Solved

Securing POP and SMTP for Exchange 2003

Posted on 2010-08-31
2
552 Views
Last Modified: 2012-05-10
We use Exchange 2003 and have a frontend server and 3 backend servers. The frontend is used for centralised OWA access, but I would like to use this for secure POP\IMAP access, predominately for smart phones.

I have secured POP and IMAP using SSL, and that is working fine. My question is in relation to SMTP.

Does SMTP have to be encrypted in the same manner for client connections to the front end server? If I enable SLL on the SMTP virtual server of the front end server, this should encrypt all client\server smtp traffic? Is this recommended?

I assume existing email delivery should be remain unaffected, as the front-end will pass any outbound email to the relevant backend server for delivery? (all backends send their own outbound email, no bridge heads or smart hosts etc due to child company structure and geographic locations).

Is it enough to just secure the POP3 session?

On a side note, should all SMTP virtual servers use at least TLS as a best practice? or does this create problems with connections between external email servers?

Is it ok to use SSL cert on an exchange server that handles outbound email delivery? Are there any potential caveats with this?

I would really like to harden our exchange environment.
0
Comment
Question by:felixresources
2 Comments
 
LVL 4

Accepted Solution

by:
MONSTA2008 earned 500 total points
ID: 33577201
If you really want to harden Exchange I would recommend you check out the Department of Defense DISA Security Guidlines (STIGs) for Exchange.  They can be found here.

http://iase.disa.mil/stigs/checklist/index.html
0
 
LVL 15

Expert Comment

by:tntmax
ID: 33581843
http://sial.org/howto/openssl/tls-name/

Alternatively, have your users install PGP and encrypt the email at the desktop level. This requires sharing PGP keys. Encrypted SMTP traffic depends on the recipient server supporting it as well.
0

Featured Post

Do email signature updates give you a headache?

Do you feel like all of your time is spent managing email signatures? Too busy to visit every user’s desk to make updates? Want high-quality HTML signatures on all devices, including on mobiles and Macs? Then, let Exclaimer solve all your email signature problems today!

Join & Write a Comment

Easy CSR creation in Exchange 2007,2010 and 2013
This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
In this video we show how to create a Shared Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Sha…
To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Servers >> Certificates…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now