Author Topic: Avast 4.7 and SSL  (Read 6507 times)

0 Members and 1 Guest are viewing this topic.

2007i

  • Guest
Avast 4.7 and SSL
« on: January 29, 2007, 03:05:38 AM »
my OE6 accounts (smtp/pop3) run over a SSL on port 995 and 465

setting the ports accordingly in the 'Internet Mail' scanner - makes OE6 unable to fetch any mail. only the default ports seem to work?

ideas?

st.


joeloucyn

  • Guest
Re: Avast 4.7 and SSL
« Reply #1 on: January 29, 2007, 03:58:07 AM »
avast's  "Internet Mail" scanner does not work with SSL , you have to use it in combination with STUNNEl. With most SSL servers your mail is already scanned by an antivirus program before it is delivered to you so you probably do not need to use avast's "Internet Mail" scanner. Take a look here for information using Stunnel http://forum.avast.com/index.php?topic=8775.msg97026#msg97026, note that Stunnel comes as an installer now which incudes OpenSSL so you now have to only download Stunnel , install and configure it. You can download Stunnel here: http://www.stunnel.org/download/stunnel/win32/stunnel-4.20-installer.exe
« Last Edit: January 29, 2007, 03:59:50 AM by Joeloucyn »

2007i

  • Guest
Re: Avast 4.7 and SSL
« Reply #2 on: January 29, 2007, 04:07:05 AM »
thank you, I was just reading some SSL related stuff here and see it's not supported.

Yes, my ISP is doing a mail scan on his side - I just disable the Avast mail scanner as I don't want to muck around with other software to get it going.


joeloucyn

  • Guest
Re: Avast 4.7 and SSL
« Reply #3 on: January 29, 2007, 04:29:12 AM »
If you use Outlook instead of Outlook Express, the "Outlook/Exchange" scanner installs a plug-in in Outlook which scans SSL, unfortunately you can't use it with Outlook Express.
So, yes, you  might find it easier to just use your ISP's AV scan.

Offline alanrf

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3870
  • Just an avast user
Re: Avast 4.7 and SSL
« Reply #4 on: January 29, 2007, 05:24:01 AM »
You do not need to "muck about" or disable the mail scanner ... you just need to remove the ports 995 and 465 you added in the first place.

joeloucyn

  • Guest
Re: Avast 4.7 and SSL
« Reply #5 on: January 29, 2007, 05:31:31 AM »
I just disable the Avast mail scanner as I don't want to muck around with other software to get it going.

But, that is what he said! He does not want to use other software (Stunnel)
« Last Edit: January 29, 2007, 05:34:32 AM by Joeloucyn »

Offline alanrf

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3870
  • Just an avast user
Re: Avast 4.7 and SSL
« Reply #6 on: January 29, 2007, 05:39:54 AM »
The poster said that it was now necessary to stop the Internet Mail scanner to get mail.  I was pointing out that the poster had been the cause of making the Internet Mail scanner not function and should remove the problem.


joeloucyn

  • Guest
Re: Avast 4.7 and SSL
« Reply #7 on: January 29, 2007, 05:49:41 AM »
And that he did! Post closed.

Offline alanrf

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3870
  • Just an avast user
Re: Avast 4.7 and SSL
« Reply #8 on: January 29, 2007, 06:09:20 AM »
Oh, I missed where it was said that the erroneous port settings were removed.  Please point it out to me. 

2007i

  • Guest
Re: Avast 4.7 and SSL
« Reply #9 on: January 29, 2007, 06:54:24 AM »
If you use Outlook instead of Outlook Express, the "Outlook/Exchange" scanner installs a plug-in in Outlook which scans SSL, unfortunately you can't use it with Outlook Express.
So, yes, you  might find it easier to just use your ISP's AV scan.

Thx, but I don't have Outlook since I have no MS Office installed. I am an OpenOffice user. The last MS Office I used was Office 97 Pro years ago.

Offline alanrf

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3870
  • Just an avast user
Re: Avast 4.7 and SSL
« Reply #10 on: January 29, 2007, 07:18:48 AM »
Lest anyone thinks that the Outlook plugin really does scan SSL what actually happens is that the SSL session is terminated in Outlook, Outlook then passes the message source to avast for scanning via a program interface; there is no communication session (SSL or otherwise) involved at this time.  The same is true also for the plugin that works with The Bat mail client. 

Given the increasing use of secured connections for emails I hope that the avast team might give some thought to incorporating a facility into avast that provides the equivalence of STunnel function in the Internet Mail scanner (ie secure end point management and smooth delivery of the message source to avast for scanning).   

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Avast 4.7 and SSL
« Reply #11 on: January 29, 2007, 12:55:39 PM »
I don't want to muck around with other software to get it going.
Without Stunnel you won't be able to manage. With it, no problem.
Since SSL/TLS e-mail is encrypted and decrypted in the client, external virus scanners (including avast!) can't read or scan it.
The solution is to pass e-mail in and out un-encrypted from your client (Outlook Express, Thunderbird, ...) to a proxy program (Stunnel) that does the actual ssl or tls encryption/decryption of the pop3/smtp e-mail and communicates directly with the ISP server on the appropriate ports.
The best things in life are free.