Re: How secure is SSL emails?

From: Adam O'Brien (adamobrien_at_gmail.com)
Date: 06/25/04


Date: 25 Jun 2004 08:14:36 -0700

jasondavis19@hotmail.com (Jason Davis) wrote in message news:<9e03a267.0406250206.240b6d6c@posting.google.com>...
> Hi there,
>
> My boss has asked me to look at SSL authentication for our MS-Exchange
> server. As I found out, I can buy a site certificate from Verisign and
> instal it, to encrypt/sign all outgoing/incoming messages and account
> information (username/password).
>
> The user will need to switch his outlook and check "this server
> requires SSL".
>
> My question is - how secure are those emails and account information?
> in comparison to other forms of protecting email messages?
>
> Thanks,
>
> Jason

SSL is generally very secure. Make sure that you are using an up to
date version of SSL i.e. that you apply patches, and that it's not an
old US 'export-grade' system. As long as you avoid these two pitfalls
you don't need to worry about someone 'breaking the encryption' and
getting access to your messages.
Of course, as Mike alludes to, attackers don't, generally, access
improper information by code breaking. They do it by finding ways of
accessing unencrypted versions of the data. So if you're using SSL
from Exchange server to recieiving client, that will be secure. The
real sources of leaks come from within your network, from people not
bothering to turn SSL on and from those people who feel the need to
print every email, then just throw it out in the normal trash.
Adam



Relevant Pages

  • Most users cant connect to our SSL-- help!
    ... I've included all relevant SSL settings from our ... Subject: Large percentage of customers cannot connect to https: ... server, which then grinds indefinitely. ... "2) Your secure order form is not working. ...
    (comp.security.misc)
  • Most users cant connect to our SSL-- help!
    ... I've included all relevant SSL settings from our ... Subject: Large percentage of customers cannot connect to https: ... server, which then grinds indefinitely. ... "2) Your secure order form is not working. ...
    (comp.security.ssh)
  • Most users cant connect to our SSL-- help!
    ... I've included all relevant SSL settings from our ... Subject: Large percentage of customers cannot connect to https: ... server, which then grinds indefinitely. ... "2) Your secure order form is not working. ...
    (comp.security.unix)
  • Re: Antw: Re: LDAP Authentication Problem
    ... TLSv1 und wird auf einen SSL Client Hello Request mit TLSv1 nicht ... antworten anstatt ein SSLv3 Server Hello. ... the LDAP PAM module and the shadow package. ...
    (de.comp.sys.novell)
  • Re: ModSSL - Knoppix 3.3
    ... NameVirtualHosts and SSL don't mix. ... This automatically pushes an incorrect http request to the secure host over ... > I create some server key & crt. ...
    (Focus-Linux)

Quantcast