<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;Changes coming for SSL certs- Exchange issue&#x27; in forum &#x27;No, I Will Not Fix Your #@$!! Computer&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/Changes-coming-for-SSL-certs-Exchange-issue-27970168</link>
<description></description>
<language>en</language>
<pubDate>Thu, 23 May 2013 04:43:08 EDT</pubDate>
<lastBuildDate>Thu, 23 May 2013 04:43:08 EDT</lastBuildDate>

<item>
<title>Re: Changes coming for SSL certs- Exchange issue</title>
<link>http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28157644</link>
<description><![CDATA[DarkLogix posted : You could also add in some of the e-mail security that yahoo, ebay, and good have.<br><br>I don't remember the name of the tech but it basically stores a public key in DNS and uses a private key to sign all outgoing e-mail.<br><br>then any e-mail claimed to be from the given domain (ie google, yahoo, or ebay) can be verified by checking with the key in the DNS record.<br><br>Combine that with SRP and you can be sure that no one will be able to spoof you.<br><small>--<br>&raquo;<A HREF="http://www.change.org/petitions/create-a-100-offline-single-player-mode-in-simcity-2013-remove-the-origin-requirement-from-it-and-bring-back-popular-features-from-simcity-4" >www.change.org/petitions/create-&middot;&middot;&middot;imcity-4</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28157644</guid>
<pubDate>Mon, 01 Apr 2013 10:00:57 EDT</pubDate>
</item>

<item>
<title>Re: Changes coming for SSL certs- Exchange issue</title>
<link>http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28157429</link>
<description><![CDATA[ke4pym posted : <div class="bquote"><said>said by <a href="/profile/961620" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=961620');">IamGimli</a>:</said><p><div class="bquote"><said>said by <a href="/profile/1046768" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1046768');">ke4pym</a>:</said><p>You apparently haven't been keeping up on all the rage in IT these days that is BYOD.<br> </p></div>...and you apparently haven't been keeping up with the security risks that represents, which are much greater than unencrypted email on a closed network.<br><br>You do realize that all those emails are going out to the destination on the Internet unencrypted, right?<br> </p></div>Being that I work for a healthcare facility, I am *KEEEEEEENLY* aware of the security risks.  However, this isn't something that's my call.  BYOD and the consumerization of IT is an industry thing that is impacting all IT departments now, and one my employer is embracing.<br><br>There are plenty of technologies out there (some of which we deploy) that will mitigate most, if not all of the risks of a BYOD on a corporate network.  Personal responsibility and liability set by laws/rules such as HIPAA are also pretty good deterrents that help fill in the gaps.<br><br>As for "all those emails" - they're not necessarily going out to the internet unencrypted.  We have a system that intercepts emails and if it finds certain information, it will divert that email from an unencrypted state to our protected email system which uses SSL.  It also isn't shy about grabbing to many emails rather than not enough.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28157429</guid>
<pubDate>Mon, 01 Apr 2013 08:21:49 EDT</pubDate>
</item>

<item>
<title>Re: Changes coming for SSL certs- Exchange issue</title>
<link>http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28156256</link>
<description><![CDATA[IamGimli posted : <div class="bquote"><said>said by <a href="/profile/1046768" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1046768');">ke4pym</a>:</said><p>You apparently haven't been keeping up on all the rage in IT these days that is BYOD.<br> </p></div>...and you apparently haven't been keeping up with the security risks that represents, which are much greater than unencrypted email on a closed network.<br><br>You do realize that all those emails are going out to the destination on the Internet unencrypted, right?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28156256</guid>
<pubDate>Sun, 31 Mar 2013 18:25:25 EDT</pubDate>
</item>

<item>
<title>Re: Changes coming for SSL certs- Exchange issue</title>
<link>http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28155398</link>
<description><![CDATA[ke4pym posted : <div class="bquote"><said>said by <a href="/profile/961620" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=961620');">IamGimli</a>:</said><p><div class="bquote"><said>said by <a href="/profile/1046768" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1046768');">ke4pym</a>:</said><p><div class="bquote"><said>said by <a href="/profile/789469" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=789469');">exocet_cm</a>:</said><p>Self-signed SSL certificates FTW. Lame IMO but hey, I don't make the rules. <br> </p></div>Sure, doing this or setting up your own internal CA is all fun and games until someone brings in their own device.  Then who's the poor soul that has to load the root cert on their device?  And keep up with updating it after it expires (short of making it a 100 year cert).<br> </p></div>If you let people plug in their own devices to your network you might as well not use certificates at all. <br> </p></div>You apparently haven't been keeping up on all the rage in IT these days that is BYOD.<br><br>And regardless of who's using your network, you better be encrypting the sensitive data.  And while you're at it, you better make sure you're configuring your server's SSL settings correctly.<br><br>Using ".local" as a name is a foreign concept to me.  Our internal name matches our external name.  So, it's no big thing for us to just get a wildcard cert and be done with it (aside from tracking where that cert has been installed).]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28155398</guid>
<pubDate>Sun, 31 Mar 2013 10:48:30 EDT</pubDate>
</item>

<item>
<title>Re: Changes coming for SSL certs- Exchange issue</title>
<link>http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28150916</link>
<description><![CDATA[demir posted : Setting up a CA isn't a big deal, even for a single person, let alone a company.  You could do it in 5 minutes and start generating your own certs, whether you are a single person, small, medium or large company.<br><br>If you've never gone through the exercise or thought about managing your own certificates, maybe it's a good time to start.<br><br>&raquo;<A HREF="http://www.freebsdmadeeasy.com/tutorials/freebsd/create-a-ca-with-openssl.php" >www.freebsdmadeeasy.com/tutorial&middot;&middot;&middot;nssl.php</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28150916</guid>
<pubDate>Fri, 29 Mar 2013 13:03:24 EDT</pubDate>
</item>

<item>
<title>Re: Changes coming for SSL certs- Exchange issue</title>
<link>http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28149253</link>
<description><![CDATA[lorennerol posted : <div class="bquote"><said>said by <a href="/profile/1744464" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1744464');">demir</a>:</said><p><div class="bquote"><said>said by <a href="/profile/961620" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=961620');">IamGimli</a>:</said><p>Setup your own internal CA for your internal requirements. Pretty simple and a lot less expensive than paying a third party for all your internal certificate needs.<br> </p></div>This.<br> </p></div>Once company with an IT department and 20 sites, yes, this is simpler.<br><br>One IT consultant with 50 clients, 50 email servers, etc. This is NOT easier, or more cost effective.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28149253</guid>
<pubDate>Thu, 28 Mar 2013 21:09:49 EDT</pubDate>
</item>

<item>
<title>Re: Changes coming for SSL certs- Exchange issue</title>
<link>http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28148899</link>
<description><![CDATA[demir posted : <div class="bquote"><said>said by <a href="/profile/961620" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=961620');">IamGimli</a>:</said><p>Setup your own internal CA for your internal requirements. Pretty simple and a lot less expensive than paying a third party for all your internal certificate needs.<br> </p></div>This.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28148899</guid>
<pubDate>Thu, 28 Mar 2013 19:01:38 EDT</pubDate>
</item>

<item>
<title>Re: Changes coming for SSL certs- Exchange issue</title>
<link>http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28144374</link>
<description><![CDATA[IamGimli posted : <div class="bquote"><said>said by <a href="/profile/1046768" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1046768');">ke4pym</a>:</said><p><div class="bquote"><said>said by <a href="/profile/789469" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=789469');">exocet_cm</a>:</said><p>Self-signed SSL certificates FTW. Lame IMO but hey, I don't make the rules. <br> </p></div>Sure, doing this or setting up your own internal CA is all fun and games until someone brings in their own device.  Then who's the poor soul that has to load the root cert on their device?  And keep up with updating it after it expires (short of making it a 100 year cert).<br> </p></div>If you let people plug in their own devices to your network you might as well not use certificates at all. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28144374</guid>
<pubDate>Wed, 27 Mar 2013 14:31:31 EDT</pubDate>
</item>

