A Microsoft Outlook email forum. Outlook Banter

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Go Back   Home » Outlook Banter forum » Microsoft Outlook Email Newsgroups » Outlook - General Queries
Site Map Home Register Authors List Search Today's Posts Mark Forums Read Web Partners

OWA 2003 and SSL Security Vulnerability



 
 
Thread Tools Search this Thread Display Modes
  #1  
Old August 6th 08, 05:23 AM posted to microsoft.public.outlook
ExchangeGuy
external usenet poster
 
Posts: 3
Default OWA 2003 and SSL Security Vulnerability

Hello--

I'm hoping you can provide some direction. We currently are running
Exchange 2003 Enterprise with an OWA server in the DMZ. Yes.. I know
best practices recommend routing this traffic through an ISA server.
There is a trusted SSL certificate on the server and we have many
mobile device users.

Anyway, on a recent scan, we received the following security notice.

SSLv2 Supported
This SSL service supports SSLv2 connections. SSLv2 has known
cryptographic weaknesses. Secure web applications should only enable
the SSLv3 or TLSv1 protocols. For PCI compliance validation scans,
note that either or both of the SSLv3 or TLSv1 protocols must be
enabled (i.e., SSLv2 can not be the only supported protocol version).

They provide the following resolution suggestion:

Disable the use of SSL 2.0 if possible. Note that some older client
software may not support the most recent protocol versions.

Refer to the following:

Microsoft Knowledge Base article to remove SSLv2 support from
Microsoft's Internet Information Server (IIS):
http://support.microsoft.com/kb/187498
http://support.microsoft.com/kb/245030

I've been scouring the boards trying to find out if:

1. Does OWA 2003 support SSL v3?
2. If I follow the suggestions and disable SSLv2, will it affect the
users of mobile devices running Windows Mobile 5/6?

I haven't been able to locate documentation regarding the supported
versions.

Any direction would be appreciated!
Ads
  #2  
Old August 8th 08, 05:29 PM posted to microsoft.public.outlook
Milly Staples [MVP - Outlook][_2_]
external usenet poster
 
Posts: 2,202
Default OWA 2003 and SSL Security Vulnerability

Since OWA is a part of Exchange and not Outlook, you should probably post this "down the hall" in one of the Exchange groups.

--
Milly Staples [MVP - Outlook]

Post all replies to the group to keep the discussion intact.
How to ask a question:
http://support.microsoft.com/KB/555375


After furious head scratching, ExchangeGuy asked:

| Hello--
|
| I'm hoping you can provide some direction. We currently are running
| Exchange 2003 Enterprise with an OWA server in the DMZ. Yes.. I know
| best practices recommend routing this traffic through an ISA server.
| There is a trusted SSL certificate on the server and we have many
| mobile device users.
|
| Anyway, on a recent scan, we received the following security notice.
|
| SSLv2 Supported
| This SSL service supports SSLv2 connections. SSLv2 has known
| cryptographic weaknesses. Secure web applications should only enable
| the SSLv3 or TLSv1 protocols. For PCI compliance validation scans,
| note that either or both of the SSLv3 or TLSv1 protocols must be
| enabled (i.e., SSLv2 can not be the only supported protocol version).
|
| They provide the following resolution suggestion:
|
| Disable the use of SSL 2.0 if possible. Note that some older client
| software may not support the most recent protocol versions.
|
| Refer to the following:
|
| Microsoft Knowledge Base article to remove SSLv2 support from
| Microsoft's Internet Information Server (IIS):
| http://support.microsoft.com/kb/187498
| http://support.microsoft.com/kb/245030
|
| I've been scouring the boards trying to find out if:
|
| 1. Does OWA 2003 support SSL v3?
| 2. If I follow the suggestions and disable SSLv2, will it affect the
| users of mobile devices running Windows Mobile 5/6?
|
| I haven't been able to locate documentation regarding the supported
| versions.
|
| Any direction would be appreciated!
 




Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
outlook 2003 security Roy Outlook - Installation 3 December 10th 07 08:37 AM
Preview Pane vulnerability Stan Outlook Express 2 November 30th 07 04:28 AM
Security in Outlook 2003 Angie Outlook - Installation 0 July 30th 07 04:42 PM
Outlook 2003 (SP2) security DustWolf Outlook - General Queries 3 June 5th 06 03:41 PM
MS Security Bulletin MS06-001: Vulnerability in Graphics Rende Alphablue Outlook Express 6 January 20th 06 04:04 PM


All times are GMT +1. The time now is 03:38 AM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.Search Engine Friendly URLs by vBSEO 2.4.0
Copyright ©2004-2025 Outlook Banter.
The comments are property of their posters.