FW: Email Encryption Between Servers

From: check (check@wescom.org)
Date: 04/02/03

  • Next message: Moeckel, Sharon: "RE: Legislation on employee monitoring"
    From: check <check@wescom.org>
    To: "'security-basics@securityfocus.com'" <security-basics@securityfocus.com>
    Date: Wed, 2 Apr 2003 09:19:26 -0800 
    
    

    -----Original Message-----
    From: Michael Osten [mailto:mosten@bleepyou.com]
    Sent: Tuesday, April 01, 2003 4:53 PM
    To: security-basics@securityfocus.com
    Subject: RE: Email Encryption Between Servers

    On Tue, 2003-04-01 at 11:27, Robinson, Sonja wrote:
    > We evaluated three enterprise solutions and bid them out. I believe that
    > once e-mail leaves your network using exchange it is automatically sent
    > clear text, hence the need for encryption. I am not an exchange
    > administrator so... And if you are sending PHI or GLBA I would send in no
    > less then 128-bit anyway.
    >
    > There are a number of issues you need to think of when evaluating
    encryption
    > including, logging/reporting, forensics & investigations, ease of use for
    > users, ease of administration, key exchanges, can I force my business
    > partners to buy the same product/hardware/service, send to anyone
    > capability, what constitutes due diligence, cost, etc.
    >
    > I am not endorsing any one vendor and these are not necessarily the
    opinions
    > of my employer and should not be construed as such.
     

    I'm pretty sure that Exchange (I know Sendmail/Postfix/Qmail/Exim do)
    support StartTLS?

    The benefit of StartTLS is that it is free (other than the cert), open
    standards, and will automatically encrypt communications between any
    other mail sever running StartTLS (not just your partners).

    ---------------------------
    Michael Osten

    http://lists.netsys.com/pipermail/full-disclosure/2003-February/008369.html
    When caught, McWilliams was seen at his
    computer finishing a non fictional piece titled "Art
    of Deception to the 100th Power. Pi don't equal Pie
    Bitch."

    -------------------------------------------------------------------
    SurfControl E-mail Filter puts the brakes on spam,
    viruses and malicious code. Safeguard your business
    critical communications. Download a free 30-day trial:
    http://www.securityfocus.com/SurfControl-security-basics

    **********************************************************************
    This email and any files transmitted with it are confidential
    and intended solely for the use of the individual or entity to
    whom they are addressed. If you have received this email
    in error, please delete it immediately and advise the sender.
    WESCOM CREDIT UNION (626) 535-1000
    **********************************************************************

    -------------------------------------------------------------------
    SurfControl E-mail Filter puts the brakes on spam,
    viruses and malicious code. Safeguard your business
    critical communications. Download a free 30-day trial:
    http://www.securityfocus.com/SurfControl-security-basics


  • Next message: Moeckel, Sharon: "RE: Legislation on employee monitoring"

    Relevant Pages

    • RE: Email Encryption Between Servers
      ... Subject: Email Encryption Between Servers ... gateway between Exchange and the Internet. ... > Subject: Email Encryption Between Servers ... > SurfControl E-mail Filter puts the brakes on spam, ...
      (Security-Basics)
    • RE: Email Encryption Between Servers
      ... > once e-mail leaves your network using exchange it is automatically sent ... hence the need for encryption. ... > There are a number of issues you need to think of when evaluating encryption ... The benefit of StartTLS is that it is free, ...
      (Security-Basics)
    • RE: Email Encryption Between Servers
      ... Even though IPSec enabled communication between two mail servers, ... > Subject: Email Encryption Between Servers ... Some of our partners are also using Exchange and some are ... > SurfControl E-mail Filter puts the brakes on spam, ...
      (Security-Basics)
    • Re: Backup solution 3Tbytes+
      ... They run an rsync, encrypted exchange overnight, in my unmetered hours. ... In return for the bit of electricity they use, they also store my backup ... Goodsync running on my Windows systems to a Share on their local drives ... Also check where you've stored your data's encryption keys so your data ...
      (uk.comp.homebuilt)
    • Re: Use of Microsoft Enhanced CSP in custom bulit applications
      ... Usually algorithms with long keys are used for key ... exchange only, while more efficient algorithms like Diffie-Hellman. ... Peter Guttmann's Encryption and Security tutorial ... >>> exchanges files with our clients over the Internet. ...
      (microsoft.public.security)