Firewall Wizards mailing list archives

Re: POP3 Security Issues


From: Christopher Nielsen <enkhyl () scient com>
Date: Tue, 1 Dec 1998 16:50:03 -0800 (PST)

On Mon, 30 Nov 1998, Rodney van den Oever wrote:

Speaking of pop3 over SSL, is anyone aware of mail clients or pop3
retrievers (Unix and/or Windows) that support it? The reason I'm asking
is that i've recently plugged SSL into qpopper (2.53), and want to know
whether I need to patch something like fetchmail, or whether there's
something out there already that will do the job.

o Microsoft Exchange Server 5.0/5.5
o Microsoft Outlook Express client

That would be fine if Microsoft had implemented SSL correctly. I've had
nothing but trouble getting our Exchange server to interoperate with
anything other than Outlook Express and Netscape's IMAP client without
coding around the bugs in Microsoft's implementation. The bug seems to be
in the handshake sequence. There's another bug that will cause all
incoming SSL connections to hang. This seems to happen randomly and we've
been unable to determine under what conditions trigger the bug. Without
source it's difficult to find the bug.

-- 
Christopher Nielsen
Scient: The eBusiness Systems Innovator
<http://www.scient.com>
cnielsen () scient com



Current thread: