• Delicious
  • Sales: 0800 634 6513
    General: 0845 053 0371

news and info

Using LetsEncrypt with VPOP3 Enterprise v9.0 and later

First of all, to do this you need VPOP3 Enterprise v9 as it supports dynamic updating of certificates, and the ability for an ACME client to update the web data dynamically, and for LetsEncrypt to access the ACME data.

LetsEncrypt commonly works by an ACME client utility on the web server computer injecting dynamically generated authentication data into the website, then calling an API at LetsEncrypt which validates this authentication data and issues a certificate.

This means that for this to work, VPOP3 must be publishing its Webmail onto the public Internet on port 443.

Making Webmail accessible

So, you need to go to Services -> Webmail Server and add a binding for the relevant IP address (or ‘[Any]’) on port 443. You can keep the binding for port 5108 if you wish, for backwards compatibility.

If there is some reason that you cannot do this, eg you don’t want to make Webmail accessible from outside, or you are using port 443 for something else, then you cannot use the instructions in this article. Instead, you would have to use DNS authentication for LetsEncrypt. Some parts of the article may still be useful, but as DNS authentication requires integration with your DNS service, there are too many possible options, and that is outside the scope of this article.

You also need to set up your firewall/router to allow incoming connections on port 443 to go to the VPOP3 computer (using Port Forwarding or similar).

You must also set the IP Access Restrictions for the Webmail service to allow access from outside. So, go to the Services -> Webmail -> IP Access Restrictions tab and add a restriction to Allow – Any. Note that you can restrict it to certain users if you wish, LetsEncrypt will not be logging in, so only needs basic access

Check that Webmail is accessible from outside your network before continuing. Note that you do not need to be able to log in from outside, but the Login form must be accessible

Priming with a certificate

Next you must add a certificate into VPOP3 manually. This is needed because the functionality in this article just updates that certificate. VPOP3 will only refresh its certificate if a previous certificate already existed.

To do this, go to Services -> General -> SSL/TLS and press the ‘Add’ button and enter the certificate and key. For this article we will assume that this is the only certificate in VPOP3. VPOP3 v9 supports multiple certificates and can use SNI to determine which certificate to use, but that is beyond the scope of this article

The certificate you enter here can be a globally signed certificate or a self-signed certificate. It does not matter as it will be replaced soon. I have put a basic self-signed certificate below in case you can not easily create your own

Private Key

-----BEGIN PRIVATE KEY-----
MIIEvAIBADANBgkqhkiG9w0BAQEFAASCBKYwggSiAgEAAoIBAQDRfOh6TZq+SDeA
5oFqA3fnixOQj2R2hoRX8eTzOi3VWCR2Sl94QT48PcvBTJ7Jet9ri+gBgJ1AZslm
C+Ssg1yJ71LaFQ5W32A8d0P7YeCPkhhTnjN4UdIKA3aqqGyMdA90LxjEBf8SbzLI
BcGzOAJQoHlGO72banc7qnH6ciJbzcqG1QF2/710/72hkGqbhSmQi5/McaE9mRaA
ZC1qQfpfGJGbOllUa6XGiO30dp/0PyWgDtxk8ejKkoDpptdB2pjJPvCRErZXUxx3
QoPZrkFeeaRO/OXOJcCxi9AoGxeJVBIVG6DOZLk2gYkqR/62Kq+iI2UnSOJwHh6K
8rjHZd1vAgMBAAECggEAQD3HRxY8UYTw7GkDn8CPiSR3q/mlK8nFlPibptEdFBMz
H0lgbI7JaIzkypLWEOBK2n6td6R61LCQq2gTSKoB+1S2eiVB3/chWnmSkejqheyd
5CqcCxZATIzSW7RJkWrYAF+e/yH9nigWkQte4rhW0WXcuuKAG0RzawsyZ8SPb8om
TNBh2V8AFin4eWMKxgtbRKrt9YWkcTaErtiJAG+w2DMDB892OemZxQScQB8g4QtU
aIyCODbRyc4XTlb2w/Lu8RRl1SyNzKUS46jbxMC8n4b6ETei9hcswowsTITU0VWv
8heie5/xfdpOIH/lc8Oatdeew5JhhNID/6hTUfkhbQKBgQDztoLnS/ppCnM/d9i9
VN6J1s3LHTmkEPr+g+SDyG/LXrO6KA/CNsbu/13YrOLSO0BdhZaypwXw5MF6WRb3
cpxEZcDIIpZ1nJafSHTGa61c8E438QNNwPx8nXqvhD6hQOVPs/N2BeLW5nNhpUAb
nQUs3Be/dxiRIw2ukSAtjKZPJQKBgQDcDKuqrSPyIoPmO8Kxbw3Iwqly030Ubd4y
0gi7E7iNJhZSfnCDuVQJQSD9xNMHNoSrnDmfdnYssDkrWKVCheVmwArF05mr3yy3
QiFaO1uGKP7DVShiZX8vW3uZZjooY3gCguRoKfQIhCsr7E82rqtv/gSbsWJeuWZO
UFJHo2wwAwKBgFrRenqC36/hCw1ttcDoLX2kJFA6dc5j3YSW1cMeIDri8Yq/fw/a
pctOMkSaOHQrTFMNgxjUEOyx8j+Lj3lqpjz+xhZOfU8aqS52K739Rj9J9Xv3Pknt
TqmJbbyWRViF/G31GxayHtQCUKDkmb0wiEstQVRCJ09+hoy03A7dSORZAoGAe2E3
V6lgwEEOB6d2UJpd9jT/YXynYy7/KSuO7aXvEmVKmtJ+L71YGyBDaUZUtHSjCr27
qWd4dzIPu/gmIRiGOYhwAd/VCANIRTB1Fuy1MpIF1mwHCrSyDVGUCbzB2yd6gJ33
h1gOlj/VHPmQqK5jPZYF624YI9h8PmjW2YgN/xUCgYBioyTo/P5CbM+TuWSS0LFk
tWyKljKAmSB311jaW0DS5QZ3H+KuosLkVfxjUfAwLXMv8tmMQ1dEdBY8VQAS5M7T
+ppKWRvbBViBUGf4JKh1j7elW4hZDjYKo7CzKxMfLt2dMyYt8E08CtOcvMCFNXR7
j5or/uZ+DeTAUZxE1ofwrg==
-----END PRIVATE KEY-----

