Solved

Exchange 2007/2010 - TLS

Posted on 2013-01-08
4
513 Views
Last Modified: 2013-02-04
Hi Experts,

I've never really attempted to configure TLS on any of our customer Exchange servers before.

I've read this:
http://technet.microsoft.com/en-us/library/aa998840(v=exchg.141).aspx

But I'm a bit confused on what certificates are required.

We have multiple hub transport servers, sending and receiving emails to/from the Internet.

Are we able to enable TLS if there is a smart host in the way?
If we are sending from multiple hub transport servers, do we need a cert for each of these? or can these be covered by a single cert?

Any help is appreciated!
0
Comment
Question by:MarkMichael
  • 2
4 Comments
 
LVL 16

Accepted Solution

by:
PaciB earned 250 total points
ID: 38754486
Hi,

In Exchange 2007/2010 each server have its own self-signed certificate by default.
Exchanger servers inside the organisation ALWAYS use TLS between them.

Enabling TLS for external servers is probably a bit useless because I really doubt many external servers use it.

If you plan to enable TLS anyway on send connectors you should NEVER REQUIRE TLS ! You can enable it but do not require it !

Exchange servers inside the Exchange organization must authenticate each other and then use TLS certificate in that manner, added to the need of encryption.

As far as I know, using TLS with external servers is just for encryption and this will not be used for authentication. That means that you should not be forced to use publicly trusted certificates and you should be able to use your own self-signed and free certificates...

TLS with external servers is negociated and should stay negociated. It should never be required. So if servers are not able to use TLS they will use unencrypted SMTP.


The real question is why the hell to do want to encrypt dialogs with external servers ? This is not a security enforcement because you can not be sure that the message will still be encrypted on the next hop !
If you plan to encrypt messages so that they won't be read during the transfer to the destination you should encrypt the message body with S/MIME or any sort of PGP software. This is the only way to protect the mail content.


Have a good day.
0
 
LVL 18

Assisted Solution

by:irweazelwallis
irweazelwallis earned 250 total points
ID: 38754504
we use TLS and enforce it for quite a few customers. We use Microsoft FOPE as service to do email filtering.

We enforce TLS between our edge servers and Microsoft so that are emails between use and the cloud are secure.

Between Microsoft specific customers we enforce TLS and if its fails then the email does not send. For other mail it can send eiher with or without i.e. opportunistic negotiation.

Depending ho how you have set up your certificates you can install the same cert on all hub/edge servers and make sure the FQDN connector matches the name in the cert.
If you have different FQDN's then you would need to include them all on one cert or have different certs attached the SMTP service
0
 
LVL 15

Author Comment

by:MarkMichael
ID: 38754513
Thanks for the quick reply!

I was thinking of creating an additional send connector, locked down for that particular domain that would like to use encryption.

On a totally different note, Digital Signatures *could* be used to encrypt data between 2 particular users between 2 different Exchange Organizations right?

Thanks again!
0
 
LVL 18

Expert Comment

by:irweazelwallis
ID: 38754645
yes a scoped send connector would be the way to enforce TLS to a specific Domain


as far as i am aware digital signatures (within Exchange) can be used to sign emails but not encrypt them, this is using the Exchange Rights Management to do this which is a load of extra infrastructure an licensing. If you want to do user to user encryption then PGP is a good choice.
there is a PGP universal server which does gateway encryption which means it sits next to the exchange server and does the encryption there and removes the need to end user setup with software and encryption keys
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Lotus Notes – formerly IBM Notes – is an email client application, while IBM Domino (earlier Lotus Domino) is an email server. The client possesses a set of features that are even more advanced as compared to that of Outlook. Likewise, IBM Domino is…
Not sure what the best email signature size is? Are you worried about email signature image size? Follow this best practice guide.
In this video we show how to create a User Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Mailb…
In this video we show how to create a Shared Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Sha…

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now