RE: Email Encryption Between Servers

From: Garbrecht, Frederick (FGarbrecht@ecogchair.org)
Date: 04/01/03

  • Next message: Sander de Rijk: "RE: Win2000 Directory Permissions"
    From: "Garbrecht, Frederick" <FGarbrecht@ecogchair.org>
    To: 'Al Cooper ' <alc@2wh.com>, "'security-basics@securityfocus.com '" <security-basics@securityfocus.com>
    Date: Tue, 1 Apr 2003 12:52:11 -0500 
    
    

    Since you're doing this to comply with HIPAA, then you and your partner
    companies most likely already have firewalls in place; why don't you set up
    a gateway to gateway vpn between your company and each of your partners to
    provide transparent encryption services for your smtp traffic. You can set
    up the appropriate routing and FW rules so that only the mail going to your
    partners gets routed through the encrypted tunnel, the rest would get sent
    out as usual. Decryption would occur transparently on the distal gateway,
    and then the unencrypted email would then be passed to the partners smtp
    server for delivery. You can certainly do this with Checkpoint and PIX; you
    can probably also rig something up using the Windows native ipsec, although
    I've never done this.

    Good luck,
    Fred
    -----Original Message-----
    From: Al Cooper
    To: security-basics@securityfocus.com
    Sent: 3/31/03 12:44 PM
    Subject: Email Encryption Between Servers

    We are attempting to set up secure e-mail with our partner companies to
    comply with the upcoming HIPAA requirements. I would like to find a way
    to
    encrypt all e-mail going between our mail server and our partners. We
    are
    using Exchange. Some of our partners are also using Exchange and some
    are
    using other SMTP servers.

    Is there a way to automatically force all e-mail between our two e-mail
    servers (either Exchange to Exchange or Exchange to SMTP) to be
    encrypted
    then decrypted on arrival with no end user intervention? If there are,
    what affect, if any will these encryption methods have on our overall
    network security.

    Thanks for your help,

    -------------------------------------------------------------------
    SurfControl E-mail Filter puts the brakes on spam,
    viruses and malicious code. Safeguard your business
    critical communications. Download a free 30-day trial:
    http://www.securityfocus.com/SurfControl-security-basics

    -------------------------------------------------------------------
    SurfControl E-mail Filter puts the brakes on spam,
    viruses and malicious code. Safeguard your business
    critical communications. Download a free 30-day trial:
    http://www.securityfocus.com/SurfControl-security-basics


  • Next message: Sander de Rijk: "RE: Win2000 Directory Permissions"

    Relevant Pages

    • Re: Email Encryption Between Servers
      ... >We are attempting to set up secure e-mail with our partner companies to ... >encrypt all e-mail going between our mail server and our partners. ... Some of our partners are also using Exchange and some are ... >using other SMTP servers. ...
      (Security-Basics)
    • Re: Email Encryption Between Servers
      ... > encrypt all e-mail going between our mail server and our partners. ... Some of our partners are also using Exchange and some are ... > using other SMTP servers. ...
      (Security-Basics)
    • Email Encryption Between Servers
      ... encrypt all e-mail going between our mail server and our partners. ... Some of our partners are also using Exchange and some are ... using other SMTP servers. ...
      (Security-Basics)
    • RE: Email Encryption Between Servers
      ... once e-mail leaves your network using exchange it is automatically sent ... There are a number of issues you need to think of when evaluating encryption ... Subject: Email Encryption Between Servers ... encrypt all e-mail going between our mail server and our partners. ...
      (Security-Basics)
    • Re: Data Encryption Product Limits: 300 Datasets per month
      ... The intent for encryption is for ... Also we have one Accelerator for each CP engine configured for use. ... Public/Private Keys pairs and giving out the Public key to the world for Data ... Exchange Partners to use when sending us their data. ...
      (bit.listserv.ibm-main)