<item>
<title>Re: Changes coming for SSL certs- Exchange issue</title>
<link>http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28113737</link>
<description><![CDATA[DarkLogix posted : <div class="bquote"><said>said by <a href="/profile/892685" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=892685');">lorennerol</a>:</said><p><div class="bquote"><said>said by <a href="/profile/1046768" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1046768');">ke4pym</a>:</said><p><div class="bquote"><said>said by <a href="/profile/789469" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=789469');">exocet_cm</a>:</said><p>Self-signed SSL certificates FTW. Lame IMO but hey, I don't make the rules. <br> </p></div>Sure, doing this or setting up your own internal CA is all fun and games until someone brings in their own device.  Then who's the poor soul that has to load the root cert on their device?  And keep up with updating it after it expires (short of making it a 100 year cert).<br> </p></div>That. Not to mention users who want to sync their home computer to corporate email, something quite common in the SMB segment.<br><br>The easy fix would be to not sell the .local tld.<br> </p></div>Use outlook anywhere and never let that computer be on the internal network.<br><br>And ya the .local should be reserved indefinitely just like the 10.x.x.x/8 range<br><br>What we have is any public facing address gets a cert from a real CA and all internal ones get one from the internal CA.<br><br>Also with an internal CA you can set the lifetime to something very long so the CA's cert won't expire for a very long time, as well as make a self applying exe for the CA certs.<br><small>--<br>&raquo;<A HREF="http://www.change.org/petitions/create-a-100-offline-single-player-mode-in-simcity-2013-remove-the-origin-requirement-from-it-and-bring-back-popular-features-from-simcity-4" >www.change.org/petitions/create-&middot;&middot;&middot;imcity-4</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28113737</guid>
<pubDate>Mon, 18 Mar 2013 13:56:35 EDT</pubDate>
</item>

<item>
<title>Re: Changes coming for SSL certs- Exchange issue</title>
<link>http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28113730</link>
<description><![CDATA[DarkLogix posted : Well frankly why put a publicly signed cert on an internal host?<br><br>IMO do OWA.public-domain.com, and internal-server-name.domain.local<br><br>use a public cert on the public address and a internally signed cert on the internal address<br><br>then sort out the rest of the details<br><small>--<br>&raquo;<A HREF="http://www.change.org/petitions/create-a-100-offline-single-player-mode-in-simcity-2013-remove-the-origin-requirement-from-it-and-bring-back-popular-features-from-simcity-4" >www.change.org/petitions/create-&middot;&middot;&middot;imcity-4</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28113730</guid>
<pubDate>Mon, 18 Mar 2013 13:53:07 EDT</pubDate>
</item>

<item>
<title>Re: Changes coming for SSL certs- Exchange issue</title>
<link>http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28113550</link>
<description><![CDATA[lorennerol posted : <div class="bquote"><said>said by <a href="/profile/1046768" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1046768');">ke4pym</a>:</said><p><div class="bquote"><said>said by <a href="/profile/789469" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=789469');">exocet_cm</a>:</said><p>Self-signed SSL certificates FTW. Lame IMO but hey, I don't make the rules. <br> </p></div>Sure, doing this or setting up your own internal CA is all fun and games until someone brings in their own device.  Then who's the poor soul that has to load the root cert on their device?  And keep up with updating it after it expires (short of making it a 100 year cert).<br> </p></div>That. Not to mention users who want to sync their home computer to corporate email, something quite common in the SMB segment.<br><br>The easy fix would be to not sell the .local tld.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28113550</guid>
<pubDate>Mon, 18 Mar 2013 12:58:23 EDT</pubDate>
</item>

<item>
<title>Re: Changes coming for SSL certs- Exchange issue</title>
<link>http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28113509</link>
<description><![CDATA[ke4pym posted : <div class="bquote"><said>said by <a href="/profile/789469" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=789469');">exocet_cm</a>:</said><p>Self-signed SSL certificates FTW. Lame IMO but hey, I don't make the rules. <br> </p></div>Sure, doing this or setting up your own internal CA is all fun and games until someone brings in their own device.  Then who's the poor soul that has to load the root cert on their device?  And keep up with updating it after it expires (short of making it a 100 year cert).]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28113509</guid>
<pubDate>Mon, 18 Mar 2013 12:47:39 EDT</pubDate>
</item>

