25.06.2013 Views

Guide to the Secure Configuration and Administration of Microsoft ...

Guide to the Secure Configuration and Administration of Microsoft ...

Guide to the Secure Configuration and Administration of Microsoft ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Exchange <strong>to</strong> “Foreign” E-mail System<br />

Jack (Client)<br />

Exchange can also connect <strong>to</strong> what Micros<strong>of</strong>t terms “foreign” e-mail systems. Foreign email<br />

systems are simply e-mail networks outside <strong>of</strong> <strong>the</strong> Exchange environment, such as<br />

X.400 <strong>and</strong> Simple Mail Transport Pro<strong>to</strong>col (SMTP) mail systems. Exchange Server 5.0<br />

<strong>and</strong> Exchange Server 5.5 provide connec<strong>to</strong>rs for both <strong>of</strong> <strong>the</strong>se. Exchange Server 5.5<br />

<strong>and</strong> third party vendors <strong>of</strong>fer additional connec<strong>to</strong>rs that are not covered in this document.<br />

The X.400 connec<strong>to</strong>r provides connectivity <strong>to</strong> X.400 hosts. Server-<strong>to</strong>-server<br />

communication between Exchange <strong>and</strong> X.400 hosts is not encrypted, nor is any kind <strong>of</strong><br />

robust au<strong>the</strong>ntication provided. Only plain text au<strong>the</strong>ntication is available as an option.<br />

The Internet Mail Service (IMS) provides connectivity <strong>to</strong> SMTP hosts. In Exchange<br />

Server 5.0 <strong>the</strong>re are no encryption or au<strong>the</strong>ntication options when connecting <strong>to</strong> non-<br />

Exchange SMTP hosts. In Exchange Server 5.5, <strong>Secure</strong> Socket Layer (SSL) encryption<br />

<strong>and</strong> Simple Au<strong>the</strong>ntication <strong>and</strong> Security Layer (SASL) au<strong>the</strong>ntication can be used<br />

provided <strong>the</strong>se features are supported by <strong>the</strong> o<strong>the</strong>r hosts with which <strong>the</strong> Exchange<br />

Server will connect. Please note that this feature is not well documented <strong>and</strong> attempts<br />

by <strong>the</strong> author <strong>and</strong> o<strong>the</strong>rs <strong>to</strong> enable SMTP over SSL have failed.<br />

GWS1 (Server)<br />

VulCo<br />

(Organization )<br />

Washing<strong>to</strong>n (Site)<br />

Baltimore (Site)<br />

GWS2 (Server)<br />

Au<strong>the</strong>ntication:<br />

-X.400: Simple, non-encrypted<br />

passwords<br />

-Internet Mail Service: SASL optional<br />

(Exchange 5.5)<br />

Encryption:<br />

-X.400: None<br />

-Internet Mail Service: SSL optional<br />

(Exchange 5.5)<br />

Foreign E-mail Networks<br />

Figure 3 Exchange <strong>to</strong> “Foreign” E-mail Systems -- Security Options<br />

24

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!