> If set to "TLS to Proxy" and both peers (client and server) supports  
> TLS, both connection will be moved in to a transparent Proxy mode.  
> All data will be encrypted and unreadable to ASSP.

I had understood this to be between my client's computers (client) and  
my server (server), and, given the nature of the function, I had  
pretty much assumed that it would only work for authenticated clients.  
Given the wording, I had not anticipated that TLS would happen between  
an outside SMTP server and my server for incoming mail destined for my  
clients. This is where this problem is occurring for in this case:  
incoming SMTP, not outgoing SMTP for messages from my clients.

> I did not know, that you were using the transparent mode.

I had to do this because, during testing of TLS with Thomas, I  
discovered that Do TLS does not work properly with all mail clients.  
These clients can use TLS by Proxy successfully, but this kills assp's  
ability to investigate the outgoing mail for whitelisting. So, I'm  
damned if I do, and damned if I don't. I'm beginning to suspect that  
the only solution to the problem with Do TLS is to have those problem  
clients switch off SSL while assp does Do TLS, because TLS by Proxy  
kills much of assp's useful functionality (and that aspect is not very  
obvious in the GUI's text).

If Do TLS worked for all mail clients, I'm not sure why assp needs  
"TLS by Proxy," since it turns off payload inspection for incoming  
mail, and, by doing the same for outgoing mail, it prevents assp  
functions like whitelisting. I'm also not sure why incoming mail is  
ever allowed to be processed using TLS by Proxy, since Do TLS ensures  
that incoming payloads are inspected but TLS by Proxy prevents that.  
For outgoing mail, I feel the same way, since using TLS by Proxy  
prevents useful features of assp, like whitelisting, from working.

T.

------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
trial. Simplify your report design, integration and deployment - and focus on 
what you do best, core application coding. Discover what's new with 
Crystal Reports now.  http://p.sf.net/sfu/bobj-july
_______________________________________________
Assp-test mailing list
Assp-test@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/assp-test

Reply via email to