
    • Restart mail flow by starting the following services: SMTP Inbound Transport, SMTP Outbound Transport, and SMTP Alert Transport.
  3. Check your email routing failover procedures. Postfix does not attempt multiple routing table entries on initial failure and must be set up so that routing is performed by DNS, using a DNS record for the domain with multiple "A" records. Ensure that your failover procedures take this into account. For more information, refer to Specifying Routing of Email.
  4. If you are using address rewriting, note that the Validate Sender Domain check is now performed on the original address, not the rewritten address.
  5. Change your AUTH profile user names and passwords, if you are using the same user name on different profiles. For more information, refer to SMTP Authentication.

For further information on how to upgrade, refer to Upgrading from an earlier version 4 release to version 4.7.0.

Detailed instructions on backup and restore are available in the Clearswift SECURE Email Gateway Installation & Getting Started Guide.

 

Installing the product

You can install the SECURE Email Gateway from the ISO image available for download in the Clearswift download area.

Full installation instructions are provided in the Installation and Getting Started Guide.

Upgrading from an earlier version 4 release to version 4.7.0

Perform the following steps to download and apply software updates when you upgrade to Clearswift SECURE Email Gateway 4.7.0.

Open an SSH session and access the Clearswift Server Console. Log in using your cs-admin access credentials.

 

Online or Offline mode?

Offline mode is designed for installations that operate in a closed environment, disconnected from the Internet. Unless this is a specific requirement for your system, you should install the Clearswift SECURE Email Gateway in online mode.

To perform an offline upgrade you require a copy of the latest release ISO mounted to suitable media (DVD/USB). Please contact Clearswift Technical Support if you need additional guidance on how to complete this step.

If you have online repositories enabled, updates will be downloaded overnight (automatically). You can apply them immediately. You can also use the Check for New Updates button if you believe that there has been a recent security fix issued.

To apply software updates:

  1. Select Configure System > View and Apply Software Updates > Apply UpdatesOK from the Clearswift Server Console main menu.
  2. Select Yes to confirm that you want to apply the updates.
    All downloaded updates will now be installed. This process can take several minutes. A rolling progress log will be displayed.

  3. When the Operation Complete message appears, select Done to complete the install process.

At the end of the upgrade process, the system will prompt you to either reboot or log out. Follow the instructions on-screen.

Gateway services will restart automatically in either case.

After you have upgraded, you need to:

Fixed Issues

This update includes the following fixes, which have been implemented in version 4.7.0:

Known issues

See Known Issues for Email 4.7.0 for a list of known issues or limitations in this release.

Product version end of life

Note the following end of life information:

For more details, see the End of Life statement.

Contact information

For contact details, information on product updates and other products, see the Clearswift Website.

Revision 1.0 November 2017

Published by Clearswift Ltd.

© 1995-2017 Clearswift Ltd

All rights reserved

The materials contained herein are the sole property of Clearswift Ltd. No part of this publication may be reproduced or disseminated or transmitted in any form or by any means electronic, mechanical, photocopying, recording, or otherwise stored in any retrievable system or otherwise used in any manner whatsoever, in part or in whole, without the express permission of Clearswift Ltd.

Information in this document may contain references to fictional persons, companies, products and events for illustrative purposes. Any similarities to real persons, companies, products and events are coincidental and Clearswift shall not be liable for any loss suffered as a result of such similarities.

The Clearswift Logo and Clearswift product names are trademarks of Clearswift Ltd.

All other trademarks are the property of their respective owners. Clearswift Ltd. (registered number 3367495) is registered in Britain with registered offices at 1310 Waterside, Arlington Business Park, Theale, Reading, Berkshire RG7 4SA, England. Users should ensure that they comply with all national legislation regarding the export, import, and use of cryptography.

Clearswift reserves the right to change any part of this document at any time.

Copyright © 1997-2017 Kaspersky Labs, 10 Geroyev Panfilovtsev St., 125365 - Moscow, Russian Federation. The Kaspersky Logo and Kaspersky product names are trademarks of Kaspersky Labs.

Copyright © 2000-2017 Sophos Limited. All rights reserved. Sophos is a registered trademark of Sophos Limited and Sophos Group. All other product and company names mentioned are trademarks or registered trademarks of their respective owners.

Licensed under US Patent No:5,623,600

Protected by UK Patent 2,366,706

The software allows Clearswift to collect certain data from you regarding spam and other unwanted emails. Clearswift will use this information to improve its service to you (defined as the "Support Service") in the license agreement. Clearswift will use all information provided in accordance with the license agreement and Clearswift's stated privacy policy which can be found at http://www.clearswift.com/about-us/legal-information .

Click here to read Copyright and Acknowledgments in full.


© 1995–2017 Clearswift Ltd.