Wilders Security Forums  

Go Back   Wilders Security Forums > Privacy Related Topics > privacy general
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 10th, 2008, 02:19 PM
Defenestration Defenestration is offline
Frequent Poster
 
Join Date: Jul 2004
Posts: 990
Default SMTP Server Connection using TLS (ie. port 465) & Secure Authentication ?

My e-mail client allows me to specify the SMTP connection to be either

- Regular on port 25
- Secure to regular (STARTTLS) on port 25
- Secure to dedicated (TLS) on port 465

It also has another couple of settings for Authentication:

- Perform SMTP authentication
- Require secure SMTP authentication

If I use Secure to dedicated (TLS) + Perform SMTP authentication, but not require secure authentication, is all data transferred between my e-mail client and the SMTP server (ie. username + password, and all message content) encrypted ?

Is secure authentication needed when connecting using secure to dedicated (TLS) on port 465 ?

Same questions for POP - Is all content encrypted when receiving mail on a secure to dedicated connection (TLS) on port 995 ?

Is it OK to use regular POP authentication when using TLS on port 995 ?

It's confusing me because you can have both secure authentication and a secure TLS connection.
  #2  
Old April 15th, 2008, 02:07 AM
Mrkvonic Mrkvonic is offline
Linux Systems Expert
 
Join Date: May 2005
Posts: 7,465
Default Re: SMTP Server Connection using TLS (ie. port 465) & Secure Authentication ?

Hello,

POP is not encrypted. So in order to encrypt POP, you use tunneling - encapsulate POP in an encrypted communication tunnel.

This can be done in several ways.

In your case, the data transfered will be encrypted. However, the two differences between the authentication methods:

Regular - your credentials are sent in unecrypted form to the server. Once the communication is established, all data sent will be encrypted.

Secure authentication - you will first establish a secure tunnel and then authenticate using it. This is the preferred method. But you must trust the server you communicate with.

Mrk
__________________
http://www.dedoimedo.com

All your base are belong to us

Linux Systems Expert / Systems Programmer, Linux System Administrator, LPIC-1, LPIC-2 (WIP), GSEC, CCHD, CCHA
  #3  
Old April 24th, 2008, 07:00 PM
SteveTX's Avatar
SteveTX SteveTX is offline
Very Frequent Poster
 
Join Date: Mar 2007
Location: TX
Posts: 1,641
Default Re: SMTP Server Connection using TLS (ie. port 465) & Secure Authentication ?

Thrower of things out windows,

Should I assume you are using TheBat! as your email client?

You want to use SSL/STARTTLS or TLS, with secure authentication.

The only question is if your smtp server supports it.
__________________
The Deep Packet Inspection in Act I will be used for domestic surveillance in Act II. | Ye shall know the truth, and the truth shall make you mad. ~Aldous Huxley
Never duplicated, frequently impersonated (on Usenet) | PGP Fingerprint: 4A83 2DB4 E8E5 46D9 59A1 3A3D D88F D7B7 BB67 8C30
 

Wilders Security Forums > Privacy Related Topics > privacy general « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:15 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums