IBMDO YOU?Hi, I'm MBO!

Settings

Make the site feel at home on your screen.

Theme

Loading your theme preference.

Keyboard shortcuts

Open search from anywhere, then move through the results without leaving the keyboard.

Open settings
Ctrl,or⌘,
Open search
CtrlKor⌘K
Select a search result
↑↓
Open the selected result
Enter
Close an open dialog
Esc

Invisible Bits of Maximo

Set up an isolated Maximo test email server

Preserve a legacy hMailServer test setup while preventing development emails from escaping to real recipients.

A development mail server lets you inspect Maximo notifications without delivering them to real people. The example environment used hMailServer 5.6.7 on Windows Server 2016, a local test domain and one mailbox viewed through Thunderbird.

This is a legacy walkthrough. For a new environment, a purpose-built SMTP capture tool is usually smaller and safer because it accepts mail for inspection without acting as a general mail server. If you retain hMailServer, keep it isolated and patch the host.

Containment comes first

A domain catch-all does not receive every message regardless of its destination: a catch-all receives mail for unknown addresses inside its configured domain. It does not automatically capture a message addressed to a real external domain.

Before connecting Maximo:

  • Block outbound SMTP from the test server at the network firewall.
  • Allow inbound SMTP only from the development Maximo hosts.
  • Do not publish MX records or expose SMTP, POP3, IMAP or administration ports to the internet.
  • Require authentication and restrict hMailServer IP ranges; never create an open relay.
  • Use an obviously fictional internal test domain and make every test person's email address use it.
  • Do not copy production personal data or real recipient addresses into the environment.

Prove the block with a harmless external-address test before relying on it. Application configuration is not a sufficient boundary by itself.

Install the hMailServer release

The 2019 server required the Windows .NET Framework 3.5 feature:

The .NET Framework 3.5 Windows Server feature enabled

The following screens preserve the hMailServer 5.6.7 installation. Obtain installation media only from a trusted source, verify its integrity, and assess the release against the organization's current software policy.

  1. Launch the installer and review the setup information.

    Launching the hMailServer installer

    The hMailServer setup information page

  2. Read and accept the licence if it is compatible with your use.

    The hMailServer licence agreement

  3. Choose the installation directory.

    Choosing the hMailServer installation directory

  4. Install both the server and administrative tools.

    Selecting the hMailServer server and administrative tools

  5. The small test environment used the built-in database. Use an externally managed database if your chosen release or operational policy requires one.

    Selecting the built-in hMailServer database

  6. Choose the Start menu folder and set a unique administrator password stored in the team's password manager.

    Choosing the hMailServer Start menu folder

    Setting the hMailServer administrator password

  7. Review the selections and install.

    The hMailServer installer ready to install

Create the local test mailbox

Open hMailServer Administrator and authenticate with the administrator password:

Launching hMailServer Administrator

Signing in to hMailServer Administrator

Add an internal test domain:

Adding a domain in hMailServer

This example uses maximotest.com. Avoid a domain that could resolve publicly or become deliverable later; use a namespace reserved and controlled for internal testing instead.

The maximotest.com test domain

Under the domain, add a mailbox account with a unique password:

Adding an account to the test domain

The tester mailbox account

On the domain's Advanced tab, set that mailbox as the catch-all:

The tester mailbox configured as the domain catch-all

This captures unknown recipients at the local test domain. It does not replace the outbound firewall block.

Lock down the mail protocols

Before testing, review hMailServer's Settings → Advanced → IP Ranges and protocol bindings:

  • Permit SMTP submission only from the known development Maximo addresses.
  • Require authentication for the permitted Maximo range.
  • Deny external-to-external delivery and all relay paths that are not required.
  • Bind client protocols to an internal interface and allow access only from administrator workstations.
  • Disable POP3 or IMAP if nobody needs a mail client.
  • Enable logging long enough to verify behavior, then retain and protect logs according to policy.

If a mail client is useful, configure it only on the isolated network. The example used Thunderbird to view the mailbox:

The test mailbox opened in Thunderbird

Point development Maximo at the server

In Maximo's System Properties application, set the SMTP host to the internal hMailServer address. The example configuration also supplied the test mailbox credentials through mxe.smtp.user and mxe.smtp.password:

mail.smtp.host=<internal test mail host>
mxe.smtp.user=tester@<internal test domain>
mxe.smtp.password=<test mailbox password>

Maximo SMTP properties pointing to the hMailServer host and test account

Mark the password property encrypted and masked. Add mail.smtp.port when the server is not using Maximo's default SMTP port, and configure TLS if the isolated server supports it. Save and live-refresh supported properties or restart the relevant JVMs.

Change all development person records and communication defaults to the internal test domain. A catch-all cannot protect you from a forgotten real address outside that domain.

Test delivery and containment

The test changed a test user's password to trigger an email:

Changing the test user's password to trigger a Maximo email

The resulting message appeared in the local mailbox:

The captured Maximo password-change email

Test each Maximo mail path that matters: direct communications, workflows, escalations, scheduled reports and password notifications. Use invented recipients within the test domain and confirm that the catch-all receives them.

Finally, address a message to a controlled external test address and verify that the network blocks delivery. Check the hMailServer queue and logs to make sure it was rejected rather than waiting for a later retry. Repeat that containment test after firewall, mail-server or environment refresh changes.

References

Find the fix

Search articles

Esc

Search titles, technical terms or error codes.