Solved

TLS Encryption Exchange 2010

Posted on 2013-01-17
4
827 Views
Last Modified: 2013-01-17
A client of mine used to have TLS encryption setup on their old Exchange 2003 setup for various clients, they now use Exchange 2010 am I right in thinking that all mail is sent using this method where required so no extra work is required unlike on 2003?
0
Comment
Question by:dannyfccs
4 Comments
 
LVL 14

Accepted Solution

by:
BlueCompute earned 500 total points
ID: 38786698
Yes that's correct.  Exchange 2010 will do opportunistic TLS by default, so long as there is a certificate configured for SMTP.  If you run the Get-ExchangeCertificate cmdlet you can see which certificate you have configured for SMTP.

If you have a certificate enabled for SMTP then exchange will offer the STARTTLS option and where the other server supports it communication will be encrypted.  If the other server doesn't support TLS then exchange will default / fall-back to unencrypted SMTP. (Hence 'opportunistic' TLS.  If you wish to force TLS and never fall-back to unencrypted then you must configure your connectors to 'require TLS')
0
 

Author Comment

by:dannyfccs
ID: 38786725
But if the server your sending to doesn't support TLS won't the mail not be delivered?
0
 
LVL 18

Expert Comment

by:irweazelwallis
ID: 38786784
if you need to force TLS you are best off setting up a scoped send connector to enforce TLS and fail if it can't do it

then you don't affect other mail
0
 
LVL 49

Expert Comment

by:Akhater
ID: 38786826
exchange 2010 uses opportunistic TLS so, if the certificates is correct and the other party supports it, exchange 2010 will use TLS, if not it will failback and user no-encrypted SMTP

all internal emails (within an exchange organization) will be sent with TLS encryption
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Utilizing an array to gracefully append to a list of EmailAddresses
This article aims to explain the working of CircularLogArchiver. This tool was designed to solve the buildup of log file in cases where systems do not support circular logging or where circular logging is not enabled
In this video we show how to create a User Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Mailb…
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question