This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

TLS 1.2 Mandatory setzen

Hallo zusammen,

 

die neue Europäische Datenschutzverordnung stellt uns gerade vor die Herausforderung unseren gesamten Emailverkehr nach aussen mittels TLS 1.2 zu verschlüsseln. Also den Übertragungskanal. Für uns stellt sich nun die Frage ob wir diese Verbindung mittels der Sophos UTM realisiert bekommen. In unserem Falle sollen alle Übertragungen, die nicht mittels TLS 1.2 gesichert werden können, blockiert werden. Ich weiß das es andere Compliances gibt die dies unterstützen. Daher nehme ich an das die Sophos das auch kann. Jedoch muss ich hier wissen wie man das eingestellt bekommt und was passiert wenn die Übertragung nicht statt findet. 

Wir nutzen derzeit die UTM in der Version: 9.506-2

 



This thread was automatically locked due to age.
Parents Reply
  • To show compliance with a mandate like this, you really need two things:  (1) a setting to cause the desired behavior in the future, and (2) log data to prove that the setting was in effect at any point in time that might be of interest to an auditor or lawyer.    Fortunately, the SMTP log shows the inbound and outbound cipher settings, if you hunt for it.   

    If you can effectively parse the SMTP logs into a database structure, you can respond to audit questions at any level of complexity.   (Look for X=... in the logs to see the way cipher information is represented.)   Also see my post from earlier today for an annotated example of the log data.

    https://community.sophos.com/products/unified-threat-management/f/management-networking-logging-and-reporting/103336/understanding-the-smtp-logs

    If Sophos is really going to help its UTM customer base with GDPR, they really need to make IView into a database tool for querying the logs, rather than leaving it in its present state as a tool for generating beautiful summary reports.   I would be reluctant to give a summary report to a manager unless I knew how to generate the supporting detail, and when I last looked at IView, it could not provide those details.

Children
No Data