Go Back   Defender Hosting Forums > PowerVPS Virtual Private Servers > Linux VPS - Security and Tuning

Linux VPS - Security and Tuning Security and Tuning Discussion for Linux Virtual Private Servers based on Virtuozzo by SWsoft

Reply
 
Thread Tools Display Modes

  #1  
Old 09-12-2005, 02:36 AM
Ulysses Ulysses is offline
Member
 
Join Date: Mar 2005
Location: Australia
Posts: 70
Ulysses is an unknown quantity at this point
Question Encrypted SMTP

Hi,

A client wants to encrypt (SMTP with SSL or TLS) his email (for one particular email account) en-reute from his mailbox on the server to his desktop email client (Outlook).

How can this be done and where, if at all, does Thawte's "Personal Email CA" enter into the picture?

Thanks
Reply With Quote

  #2  
Old 09-12-2005, 04:59 AM
Starchild
Guest
 
Posts: n/a
Default

I'm not sure if I understand you correctly. But if you setup your mail client to use ssl/tls for IMAP/SMTP the connection is encrypted and therefor any data (emails) sent and received are encrypted as well. But this is different from digitally signing/encrypting individual emails.
Reply With Quote

  #3  
Old 09-12-2005, 06:17 AM
Ulysses Ulysses is offline
Member
 
Join Date: Mar 2005
Location: Australia
Posts: 70
Ulysses is an unknown quantity at this point
Default

Quote:
Originally Posted by Starchild
I'm not sure if I understand you correctly. But if you setup your mail client to use ssl/tls for IMAP/SMTP the connection is encrypted and therefor any data (emails) sent and received are encrypted as well....
It's what's required at the server end that the email client interacts with (and how) is what I'm wondering.

Plus, I'm curious about the relationship of these technical communications factors with Thawte's "Personal Email CA", if any.
Reply With Quote

  #4  
Old 09-12-2005, 07:05 AM
Zaf Zaf is offline
Senior Member
 
Join Date: Aug 2005
Posts: 294
Zaf is on a distinguished road
Default

Quote:
Originally Posted by Ulysses
It's what's required at the server end that the email client interacts with (and how) is what I'm wondering.

Plus, I'm curious about the relationship of these technical communications factors with Thawte's "Personal Email CA", if any.
Don't think you really need any changes at the server side unless your APF has not been setup to allow traffic on port number 995 and 465.

If your client needs just simple SSL connection to his mail account, I dont think you need a Certificate for that. If it were for the masses to login to your server to do transactions or if you had a service like Gmail, a Certificate would make sense.

In case your client insists for SSL certificate installed, you'd have to get in touch with support and they'll get you setup right away.
Reply With Quote

  #5  
Old 09-12-2005, 09:59 AM
nadzri nadzri is offline
Senior Member
 
Join Date: Feb 2005
Location: Kuala Lumpur
Posts: 258
nadzri is on a distinguished road
Send a message via MSN to nadzri
Default

Thawte's cert is about digitally signing the email, saying "this email is really from me, and not someone else pretending to be me".

Get support to set up secure, encrypted POP3 for you if I'm getting you correctly (from mail server to mail client).
Reply With Quote

  #6  
Old 11-02-2005, 02:58 PM
zoney70 zoney70 is offline
Junior Member
 
Join Date: Oct 2005
Location: Tucson, AZ
Posts: 16
zoney70 is on a distinguished road
Default

The only way I know how to encrypt SMTP is tunnel it via SSH.

I personally use Tunnelier (http://www.bitvise.com/tunnelier.html) as my SSH client. I configure Tunnelier to forward both imap and smtp. Then all I have to do is configure my mail client (ThunderBird) to use Localhost for both imap and smtp and everything is encrypted. (This also provides me with a console and SFTP of course)

My setup is actually a bit more complicated than described because I use multiple concurrent instances of Tunnelier to simultaneously access multiple servers. This is easy to do because Tunnelier will listen on any port you specify and forward it to any other port you specify. Because TBird requires each email service to have a unique servername/username combination, I had to set up a localhost alias in my Windows hosts file for each server I access.

If you give your client SSH access, I suggest disabling the SSH SFTP capability for security reasons.
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Can I enable Shell Fork Bomb Protection & the SMTP Tweak? afrederc Linux VPS - cPanel 2 05-27-2006 12:59 AM
Add smtp port (26) ? hagmund Linux VPS - General 2 05-18-2006 05:57 AM
Anylizing Stats SMTP mbrando Linux VPS - General 2 03-27-2006 10:16 AM
SMTP Authentication Rocky Linux VPS - cPanel 3 06-05-2005 04:23 AM



All times are GMT -4. The time now is 12:29 AM.


vBulletin skin developed by: eXtremepixels
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright Defender Technologies Group, LLC 2006