Solved

Securing POP and SMTP for Exchange 2003

Posted on 2010-08-31
2
554 Views
Last Modified: 2012-05-10
We use Exchange 2003 and have a frontend server and 3 backend servers. The frontend is used for centralised OWA access, but I would like to use this for secure POP\IMAP access, predominately for smart phones.

I have secured POP and IMAP using SSL, and that is working fine. My question is in relation to SMTP.

Does SMTP have to be encrypted in the same manner for client connections to the front end server? If I enable SLL on the SMTP virtual server of the front end server, this should encrypt all client\server smtp traffic? Is this recommended?

I assume existing email delivery should be remain unaffected, as the front-end will pass any outbound email to the relevant backend server for delivery? (all backends send their own outbound email, no bridge heads or smart hosts etc due to child company structure and geographic locations).

Is it enough to just secure the POP3 session?

On a side note, should all SMTP virtual servers use at least TLS as a best practice? or does this create problems with connections between external email servers?

Is it ok to use SSL cert on an exchange server that handles outbound email delivery? Are there any potential caveats with this?

I would really like to harden our exchange environment.
0
Comment
Question by:felixresources
2 Comments
 
LVL 4

Accepted Solution

by:
MONSTA2008 earned 500 total points
ID: 33577201
If you really want to harden Exchange I would recommend you check out the Department of Defense DISA Security Guidlines (STIGs) for Exchange.  They can be found here.

http://iase.disa.mil/stigs/checklist/index.html
0
 
LVL 15

Expert Comment

by:tntmax
ID: 33581843
http://sial.org/howto/openssl/tls-name/

Alternatively, have your users install PGP and encrypt the email at the desktop level. This requires sharing PGP keys. Encrypted SMTP traffic depends on the recipient server supporting it as well.
0

Featured Post

Live: Real-Time Solutions, Start Here

Receive instant 1:1 support from technology experts, using our real-time conversation and whiteboard interface. Your first 5 minutes are always free.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Office 365 Login Audit Report 1 33
Final Exchange 2010 to 2016 steps query 9 44
Exchange powershell help 4 22
Exchange 2016 Dag Question 2 31
This article lists the top 5 free OST to PST Converter Tools. These tools save a lot of time for users when they want to convert OST to PST after their exchange server is no longer available or some other critical issue with exchange server or impor…
Pop culture is prime bait for hackers seeking to infect user’s computers and mobile devices with malicious malware. Hackers know exactly what the latest trends are online and know how to use them to their advantage.
In this video we show how to create a Distribution Group in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >>…
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…

815 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now