Solved

Exchange 2007/2010 - TLS

Posted on 2013-01-08
4
518 Views
Last Modified: 2013-02-04
Hi Experts,

I've never really attempted to configure TLS on any of our customer Exchange servers before.

I've read this:
http://technet.microsoft.com/en-us/library/aa998840(v=exchg.141).aspx

But I'm a bit confused on what certificates are required.

We have multiple hub transport servers, sending and receiving emails to/from the Internet.

Are we able to enable TLS if there is a smart host in the way?
If we are sending from multiple hub transport servers, do we need a cert for each of these? or can these be covered by a single cert?

Any help is appreciated!
0
Comment
Question by:MarkMichael
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 16

Accepted Solution

by:
Bruno PACI earned 250 total points
ID: 38754486
Hi,

In Exchange 2007/2010 each server have its own self-signed certificate by default.
Exchanger servers inside the organisation ALWAYS use TLS between them.

Enabling TLS for external servers is probably a bit useless because I really doubt many external servers use it.

If you plan to enable TLS anyway on send connectors you should NEVER REQUIRE TLS ! You can enable it but do not require it !

Exchange servers inside the Exchange organization must authenticate each other and then use TLS certificate in that manner, added to the need of encryption.

As far as I know, using TLS with external servers is just for encryption and this will not be used for authentication. That means that you should not be forced to use publicly trusted certificates and you should be able to use your own self-signed and free certificates...

TLS with external servers is negociated and should stay negociated. It should never be required. So if servers are not able to use TLS they will use unencrypted SMTP.


The real question is why the hell to do want to encrypt dialogs with external servers ? This is not a security enforcement because you can not be sure that the message will still be encrypted on the next hop !
If you plan to encrypt messages so that they won't be read during the transfer to the destination you should encrypt the message body with S/MIME or any sort of PGP software. This is the only way to protect the mail content.


Have a good day.
0
 
LVL 18

Assisted Solution

by:irweazelwallis
irweazelwallis earned 250 total points
ID: 38754504
we use TLS and enforce it for quite a few customers. We use Microsoft FOPE as service to do email filtering.

We enforce TLS between our edge servers and Microsoft so that are emails between use and the cloud are secure.

Between Microsoft specific customers we enforce TLS and if its fails then the email does not send. For other mail it can send eiher with or without i.e. opportunistic negotiation.

Depending ho how you have set up your certificates you can install the same cert on all hub/edge servers and make sure the FQDN connector matches the name in the cert.
If you have different FQDN's then you would need to include them all on one cert or have different certs attached the SMTP service
0
 
LVL 15

Author Comment

by:MarkMichael
ID: 38754513
Thanks for the quick reply!

I was thinking of creating an additional send connector, locked down for that particular domain that would like to use encryption.

On a totally different note, Digital Signatures *could* be used to encrypt data between 2 particular users between 2 different Exchange Organizations right?

Thanks again!
0
 
LVL 18

Expert Comment

by:irweazelwallis
ID: 38754645
yes a scoped send connector would be the way to enforce TLS to a specific Domain


as far as i am aware digital signatures (within Exchange) can be used to sign emails but not encrypt them, this is using the Exchange Rights Management to do this which is a load of extra infrastructure an licensing. If you want to do user to user encryption then PGP is a good choice.
there is a PGP universal server which does gateway encryption which means it sits next to the exchange server and does the encryption there and removes the need to end user setup with software and encryption keys
0

Featured Post

Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article explains how to install and use the NTBackup utility that comes with Windows Server.
There are times when we need to generate a report on the inbox rules, where users have set up forwarding externally in their mailbox. In this article, I will be sharing a script I wrote to generate the report in CSV format.
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses
Course of the Month11 days, 7 hours left to enroll

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question