SyncriTab

Server Configuration

The Configuration page controls how people reach SyncriTab, how it sends email, and its security settings.

Opening the Configuration page

Sign in as an administrator and click Configuration in the side menu. The page has three tabs:

Each tab has its own Save button, which saves only that tab. Saving reloads the page, so unsaved changes on the other tabs are lost. Change and save one tab at a time.

HTTP Configuration

The HTTP Configuration tab on the Configuration page.
The HTTP Configuration tab.
SettingWhat it does
TCP/IP port for HTTP (primary/secondary) Two ports for plain HTTP. The primary port is 21786 after installation. Enter 80 as the secondary port so users can open SyncriTab without typing a port number. Leave the secondary box empty to use only the primary port.
TCP/IP port for HTTPS The port for encrypted HTTPS connections, normally 443. Enter 0 to turn HTTPS off. HTTPS also needs a certificate; click Configure Certificate... next to this field. See SSL Certificates.
Enforce HTTPS When selected, and HTTPS is turned on, browsers that open SyncriTab over plain HTTP are redirected to the HTTPS address. Turn this on once HTTPS works, so passwords and data are never sent unencrypted.
Preferred URL The full address users should use, for example https://syncritab.example.com. SyncriTab uses its host name when it creates a certificate, and uses the address in the links it emails, such as password reset links. It must start with http:// or https://. If you leave it empty, links use whatever address the user's browser used.

Below the settings, a summary shows the current HTTPS certificate: who issued it, when it expires, and whether it's valid.

Changing ports

Email Configuration

SyncriTab needs an email (SMTP) server to send:

Set it up soon after installation. Mandatory MFA on the Security tab can't be turned on without it.

The Email Configuration tab with SMTP server settings and Basic Authentication selected.
The Email Configuration tab.
SettingWhat to enter
SMTP server host nameYour mail server, for example smtp.example.com, smtp.office365.com, or smtp.gmail.com.
SMTP server portUsually 587 (the default). Some servers use 465 or 25.
Security STARTTLS: the connection starts unencrypted and then switches to encryption. Normally used with port 587.
TLS/SSL: encrypted from the start. Normally used with port 465.
None: no encryption. Use only with a mail server on your own network.
Authentication typeHow SyncriTab signs in to the mail server. See the next sections.

Basic Authentication

Enter the mail account's User ID and Password. This is the most common choice. Some providers, including Microsoft 365 and Google, may require OAuth or an app password instead of the account's normal password.

SSL Certificate

SyncriTab proves its identity to the mail server with a client certificate instead of a password. The mail server must be set up to accept it.

  1. Set Security to STARTTLS. This authentication type requires it.
  2. Upload the certificate as a .p12, .pfx, or .jks file with its password.
  3. In Certificate domain, enter a DNS name from the certificate, for example example.com, or *.example.com for a wildcard certificate.
  4. Check the certificate details that SyncriTab shows, including its expiration date, and click Save.

To remove the certificate, first switch to a different authentication type and save.

OAuth

Use OAuth with providers that don't allow password sign-in for SMTP, such as Microsoft 365 and Google Workspace. You'll need to register SyncriTab as an application with your provider first.

The OAuth settings dialog for the SMTP server.
OAuth settings for the email server.
  1. In your provider's admin portal, register an application for SyncriTab. Allow it to send email over SMTP, and add a redirect URI made of the address you use to open SyncriTab followed by /auth, for example https://syncritab.example.com/auth. Note the client ID and client secret.
  2. In SyncriTab, set Authentication type to OAuth and click Configure OAuth.
  3. Fill in the OAuth Parameters and click Done:
    FieldWhat to enter
    Client IDFrom the application you registered.
    Client SecretFrom the application you registered.
    Endpoint URLYour provider's OpenID configuration address, which ends in .well-known/openid-configuration. For example, https://accounts.google.com/.well-known/openid-configuration for Google, or https://login.microsoftonline.com/your-tenant-id/v2.0/.well-known/openid-configuration for Microsoft 365.
    User IDThe mailbox SyncriTab sends from, for example syncritab@example.com.
    ScopeThe permissions to request, as listed in your provider's documentation for SMTP sending. Separate several scopes with spaces. For example, https://mail.google.com/ for Google, or https://outlook.office.com/SMTP.Send offline_access for Microsoft 365.
  4. Click Save.
  5. Click Authorize and sign in to your provider with the mailbox account. Open SyncriTab at the same address you registered as the redirect URI before you click it.
  6. You return to the Email Configuration tab with the message OAuth authorization completed successfully. The Access Token and its Expiration date are filled in. SyncriTab renews the token automatically.

Sending a test email

After saving, click Send Test Email, enter a sender and recipient address, and click Send. If the message doesn't arrive, check the settings and the recipient's spam folder. The test needs the Administrator's address on the Security tab, so fill that in first.

Security

The Security tab with administrator email, MFA, IP blocking, encryption, and session timeout settings.
The Security tab.
SettingWhat it does
Administrator's addressWhere SyncriTab sends alerts. Separate several addresses with commas.
Sender's email addressThe From address on email SyncriTab sends. If you leave it empty, the mail server account decides. Many mail servers only accept a sender address that belongs to the account they sign in with.
Mandatory MFAMakes every user sign in with two-factor authentication. It can be turned on only when email is set up, a valid sender address is available, and every user has a valid MFA email address. If any are missing, SyncriTab lists the users you need to fix first.
Block malicious IP addressesTemporarily blocks an IP address after too many wrong passwords.
Encrypt sensitive data at restEncrypts saved sessions and other sensitive files on the server's disk. Existing files are converted the next time they're saved. The line below the check box shows which encryption key is in use.
Session Time (minutes)How long a user can be idle before SyncriTab signs them out and closes their database connections. The default is 30; you can enter 5 to 1,440 (24 hours). While a session is idle but hasn't timed out, SyncriTab keeps its database connections alive, so the database doesn't drop them first.

For more about these settings, including managing the encryption key, see Security & Encryption.

Recommended setup

After you first install SyncriTab:

  1. On the Security tab, enter the Administrator's address and a Sender's email address, and save.
  2. On the Email Configuration tab, set up your mail server, save, and send a test email.
  3. On the HTTP Configuration tab, enter the Preferred URL, set up an HTTPS certificate, set the ports to 80 and 443, and save. Then restart SyncriTab.
  4. When HTTPS works, select Enforce HTTPS and save.
  5. Consider turning on Mandatory MFA after every user has an MFA email address.