Certificate

-----BEGIN CERTIFICATE-----
MIIDkzCCAnugAwIBAgIUANtKgUN9fKtOxAqHR3QEIHDygk4wDQYJKoZIhvcNAQEL
BQAwWTELMAkGA1UEBhMCQVUxEzARBgNVBAgMClNvbWUtU3RhdGUxITAfBgNVBAoM
GEludGVybmV0IFdpZGdpdHMgUHR5IEx0ZDESMBAGA1UEAwwJbG9jYWxob3N0MB4X
DTI2MDgxMTA4MjU1NVoXDTM2MDgwODA4MjU1NVowWTELMAkGA1UEBhMCQVUxEzAR
BgNVBAgMClNvbWUtU3RhdGUxITAfBgNVBAoMGEludGVybmV0IFdpZGdpdHMgUHR5
IEx0ZDESMBAGA1UEAwwJbG9jYWxob3N0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
MIIBCgKCAQEA0Xzoek2avkg3gOaBagN354sTkI9kdoaEV/Hk8zot1VgkdkpfeEE+
PD3LwUyeyXrfa4voAYCdQGbJZgvkrINcie9S2hUOVt9gPHdD+2Hgj5IYU54zeFHS
CgN2qqhsjHQPdC8YxAX/Em8yyAXBszgCUKB5Rju9m2p3O6px+nIiW83KhtUBdv+9
dP+9oZBqm4UpkIufzHGhPZkWgGQtakH6XxiRmzpZVGulxojt9Haf9D8loA7cZPHo
ypKA6abXQdqYyT7wkRK2V1Mcd0KD2a5BXnmkTvzlziXAsYvQKBsXiVQSFRugzmS5
NoGJKkf+tiqvoiNlJ0jicB4eivK4x2XdbwIDAQABo1MwUTAdBgNVHQ4EFgQU54YH
pIa+p0sDQoZhJ4HBwtMaHMgwHwYDVR0jBBgwFoAU54YHpIa+p0sDQoZhJ4HBwtMa
HMgwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAKkCZeFqA0BtV
2+36R7Ux+baYp8QWqewZqG4R5tCc6wNy3ioxlNsl1uaN31FpNG51uW1vMfX5ndWT
bEATpmOrtwoywGU3AzVyLZl+uTilG4JHvThxZW97tXLidBh2HBN0zywM2keX/c1u
b5wp6YHmK5uHlwhuxtmmauDNewRHC8w7MYUVlgZ5dqfwDKIgGe8aNFLw/AVHdYz3
UxQhI6IYb3/f1OZ0U2920riqwBBgqgXA45sL4udl8iQkXTBCJEWis17mk+NAzOqH
NeMQlYjoGqPvV5LCd3bS1hgnUT9vddnZioDyr5nU4S/HqFhUNCj4gcUcvwOWtx+F
KT5U8X1hqQ==
-----END CERTIFICATE-----

Installing Powershell

For this article we will be using a Powershell script and using the PoshACME ACME client to authenticate with LetsEncrypt. We need Powershell 7 instead of Powershell 5 which is usually installed as standard

Instructions for installing Powershell 7 are available here. It is straightforward and usually doesn’t require a Windows reboot. It doesn’t replace Powershell 5, so existing Powershell scripts and functions should continue working as before
https://learn.microsoft.com/en-us/powershell/scripting/install/install-powershell-on-windows

Installing PoshACME

Once Powershell 7 is installed, open a Powershell 7 prompt, and install PoshACME by running

install-module -name posh-ACME -Scope AllUsers

In case you are interested, the documentation for PoshACME can be found at https://poshac.me/docs/latest/

Initial PoshACME setup

Now, you need to tell PoshACME to use LetsEncrypt

Set-PAServer LE_PROD

(For testing, you could use LE_STAGE instead of LE_PROD. LE_STAGE doesn’t produce usable certificates, but also doesn’t have rate-limiting in place)

Then, you need to create an account at LetsEncrypt (if you do not already have one)

New-PAAccount -contact <email address> -AcceptToS

Now, create a text file in the main VPOP3 directory called ‘cert.ps1’ and copy/paste the following content into it

#Install PowerShell 7
#
#install-module -name posh-ACME -Scope AllUsers

# New-PAAccount -contact <email> -AcceptTOS

# Scheduled Task
#      <Command>"C:\Program Files\PowerShell\7\pwsh.exe"</Command>
#      <Arguments>c:\vpop3\cert.ps1 <domain> <email></Arguments>
#      <WorkingDirectory>c:\vpop3</WorkingDirectory>

param (
 [String]$domain,
 [String]$email
)

# Uncomment the line below to write transcript to 'cert.log' file
#Start-Transcript -Append .\cert.log

function Deploy_test {
  param (
   $cert
  )
  echo $cert 
  echo $cert.FullChainFile
}

function Deploy {
  param (
   $cert
  )
  echo $cert.KeyFile
  .\vpop3settings setfromfile sslpkey $cert.KeyFile
  .\vpop3settings setfromfile sslcert $cert.FullChainFile
  .\vpop3settings set sslreload 1
  echo "Certificate Installed"
}

$pArgs = @{
    WRPath = '.\_webmail'
}

if (Get-PAOrder $domain) {
 echo "Try Renewal of $domain"
 if ($cert = Submit-Renewal $domain -Verbose) {
  Deploy $cert
 }
} else {
 echo "Try New Order of $domain"
 if ($cert = New-PACertificate $domain -Verbose -Plugin WebRoot -PluginArgs $pArgs -AcceptTOS -Contact $email) {
  Deploy $cert
 }
}

Now, in the Powershell prompt, go to the VPOP3 directory and run

.\cert.ps1 <domain> <email address>

eg

.\cert.ps1 example.com support@example.com

This should make the script obtain a certificate for the specified domain, and install it into VPOP3

Setting up automatic certificate renewal

You can use Windows Task Scheduler to run the script automatically every day. It will renew the certificate when it comes close to expiry.

Open Windows Task Scheduler, and click on Create Basic Task.

  1. In Name put ‘Renew SSL certificate’ or similar. Press Next
  2. In Trigger, choose Daily. Press Next
  3. For Action, choose Start a program
    • For Program/script enter the Powershell path – eg c:\program files\powershell\7\pwsh.exe
    • In Add Arguments, enter c:\vpop3\cert1.ps <domain> <email address>
      (adjust the path and parameters as necessary)
    • In Start in, enter c:\vpop3
      (adjust the path as necessary)
    • Press Next
  4. Select Open the Properties dialog for this task when I click Finish. Press Finish
  5. On the properties tag, choose Run whether user is logged on or not. Press OK You should be prompted to enter the account information for running the task, so enter the user details for someone with full-access permission to the VPOP3 installation directory and subdirectories (eg an administrator user)

Notes

  • If you have multiple certificates, you need to alter the ‘.\vpop3settings setfromfile’ lines in the cert.ps1 script (lines 33 and 34). Eg, the second certificate will need ‘setfromfile sslpkey-1’ and ‘setfromfile sslcert-1’ etc. You can use ‘vpop3settings get sslpkey*’ to get a list of the private keys in VPOP3 along with their setting names, and adjust the script accordingly.
  • If the script fails to install the certificates, when you run it again, it will not do anything because the certificate is not due for renewal yet, so you can edit the ‘Submit-Renewal’ command (line 45) to add ‘-Force’ after ‘-Verbose’). You should remove the ‘-Force’ afterwards to avoid unnecessary renewals

If you

Post a Comment