Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Disable SSL on Exchange

Posted on 2016-08-02
9
Medium Priority
?
28 Views
Last Modified: 2016-08-15
We are running Exchange 2010 SP3 RU12, and I'm trying to determine is disabling SSL on the server and client is acceptable without breaking anything. From what I have read it seems that everything should be fine, but trying to get an opinion from others that may
have done this.
0
Comment
Question by:timgreen7077
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
9 Comments
 
LVL 36

Expert Comment

by:Kimputer
ID: 41738909
It will work. It's just that when someone uses a public wifi (or any other network that's not their home or office connection), the traffic can be decoded quite easily (meaning, no privacy, all the email can be read in an instant). This obviously requires a hacker on that same foreign network.
0
 

Author Comment

by:timgreen7077
ID: 41738947
This may be above my original question, but have you ever done this and what steps did you follow. If  this is above the original question and you choose not to answer i understand.
0
 
LVL 4

Expert Comment

by:El Fierro
ID: 41739584
You will encounter issues...
Exchange Server server that hosted the Client Access server role has SSL required by default for services such as:

    Outlook Web App (OWA)
    ActiveSync (mobile device access)
    Exchange Web Services
    Outlook Anywhere (aka RPC-over HTTPS)

May we know why you want to disable the ssl?
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 

Author Comment

by:timgreen7077
ID: 41739615
the security team see it as a vulnerability. We will continue using TLS but they want to remove SSL.
0
 
LVL 4

Expert Comment

by:El Fierro
ID: 41739635
The only issue i encountered by a 3rd party security auditing was that my ssl had to 1024 bit encryption instead of 2048. The auditor also gave us crap about it not being bought from a "trusted" seller.that was resolved by showing them that our exchange ssl was bought from a authorized godaddy reseller.I'm curious why is it a vulnerability from their view?
0
 

Author Comment

by:timgreen7077
ID: 41739653
Our SSL cert is also from a 3rd party and it 2048, but they want to disable SSL on the server side and client side of Exchange. Its also because of auditing. I have a call into Microsoft to see what they say also. I'm also curious about what you guys say here at the exchange.
0
 
LVL 4

Expert Comment

by:El Fierro
ID: 41739665
Well tim you need it as shown on the list, prior to exchange 07 it wasnt required but you will encounter various authentication issues and errors on the client side just to name a couple .you would think they'd know and tell u more about disabling ssl on exchange. Ive never heard of anyone saying u have to disable ssl unless they ask u to replace it..unless you dont require external access then u can use a self signed ssl.
0
 

Accepted Solution

by:
timgreen7077 earned 0 total points
ID: 41750444
I have reached out to Microsoft on this and disabling SSL will not cause and issue. The actually sent me a link with instructions and via multiple emails assured me that it will not affect anything. Only devices that rely on SSL 2.0 or 3.0 will be affected but generally most devices no understand TLS, so disabling SSL will be fine. See link

https://blogs.technet.microsoft.com/samdrey/2014/10/17/vulnerability-in-ssl-3-0-poodle-attack-and-exchange-2010-or-exchange-2013/
0
 

Author Closing Comment

by:timgreen7077
ID: 41756108
After communicating with Microsoft they assured me that disabling SSL will not cause any issues other than devices that only speak SSL but that is rare.
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A list of top three free exchange EDB viewers that helps the user to extract a mailbox from an unmounted .edb file and get a clear preview of all emails & other items with just a single click on mailboxes.
Unified and professional email signatures help maintain a consistent company brand image to the outside world. This article shows how to create an email signature in Exchange Server 2010 using a transport rule and how to overcome native limitations …
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question