Re: TLS



On the receive side, (SMTP VSI) once you install the certificate, it is
optional. A client connecting to your server may use it but is not required.
At most, you can enforce that basic (base64 encoded but effectively clear
text) authentication would require TLS.

On the sending side, (send connector) once you enable the "use TLS" setting,
on the Advanced->Outbound Security page, TLS becomes mandatory. Your server
acting as a client will refuse to send mail unless it can successfully
negotiate a TLS encrypted session.

--
Please do not send email directly to this alias. This alias is for newsgroup
purposes only.

This posting is provided "AS IS" with no warranties, and confers no rights.


"DavidP" <bill@xxxxxxxxxxxx> wrote in message
news:OYgNu3l0GHA.3464@xxxxxxxxxxxxxxxxxxxxxxx
Thanks for your swift response.
Is it possible to enable TLS but not enforce it ?



"Matt Kuzior [MSFT]" <mattku@xxxxxxxxxxxxxxxxxxxx> wrote in message
news:uSrVx5e0GHA.1252@xxxxxxxxxxxxxxxxxxxxxxx
This KB article should help you on your way.
http://support.microsoft.com/kb/829721/en-us

The procedure involves "installing" a certificate on the receiving side.
As
soon as you install the certificate, your server will begin to advertise
"STARTTLS" in response to the EHLO command and can receive TLS encrypted
mail. On the remote side you can require TLS on the send connector.

Repeat the procedure in the reverse direction for two-way TLS.

--
Please do not send email directly to this alias. This alias is for
newsgroup
purposes only.

This posting is provided "AS IS" with no warranties, and confers no
rights.


"DavidP" <bill@xxxxxxxxxxxx> wrote in message
news:elnyxNd0GHA.3440@xxxxxxxxxxxxxxxxxxxxxxx
Ive been asked to setup encypted emails for one of our sister companies
domains.

we have to be able to send and recieve TLS encrypted emails to and from
our
sister company.

We have an ISA2004 server with an exchange 2000 server behind. Ive jsut
bought a certificate for use and am now ready to set it up.

problem is the info out there is pretty vague.

From what i gather, i create a new SMTP connector in exchange and in the
address space add in the sister companies domain name. set for TLS
Then setup a new SMTP virtual server and again tell it to use tls

what do i have to do with the certificate ? i guess install it within
exchange IIS. Does the sister company also have to install this
certificate
?

and then do we have to do it all again at their end ?

thanks in anticipation.






.



Relevant Pages

  • Re: New Event Log Errors!
    ... Somehow along those lines I'd also installed the Certificate Authority ... Did you apply the last Server Pack for SBS Server? ... Please install Windows Support Tools on the win2k3 sp1 problematic ... Microsoft is providing this information only as a convenience to you: ...
    (microsoft.public.windows.server.sbs)
  • Re: Adding EXCH2007 SP1 box to existing EXCH2003 SP2 Org
    ... Certificates - going to be using a SAN Certificate like I have many times before. ... We are making this a virtual server (someone is going on-site on Thursday to install VMWare (which will kill everything on this box) and WIN2008 Server SP1 x64 and then I will install EXCH2007 SP1. ... as mentioned - ISA was not involved in any of those eight environments.... ...
    (microsoft.public.exchange.admin)
  • Re: Terminal Services over a VPN
    ... Create a certificate request and submit it to godaddy in order to obtain a public cert. ... You can use the wizard in IIS Manager for this by creating a new website that matches the above name (on your TS server), right-click and choose properties, directory security tab, server certificate button. ... After the install you can stop or delete the website created above since you don't need it for anything. ...
    (microsoft.public.windows.terminal_services)
  • Re: Outlook RPC over HTTp deosnt work
    ... Go to remote web workplace (or Outlook Web Access), accept the certificate prompt, 'view', and 'install' the certificate - accepting all the defaults. ... > when you try to use RPC over HTTP to connect the Exchange Server. ...
    (microsoft.public.windows.server.sbs)
  • Re: Please Help: Additional TSL Questions
    ... As long as your server is advertising the TLS ESMTP verbs, ... >>> The method for obtaining an SSL certificate is to go into IIS Manager ... >>> Default SMTP Virtual Server, Access Tab, then click on the Certificate ...
    (microsoft.public.exchange.admin)

Quantcast