RE: TLS anyone?

"Marco Laurenzano" <[email protected]> Wed, 15 Dec 2004 12:57:54 -0500
Newsgroups gmane.mail.zoe.general
Message-ID <[email protected]>
Hi, 

> > I'm generically interested in this practice.
> 
> Ok. Playing devil's advocate: what would be the rational of 
> "securing" 
> email's "last mile" when the entire email path is insecure in 
> its very nature?

Ok, my statement was a little too strong. I'm not really a security freak.
I use Zoe running on a server connected to the internet through a wired
connection
collecting email every once in a while and sometime I need
from the outside to search for something, that's all. So securing just the
last mile 
satisfies my security paranoid ego :)

> Also, how do you manage your keys? Do you use self-signed 
> certificates for the sole purpose of encrypting connections? 
> Or are you interested in authenticating the host you are 
> connecting to as well?

I just use self-signed keys, as you said, just for encryption.
If the IP changes I get a warning, that's enough for me.
If they spoof the IP... well, good for them: such an effort for my emails...
I'm flattered.

> > If it's useful to anybody, I already have such a 
> functionality on my 
> > Zoe setup (on windows server) using delegate.
> 
> Cool. Does anyone else tunnel their connection over a secure 
> link of some sort? VPN? SSH? Care to share you experiences in 
> setting up such environment?

If anybody is interested in the details I can send the configuration line I
use for delegate
and the conf file I use for stunnel.

> > The difference is that, with delegate, you can create 
> several virtual 
> > paths like:
> > https://www.myserver.com/zoe
> > https://www.myserver.com/spambayes
> > etc...
> > with the advantage that the firewall then can expose only 
> delegate to 
> > the internet (which is kinda meant for that).
> >
> > I usually use different clients and I like the idea of 
> having all my 
> > emails all in one place. Using stunnel I also secured the 
> SMTP relay 
> > provided by Zoe so, whatever client I'm using, I can relay emails 
> > through Zoe (and have them archived) or search for something (via
> > delegate) everything in a secured fashion.
> 
> Well, at least one link is secure :)

My only purpose is to protect myself from the "occasional" hacker.
The typical scenario I'm more concerned of is doing some email works on
a public WiFi access point or something like that. I believe that these
networks are just too exposed to
people who just want to have some fun. I'm just concerned that I would end
up sharing
the fun with them.

By the way, I didn't get the chance to tell you how Zoe is great. 
I have 7 years of emails and counting and it works just fine. 
I have always been concerned about changing email client because I didn't
want to lose my mailbox
and, by separating the client part for the archiving one has been THE
solution. 
So, thank you.

Bye,
Marco.





-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now. 
http://productguide.itmanagersjournal.com/