Conclusion

Some points on messaging server software security:

  1. Require SMTP AUTH for mail submission and turn on appropriate logging, so abuse can be traced.

  2. Set ACIs in the directory appropriately for your environment.

  3. Enable SSL for LDAP, IMAP, POP, and web mail to provide secure transmission.

  4. Configure and support PGP/digital signatures if non-repudiation and sender validation are required.

  5. Configure and support SMIME or encrypted messages if absolute privacy required.

  6. Keep in mind that each layer of security at this level adds administrative and support overhead.

Get Sun™ ONE Messaging Server: Practices and Techniques for Enterprise Customers now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.