Given plenty of mail communication is still non-encrypted, having TLS1.0 is an 
improvement, granted 1.2 is the ultimate goal.

But shouldn't your public mail server be out of scope for PCI?

Surely it's not handling cardholder data, nor talking to a system that is, 
therefore should be excluded from the requirement?






________________________________
From: AusNOG <[email protected]> on behalf of Bradley Silverman 
<[email protected]>
Sent: Monday, 23 July 2018 15:06
To: Mark Newton
Cc: [email protected]
Subject: Re: [AusNOG] Issues receiving from TPG Mail servers.

Hi Matt,

Really appreciate you sending me that email, I will definitely send an email 
through to there!

@Mark Certainly not! PCI Compliance requires that TLSv1.0 be disabled on the 
server. Postifx/Exim/Dovecot are not exception to the rule, if we disable 
TLSv1.0 on the server and remove the weak cipher, then TPG's MTAs aren't able 
to send mail to us.

Regards,

Bradley Silverman | VentraIP Australia
Technical Operations

mobile. +61 418 641 103
phone. +61 3 9013 8464

On Mon, Jul 23, 2018 at 2:48 PM, Mark Newton 
<[email protected]<mailto:[email protected]>> wrote:
You're trying to exchange payment card information over email?

  - mark

On Jul 23, 2018, at 1:30 PM, Bradley Silverman 
<[email protected]<mailto:[email protected]>> wrote:

Does anyone have a contact at TPG regarding their mail servers?

We are having issues with their mail servers using non-PCI compliant ciphers 
which is stopping our servers accepting mail from them.


Regards,

Bradley Silverman | VentraIP Australia
Technical Operations

mobile. +61 418 641 103
phone. +61 3 9013 8464
_______________________________________________
AusNOG mailing list
[email protected]<mailto:[email protected]>
http://lists.ausnog.net/mailman/listinfo/ausnog


_______________________________________________
AusNOG mailing list
[email protected]
http://lists.ausnog.net/mailman/listinfo/ausnog

Reply via email to