Knowledge Base
Referenskunskap för administratörer, en sida i taget: vad ett protokoll eller en produkt är, hur det fungerar och var det dyker upp i den dagliga driften, med snabbfakta, alla artiklar om ämnet och dess plats i protokollstacken. Samlingen växer; 55 ämnen är planerade.
Sidor märkta EN eller DE håller på att översättas och öppnas tills vidare på engelska eller tyska.
Microsoft
Microsoft Exchange Microsoft Exchange: produktfamilj och driftmodeller Microsoft Exchange som produktfamilj: gemensamma begrepp och protokoll, skillnader mellan Exchange Online och Exchange Server samt Hybrid-driftens och Hybrid-e-postflödets uppgifter. Exchange Online Exchange Online: arkitektur, e-postflöde och drift Exchange Online för meddelandeadministratörer: klientorganisation- och mottagarmodell, EOP-transport, anslutningar, klientåtkomst, PowerShell och Graph, Message Trace, kvarhållning, säkerhet och återställning. Exchange On-Premises Exchange On-Premises: Serverarkitektur och drift Exchange Server i det egna datacentret: postlåde- och Edge-roller, transportpipeline, Active Directory, ESE-databaser, DAG, klientåtkomst, säkerhet, övervakning, säkerhetskopiering och återställning. Exchange Hybrid Exchange Hybrid: identitet, samexistens och drift Exchange Hybrid förklarat på ett begripligt sätt: förutsättningar, katalogsynkronisering, mottagarauktoritet, Hybrid Configuration Wizard, OAuth, organisationsrelationer, Autodiscover, postlådeöverflyttningar och drift. Hybrid mail flowDE Hybrid-Mailfluss: Routing zwischen Exchange Online und On-Premises Hybrid-Mailfluss Schritt für Schritt: direkte und zentrale Zustellung, Connectoren, TLS-Zertifikate, Remote-Domains, gemeinsame SMTP-Domains, Mail-Gateways, Message Trace und Message Tracking. Active Directory / Entra Microsoft Entra ID: Klientorganisation, token och hybrididentitet Microsoft Entra ID för infrastruktur- och meddelandeadministratörer: klientorganisations- och katalogobjekt, Security Token Service, OAuth/OIDC och SAML, appar och tjänstehuvudnamn, arbetsbelastningsidentiteter, medgivande och auktorisering, villkorad åtkomst, enheter, hybridsynkronisering, Domain Services, Microsoft Graph, loggning, återställning och teknisk historik.
E-postgateways
SEPPmailEN SEPPmail: The Secure Mail Gateway with GINA Delivery How the SEPPmail Secure E-Mail Gateway works: S/MIME and domain encryption at the gateway, GINA for recipients without keys, its position in the mail flow, LDAP integration and the operational topics from firmware to cluster. Kiteworks / TotemomailEN Totemomail: Email Encryption on the Kiteworks Platform The Totemomail encryption gateway in operation: origins and the takeover by Kiteworks, gateway encryption with S/MIME and PGP, WebMail delivery, LDAP integration, the licensing model based on licensed users, and the M365 integration. Apache James Apache James: modulär e-postserver och Mailet-plattform Apache James ur ett tekniskt perspektiv: protokoll och e-postroller, komponentbaserad arkitektur, kö och Mailet-pipeline, postlåde- och lagringsmodell, driftsvarianter från PostgreSQL till Cassandra samt utvecklingen från Java Apache-projekt till JVM-e-postplattform. HIN-gatewayEN HIN: secure email in the Swiss healthcare sector The HIN platform from an operator's perspective: HIN identities and protected mail between healthcare professionals, the HIN Mail Gateway inside an organization's own infrastructure, Access Gateway and client, platform upgrades and their deadlines. Cisco ESA / SMA Cisco Secure Email: Gateway, AsyncOS och SMA Cisco Secure Email för meddelandeadministratörer: SEG-/ESA-e-postpipeline, lyssnare, HAT och RAT, arbetskö och leverans, e-postpolicyer, AsyncOS, SMA-tjänster, klustergränser, teknikstack, övervakning, återställning och diagnostik.
AI och automation
Claude Claude och Claude Code: arkitektur, API och säker agentdrift Claude och Claude Code för plattforms-, säkerhets- och automationsadministratörer: modell- och API-gränser, tillståndslösa Messages, Content Blocks, streaming, Tool Use och MCP, lokal agentkörning, Workspaces och nycklar, Rate Limits, caching, batcher, observability, dataskydd, Prompt Injection och återställning. CloudflareEN Cloudflare Workers: serverless at the network edge An overview of Cloudflare's serverless platform: code at the edge instead of on servers, the V8 isolate model, storage services from KV to D1 and R2, bindings and Wrangler, and the limits of the model.
Öppen källkod och egen drift
Home AssistantEN Home Assistant: smart home hub with a local focus An overview of the open source smart home platform: local control instead of mandatory cloud, integrations and device connectivity, automations, installation variants, and the role of APIs, tokens, and MQTT. RcloneEN Rclone: The Universal Tool for Cloud Storage An overview of the command-line tool for cloud storage: remotes and backends, the core commands sync, copy and mount, client-side encryption with crypt, and integrity checking by checksum. Proton DriveEN Proton Drive: End-to-End Encrypted Cloud Storage An overview of Proton's cloud storage: end-to-end encryption as its basic principle, origin and ecosystem, clients and platforms, and what a zero-knowledge architecture means for third-party tools and automation. Paperless-ngxEN Paperless-ngx: self-hosted document management An overview of the open source DMS: the consume pipeline from scan to archive, OCR and full-text search, organization through tags, correspondents, and document types, storage architecture, and operation in containers.
Protokoll och standarder
SMTPEN Understanding SMTP: How Email Is Actually Delivered What SMTP is and how mail flow works: envelope and headers, MX delivery, relays and smarthosts, the ports 25, 465 and 587, StartTLS, and the reply codes with which servers justify acceptance and rejection. LDAPEN Understanding LDAP: the directory protocol behind AD, Entra, and mail gateways What LDAP is and how it works: a directory rather than a database, DIT and distinguished names, bind and search, LDAPS vs. StartTLS, and what of that really counts in Active Directory, Entra, and secure mail gateways. DNS DNS: upplösning, delegering och drift Domain Name System ur ett administratörsperspektiv: namnrymd, zoner och delegering, rekursiv upplösning, RRset, cache och TTL, negativa svar, UDP och TCP, EDNS, DNSSEC, zonreplikering samt diagnostik för meddelandeinfrastrukturer. TCP / nätverkEN TCP and Networking Basics: What Mail Admins Really Need TCP as the foundation of SMTP, LDAP, and HTTPS: connection setup with the three-way handshake, ports and firewalls, typical failure patterns from timeout to connection refused, and the steps for a quick diagnosis. TLS / certifikatEN TLS and Certificates: Trust in Mail and Directory Operations How TLS secures connections and why certificates are the most common cause of outages: handshake, certificate chains and truststores, SAN instead of CN, LDAPS and StartTLS, renewal without downtime. SSHEN SSH: Remote Access, Keys, and Hardening Secure Shell in day-to-day administration: keys instead of passwords, agent and known_hosts, the essential hardening steps for exposed servers, and SFTP as a file transport. KerberosEN Kerberos: tickets, KDC, and authentication in Active Directory How Kerberos works and why Active Directory is built on it: tickets instead of passwords, KDC and TGT, service principal names and keytabs, the time synchronization requirement, and the typical failure patterns.
E-postsäkerhet
E-postkrypteringEN Email Encryption: Transport Protection, S/MIME, PGP, and the Gateway Model The layers of email encryption cleanly separated: opportunistic and enforced TLS on the transport, S/MIME and PGP for content, central gateways instead of client-side chaos, and when each level is sufficient. SPF · DKIM · DMARCEN SPF, DKIM, and DMARC: sender authentication in combination The three sender authentication mechanisms and how they work together: what SPF checks, what DKIM signs, how DMARC ties both to the visible sender, and the rollout path from reports to p=reject. Härdning och åtkomstEN Hardening and access protection: reducing attack surface in operations The principles behind every hardening checklist: minimize the attack surface, use central instead of local accounts, grant minimal privileges, apply updates consistently, and keep access traceable, from the appliance GUI to the VPS.
Automation och APIs
PowerShell / GraphEN PowerShell and Microsoft Graph: Automation for Mail Admins The automation layer above Exchange, Entra and Microsoft 365: Exchange Online PowerShell, Microsoft Graph as an API, app registrations with certificate authentication, and where the classic modules are being retired. APIs och integrationer API:er: avtal, identiteter och distribuerade felgränser API:er för infrastruktur- och meddelandeadministratörer: REST, HTTP och JSON, RPC, GraphQL, gRPC och händelse-API:er, OpenAPI och scheman, OAuth och arbetsbelastningsidentiteter, gateways, timeouter, återförsök, idempotens, paginering, hastighetsbegränsningar, webhooks, observerbarhet, versionshantering och teknisk historia.
Drift
Releaser och uppdateringarEN Releases and Updates: Patch Operations for Mail Infrastructure How update operations for Exchange, appliances and gateways become plannable: release types from security update to firmware, maintenance windows and rollback paths, reading release notes, and the question of how quickly patching has to happen. Backup och återställning Säkerhetskopiering och katastrofåterställning: tillstånd, mål och återstart Säkerhetskopiering och katastrofåterställning för meddelandeadministratörer: avgränsning mot ögonblicksbild, replikering och hög tillgänglighet, RPO, RTO och MTD, konsekvent säkerhetskopiering av postlådor, köer, konfiguration, nycklar och index, isolerad återställning, återstartsordning, återställningstester och diagnostik. Migrering och tidsfristerEN Migration and deadlines: keeping mail infrastructure life cycles under control Why migrations in the mail environment are almost always driven by deadlines: end-of-support dates, vendor platform renewals, migration patterns from big bang to coexistence, and the checklist for cutover day. Containrar och Docker Containrar: avbildningar, körtid och robust drift Containrar för infrastruktur- och meddelandeadministratörer: OCI-artefakter, runtime- och kärnisolering, namnområden och cgroups, nätverk och lagring, orkestrering, identitet och supply chain, resurser, hälsa, loggning, återställning, Windows-containrar och teknisk historia. Lagring och synkroniseringEN Storage and Sync: Cloud Storage in Technical Terms How cloud storage works technically: object storage versus file system, access through sync, copy, and mount, client-side encryption, storage classes from hot to cold, and integrity checking of transferred data. Licenser och gränserEN Licenses and limits: licensing models for infrastructure software How infrastructure software is licensed: named users, devices, and capacity limits, how license counters are fed technically, what happens when a limit is reached, and the role the directory plays in it. Felsökning och diagnostikEN Troubleshooting and Diagnosis: Systematic Fault Finding in Infrastructure The methodology behind successful fault finding: a layered model from the connection to the application, taking error messages literally, reproducing minimally, correlating changes, and documenting findings. Testning och lasttesterEN Testing and Load Tests: Probing Infrastructure Under Controlled Conditions Methodology for functional and load testing in messaging and infrastructure environments: what to measure, the baseline-burst-soak sequence, load generators and sinks, marking test runs, and evaluating results with percentiles instead of averages.