LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-21-2015, 11:26 AM   #1
circus78
Member
 
Registered: Dec 2011
Posts: 273

Rep: Reputation: Disabled
TLS and pop3


Hi,

is it possible to configure an email client with POP3 protocol, TLS, and port 110?
Or is mandatory to use port 995 if TLS is configured?
Thank you!
 
Old 03-21-2015, 12:09 PM   #2
T3RM1NVT0R
Senior Member
 
Registered: Dec 2010
Location: Internet
Distribution: Linux Mint, SLES, CentOS, Red Hat
Posts: 2,385

Rep: Reputation: 477Reputation: 477Reputation: 477Reputation: 477Reputation: 477
Basically when you use port 995 it is SSL and TLS not just SSL. So to answer your question no you cannot configure POP3 with TLS using port 110.
 
Old 03-21-2015, 01:06 PM   #3
circus78
Member
 
Registered: Dec 2011
Posts: 273

Original Poster
Rep: Reputation: Disabled
Hi, thank you for your reply.
Instead is it possible to use STARTTLS and port 110, right?
Which is more secure?
I think that starttls is just a little insecure only for the very first part of transaction. After the negotiation, the encryption level is the same of ssl.
Please tell me if I am wrong.
Thank you again
 
Old 03-21-2015, 01:26 PM   #4
T3RM1NVT0R
Senior Member
 
Registered: Dec 2010
Location: Internet
Distribution: Linux Mint, SLES, CentOS, Red Hat
Posts: 2,385

Rep: Reputation: 477Reputation: 477Reputation: 477Reputation: 477Reputation: 477
Yes that is possible basically it provides you security on the same port other than using a different port for secure communication. However, why you want to do that, I mean what is the compelling reason behind not using secure port. I mean you can use STARTTLS + Secure port for better security.

STARTTLS handshake process is what I think is done on non-secured channel once that is done it is on TLS. That is my understanding.

My personal preference would be to go with STARTTLS + Secure port rather than doing with STARTTLS - Secure port.
 
Old 03-22-2015, 08:15 AM   #5
circus78
Member
 
Registered: Dec 2011
Posts: 273

Original Poster
Rep: Reputation: Disabled
Hi T3rm1nvt0r,

I definitely agree with you.
I just asked to better understand the difference.
Thank you so much!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
why do some mail servers send me email w/TLS and others not,even though i enable TLS? psycroptic Linux - Server 10 10-01-2013 03:20 PM
openvpn error: TLS Error: TLS key negotiation failed to occur within 60 seconds pendrive Linux - Networking 1 11-02-2011 08:39 AM
Why does TLS port accespt both TLS and plain TCP? kenneho Linux - Server 4 02-08-2009 07:30 AM
errno: TLS definition in /lib64/libc.so.6 section .tbss mismatches non-TLS reference johnpaulodonnell Programming 2 07-25-2008 04:37 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:39 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration