[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: I'm very interested in any info. you have to give.



David L. Nicol wrote:
> nels weber wrote:
> > 

<snip>

> There is not at this time a standard for encrypting the entire channel
> between mail servers, and it is unlikely that one will appear.  When
> there is risk of people reading the traffic that goes by, a better
> solution is to encrypt the entire network into a "virtual private
> network."

Well, there is an Internet draft at the moment, and there are products emerging which support domain to domain-based encryption and signing. Check out http://www.ietf.org/internet-drafts/draft-ietf-smime-domsec-03.txt
for more details on the technical side of things.

When the only thing that you actually want to encrypt is email, using a VPN is sort of like duck hunting with a bazooka. You also lose encryption coverage to remote clients who don't want/have VPNs, but have mail encryption tools handy.

--
Michael

Michael Owen
IT Security Engineer
NET-TEL Computer Systems Ltd
Michael.Owen@net-tel.co.uk

-
Securedistros: A common list for all secured Linux distributions
Archive:       http://humbolt.nl.linux.org/lists/