Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


October 1998

Using Exchange Clients Securely


RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Authenticating and encrypting MAPI, POP3, and IMAP clients and messages

If you're like me, you probably send and receive a lot of email every day. But did you ever stop and wonder how many of these messages are secure from outside attacks? In the June 1998 and July 1998 issues, I described how Microsoft's Exchange, Outlook, and Outlook Express email clients use remote procedure calls (RPCs), Simple Mail Transfer Protocol (SMTP), Post Office Protocol (POP) 3, and Internet Message Access Protocol (IMAP) to access mailboxes on an Exchange server (for more information, see "Related Articles in Windows NT Magazine," page 140).

The default installation of each of Microsoft's email clients is not as secure as you might like, and your correspondence might be more vulnerable than necessary. Fortunately, you can take several steps to help secure your email system. In this article, I'll describe the security and privacy features of these Exchange email clients and show you how to protect your account information and encrypt the messages you send.

Vulnerable Assets
In the process of securing Exchange email clients, you must protect two types of assets: logon credentials and message data. When you attempt to open an Exchange mailbox or browse a public folder, your client software provides logon credentials to the Exchange server. The Exchange server uses this information to decide whether you have the authority to access the requested information. The logon credentials are in the form of an account name and password or a secure hash (i.e., an encrypted string derived from a username and password--for information about hash algorithms, see "Related Articles in Windows NT Magazine," page 140). You need to protect the logon credential information; otherwise a hacker might gain access to your internal mail system or other NT resources. Each Exchange email client has configurable options that control how the client presents the logon credential information.

After the Exchange server validates your logon credentials, your email client can start transferring mail messages. The message content might be innocuous or highly confidential. Regardless of the message content, you need to know what level of protection the systems are providing the message when it is in transit between the Exchange email client and server or stored on the Exchange server. Each Exchange client has configurable parameters that let you control this level of protection. To protect the message content, you need to apply some degree of encryption by using algorithms such as Data Encryption Standard (DES), 3DES, or CAST (a proprietary algorithm that Carlisle Adams and Stafford Tavares devised) to the message before transmission.

Data Transmission
When you send an email message from your desktop to the recipient's home server, the message can travel over LAN links, remote access (asynchronous) links, WAN connections, and even across the Internet. Each link along the way has different vulnerabilities and security features. You can't control all the vulnerabilities and configure all the features, and you usually can't predict which path the information will take from the client to the destination server.

You need to examine data transmittal security from several points of view. For example, some security options that you can configure on your client system depend on the message transfer protocol running at the application layer of the Open Systems Interconnection (OSI) stack (e.g., POP3, Messaging API--MAPI, IMAP, and HTTP). As I discussed in my previous articles, you can use any of these protocols to submit a message from your desktop to an Exchange server. Similarly, at the transport layer, you can configure some security features such as Secure Sockets Layer (SSL), Transport Layer Security (TLS), and IP Security (IPSec--for information about IPSec, see "Related Articles in Windows NT Magazine"). Although security at this layer is independent of what happens at the application (Exchange) layer, the Exchange client or server can call the stack and request that the sending and receiving systems negotiate the use of an encrypted connection to transfer the message.

   Previous  [1]  2  3  4  Next 


Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Friday at PASS Europe 2006

Kevin talks about the closing day of the event and shares a funny Microsoft film. ...

Escape From Yesterworld

Kevin points you to the funniest SQL Server website ever! ...

PsExec

This freeware utility lets you execute processes on a remote system and redirect output to the local system. ...


Security Whitepapers The Impact of Messaging and Web Threats

Why SaaS is the Right Solution for Log Management

Protecting (You and) Your Data with Exchange Server 2007

Related Events Storage Consolidation for Your Microsoft Applications: Reducing Cost and Complexity

How IE7 & The New Extended Validation SSL Certificates Impact Your Site

The Myths & Truths of Email Management with SharePoint

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing