Thanks to everyone who replied to this question.

I had been under the impression (not necessarily an educated one) that only email clients would engage in SMTP AUTH with a server. If I can set up Exchange as a server to engage in SMTP AUTH with Imail, I agree that sounds like the simplest option.

Someone else I spoke with who has some experience with Exchange also suggested configuring users' Outlook clients to POP/SMTP via our Imail server, and engage in IMAP only with the Exchange server. Then the Outlook clients could be configured to utilize SMTP AUTH with our server.

Thanks,
Adam

----- Original Message ----- From: "Sanford Whiteman" <[EMAIL PROTECTED]>
To: "Adam Greene" <[email protected]>
Sent: Monday, August 20, 2007 3:40 AM
Subject: Re: [IMail Forum] being a smart host without being an open relay


I  don't  quite  understand  how  they could even be receiving email
reliably  with  a  dynamic  IP  address  on  their  mail server; I'm
checking  with  the networking company now. Maybe they're using some
kind of dynamic DNS service?

Obviously,  they are, or their MX record would be constantly obsolete.
Nobody would manage something like that manually.

I need the Exchange server to authenticate to Imail somehow. There's
also  the  issue  of  outbound  port  25 being blocked by many major
ISP's.

Yeah,  so  set  then  up  to  authenticate on port 25 or on your IMail
alternate  port.  MS  SMTP  can  do outbound AUTH to a smart host just
fine.

We've  toyed  with the idea of requiring SSL connections on port 465
from the Exchange server

If  the  client  is  on a dynamic IP, you can't require SSL or TLS for
them  alone,  unless  you're  using  some other SSL endpoint that uses
client  certs  or suchlike.

Don't worry about encryption if the client isn't demanding encryption.
Worry  about relaying for them using the standard method of creating a
privileged  session  from  dynamic  IPs:  SMTP  AUTH. From what you've
written,  I  don't  understand what's the big issue here. SMTPS or TLS
are  frills.  VPN tunnel is a frill. They're fine, but if all you want
to do is relay, give 'em an AUTH account and you're done.

I'm  not  sure of what kind of server-to-server authentication I can
set up in Imail to prevent us from becoming an open relay.

Relay  for  IPs and authenticated sessions only. You already should be
doing  this.  Their  server becomes another authenticated session with
the same privileges as any other.

--Sandy


------------------------------------
Sanford Whiteman, Chief Technologist
Broadleaf Systems, a division of
Cypress Integrated Systems, Inc.
e-mail: [EMAIL PROTECTED]

SpamAssassin plugs into Declude!

http://www.imprimia.com/products/software/freeutils/SPAMC32/download/release/

Defuse Dictionary Attacks: Turn Exchange or IMail mailboxes into IMail Aliases!

http://www.imprimia.com/products/software/freeutils/exchange2aliases/download/release/

http://www.imprimia.com/products/software/freeutils/ldap2aliases/download/release/

To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/










To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to