<item>
<title>Re: Changes coming for SSL certs- Exchange issue</title>
<link>http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28098966</link>
<description><![CDATA[IamGimli posted : Setup your own internal CA for your internal requirements. Pretty simple and a lot less expensive than paying a third party for all your internal certificate needs.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28098966</guid>
<pubDate>Wed, 13 Mar 2013 16:31:29 EDT</pubDate>
</item>

<item>
<title>Re: Changes coming for SSL certs- Exchange issue</title>
<link>http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28098710</link>
<description><![CDATA[kontos posted : This makes sense once you consider that rules on Top Level Domains have been relaxed.  In the future domain.local could get registered to a company/person that is not you.  If they were to issue a distant expiration certificate for that domain to Ira Hacker today, he could wreak havoc in a few years if that name comes into use on the public 'Net. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-28098710</guid>
<pubDate>Wed, 13 Mar 2013 15:35:13 EDT</pubDate>
</item>

<item>
<title>Re: Changes coming for SSL certs- Exchange issue</title>
<link>http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-27971726</link>
<description><![CDATA[AsherN posted : Split DNS and point Outlook to the public name.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-27971726</guid>
<pubDate>Sat, 02 Feb 2013 07:39:41 EDT</pubDate>
</item>

<item>
<title>Re: Changes coming for SSL certs- Exchange issue</title>
<link>http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-27970932</link>
<description><![CDATA[exocet_cm posted : Self-signed SSL certificates FTW. Lame IMO but hey, I don't make the rules. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-27970932</guid>
<pubDate>Fri, 01 Feb 2013 21:03:22 EDT</pubDate>
</item>

<item>
<title>Re: Changes coming for SSL certs- Exchange issue</title>
<link>http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-27970630</link>
<description><![CDATA[drew posted : <div class="bquote"><said>said by <a href="/profile/892685" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=892685');">lorennerol</a>:</said><p>Has anyone else run into this or even heard of it?<br> </p></div>Not until you mentioned this thread and I typed "ssl certificate domain name rules" into Dr. Internet<br><br>&raquo;<A HREF="http://exchangeserverpro.com/ssl-requirements-for-exchange-when-certificate-authorities-wont-issue-certificate" >exchangeserverpro.com/ssl-requir&middot;&middot;&middot;tificate</A><br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>The CA/Browser Forum, a collaborative effort between Certificate Authorities (companies like DigiCert that issue certificates) and Web Browsers (companies like Mozilla or Microsoft that manage trust on a CA level), has introduced new Baseline Requirements for certificate issuance.<br><br>As part of these new requirements, Certificate Authorities must phase out the issuance of certificates issued to either Internal Server Names or a Reserved IP Address by October 2016. Specifically, CAs cannot issue certificates to these internal names with expiration dates after November 1, 2015&#133;<br><br>Essentially, this change in SSL standards will make it impossible to obtain a publicly trusted certificate for any host name that cannot be externally verified as owned by the organization that is requesting the certificate.<HR></BLOCKQUOTE><br><small>--<br><A HREF="http://flic.kr/drew_dslr">flickr</a> | <i>'Cause I've been waiting, all my life just waiting<br>For you to shine, shine your light on me</i></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Changes-coming-for-SSL-certs-Exchange-issue-27970630</guid>
<pubDate>Fri, 01 Feb 2013 19:24:19 EDT</pubDate>
</item>

<item>
<title>Changes coming for SSL certs- Exchange issue</title>
<link>http://www.dslreports.com/forum/Changes-coming-for-SSL-certs-Exchange-issue-27970168</link>
<description><![CDATA[lorennerol posted : A cert provider we use is telling us that they cannot issue certs for host names like "Exchange" or "Exchange.domain.local" that are effective past November 2015.<br><br>Without some contortion, Outlook clients talk to Exchange using the internal host name, and it complains about a cert mismatch.<br><br>Has anyone else run into this or even heard of it?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Changes-coming-for-SSL-certs-Exchange-issue-27970168</guid>
<pubDate>Fri, 01 Feb 2013 17:03:46 EDT</pubDate>
</item>

</channel>
</rss>
