TLS
3 TopicsTLS Client issues on Exchange server on premise
hi all, I have on-premise Exchange 2013. When I send email to 1 particular domain it returns "530 Must issue STARTTLS". This got me thinking that my TLS settings might be misconfigured. So i did try online CheckTLS tool. It appears that I have no problems sending encrypted emails (TLS1.2). When I send emails from my domain to my gmail account I can see TLS1.2 in the header also. However when I tested receiving it says "TLS is not an option for this server". It seems like i've tried everything from here https://learn.microsoft.com/en-us/exchange/plan-and-deploy/post-installation-tasks/security-best-practices/exchange-tls-configuration?view=exchserver-2019 The one thing I did not try is to disable TLS1.0 and 1.1, but can this be the problem? I also checked IgnoreSTARTTLS parameters on receive and send connectors, it is set to False. Can anyone help?Solved1.6KViews0likes3CommentsRemove TLS 1.0/1.1 and 3DES Dependencies
When I went to http://servicetrust.microsoft.com to see any users still using TLS 1.9/1.1. How do I remove TLS 1.0/1.1. How do I go about making these compatible so they work come February 28, 2019 when Office 365 retires 3DES? Thank you for your help. Here is what I get: Notice: This report includes 3DES and TLS1.0/1.1 usages. UserName / IP address Protocol Agent Count Report Date xxxx@wynnetr.com TLS1.0/1.1 Microsoft+BITS/7.5 12 1/30/2019 xxxx@wynnetr.com TLS1.0/1.1 Microsoft+Office/16.0+(Windows+NT+10.0;+Microsoft+Outlook+16.0.11126;+Pro) 2 1/30/2019 xxxx@wynnetr.com TLS1.0/1.1 Microsoft+Office/16.0+(Windows+NT+10.0;+Microsoft+Outlook+16.0.11126;+Pro) 1 1/30/2019 xxxx@wynnetr.com TLS1.0/1.1 Android-SAMSUNG-SM-G930V/101.80000 1 1/30/2019 xxxx@wynnetr.com TLS1.0/1.1 Android-SAMSUNG-SM-G360V/101.50101 2 1/30/2019 xxxx@wynnetr.com TLS1.0/1.1 Apple-iPhone8C4/1507.77 1 1/30/2019 xxxx@wynnetr.com TLS1.0/1.1 Microsoft+BITS/7.5 8 1/30/201915KViews2likes11CommentsCan Exchange Online Protection check for TLS before forcing encryption
I know this is possible in Iron Port but not sure if EOP can handle this scenario, so asking for others opinions. In Iron Port, you can setup rules to say "If this email contains DLP data, check for TLS delivery. If email is being sent with TLS -> do not force message encryption. If email is not being sent with TLS -> Force message encryption." Can EOP execute similar functionality. Essentially what I am looking for is whether not EOP is smart enough to only use OME when TLS is not available.Solved1.8KViews1like1Comment