How to Ensure a Secure Connection to Convergence Lyon Webmail for Your Emails

The Convergence webmail of the Lyon academy is based on an Oracle Communications infrastructure (formerly Sun Java System Messaging Server) coupled with an HTTPS layer managed by the rectorate’s IT services. Accessing academic emails via https://webmail.ac-lyon.fr is not enough to guarantee the confidentiality of exchanges: the security chain depends as much on server configuration as on client-side practices.

TLS Certificates and Trust Chain Verification on webmail.ac-lyon.fr

The connection to the Convergence portal relies on a TLS certificate issued by a certification authority recognized by major browsers. During the TLS handshake, the browser checks the validity of the certificate, its expiration date, and the match between the domain name and the CN (Common Name) or SAN (Subject Alternative Name) field.

A certificate warning at the time of connection indicates a concrete problem: an expired certificate on the server side, network interception (corporate SSL proxy or man-in-the-middle attack), or a misconfigured system clock on the client machine. Never manually validate an invalid certificate on academic webmail access. If the alert persists, we recommend contacting the IT department rather than forcing access.

To ensure a secure connection to Convergence webmail Lyon, check that your browser displays the padlock and the HTTPS protocol without errors in the address bar before entering your credentials.

Academic Password Policy and Account Lockout

Since the 2023-2024 period, the IT department of the Lyon academy has strengthened password rules in line with national cybersecurity recommendations from the Ministry of Education. This concretely translates into an increased minimum length, prohibition on reusing old passwords, and automatic account lockout after several failed attempts.

This temporary lockout protects against brute force attacks, but it often traps users who keep an old password in an IMAP client configured on their phone. The client attempts to authenticate in a loop with the old password, triggering the lockout before the user even opens the webmail.

Man using two-factor authentication to secure access to his webmail from a home office

Before changing your academic password, we recommend temporarily disabling IMAP/SMTP synchronization on all your devices. Once the new password is active on the Convergence webmail, update each email client one by one.

IMAP and SMTP Settings for Third-Party Clients

The configuration documented by the DANE of Lyon uses the following servers:

  • Incoming IMAP server: encrypted connection (SSL/TLS), standard port, identifier in the format “pnom” (first letter of the first name + last name), distinct from the full email address [email protected]
  • Outgoing SMTP server: encrypted connection, mandatory authentication with the same “pnom” identifier and the academic password
  • The “reply-to address” field must match the full address [email protected], not the short identifier

This dissociation between login identifier and email address is a frequent source of error. Entering the full email address instead of the short identifier blocks authentication without an explicit error message on some clients.

Phishing Targeting ac-lyon.fr Accounts: Signals and Reporting Procedure

Phishing campaigns targeting academic accounts have intensified since 2022. Fraudulent emails often mimic notifications from Convergence webmail (quota exceeded, account validation, security update) and redirect to a fake login page.

The technical signals to watch for:

  • The URL of the login page does not exactly match webmail.ac-lyon.fr (variants with hyphens, unusual subdomains, domain in .net or .org)
  • The TLS certificate of the fake page is missing, self-signed, or issued for a different domain
  • The message contains an artificial sense of urgency (“your account will be deleted in 24 hours”)
  • The sender uses an address outside the ac-lyon.fr domain

The structured reporting procedure within the academy consists of forwarding the suspicious email as an attachment (not as a simple forward) to the dedicated address such as [email protected]. This attachment preserves the technical headers of the message, allowing the security team to analyze the actual source.

Separation of Professional and Personal Uses on Academic Messaging

Academies increasingly emphasize a strict separation between professional and personal messaging. In practice, this means not using the ac-lyon.fr address to sign up for third-party services (social networks, online purchases, personal newsletters).

Each registration on an external service exposes the address to potential data leaks. If this address is the same as that of Convergence webmail, a compromised password on a third-party site opens the door to credential stuffing on the academic portal. Using a distinct personal address for any non-professional use remains the simplest measure to limit the attack surface.

The Convergence webmail also allows configuring S/MIME (Secure/Multipurpose Internet Mail Extension) to sign and encrypt messages, provided that the option is enabled at the site level and the user has a personal certificate. This feature remains underutilized in practice, but it provides an additional layer of privacy for sensitive exchanges between staff of the Lyon academy.

Young woman securing her webmail connection via VPN in a trendy café in Lyon

Securing the Convergence webmail does not rely on a single parameter but on the interplay between server TLS configuration, password hygiene, anti-phishing vigilance, and compartmentalization of uses. A single weak link in this chain is enough to compromise the entire academic account.

How to Ensure a Secure Connection to Convergence Lyon Webmail for Your Emails