Is starttls+smtp the same with SMTP over SSL?
Asked Answered
D

1

0

I'm going to generate and send password to user's mail. Of course, I want to do it safely.

Googling showed me that I can simply use smtps but system administrator told me that our post server doesn't support SSL. He said I should use pop3 and it uses SSL.

I know nothing about post protocols and have some questions:

1) Is it possible to send messages with POP3? I read that it's only for recieving messages.
2) As I understand after looking through java-mail code examples there is 2 ways of using safe smtp:
a) mail.ssl.enabled=true
b) mail.smtp.starttls.enable=true

Quote from documentation

In addition, the "imap" and "smtp" protocols support use of the STARTTLS command (see RFC 2487 and RFC 3501) to switch the connection to be secured by TLS.

Use of the STARTTLS command is preferred in cases where the server supports both SSL and non-SSL connections. - See more at: http://javamail.java.net/docs/SSLNOTES.txt#sthash.vcrMDaqh.dpuf

Does it mean I can use smtp with starttls=true even if post server doesn't support SSL?

I personally think that any modern post server supports SSL. It seems I misunderstood sysadmin. Unfortunately, I can't ask him right now due to some reasons.

I would be very grateful if somebody could clear up the situation.

Duty answered 19/8, 2013 at 10:14 Comment(0)
P
1

Is starttls+smtp the same with SMTP over SSL?

Any protocol that uses STARTTLS is in SSL mode after the STARTTLS command is issued.

Googling showed me that I can simply use smtps but system administrator told me that our post server doesn't support SSL. He said I should use pop3 and it uses SSL.

If that's what your system administrator really said, he doesn't know what he is talking about. SMTP is for sending email. POP3 is for receiving it. They are not equivalent or interchangeable in any way shape or form. POP3 does not use SSL by default, although like SMTP it can.

Does it mean I can use smtp with starttls=true even if post server doesn't support SSL?

Of course not.

It seems I misunderstood sysadmin.

No, it seems he misunderstood you, or the problem, or email infrastructure, or all three.

Unfortunately, I can't ask him right now due to some reasons.

Probably a good thing.

Pfeiffer answered 19/8, 2013 at 10:30 Comment(2)
So, should I understand it as "If our post server really doesn't support SSL there is no way to send passwords safely?" Anyway, you really made things clear, so just get your 25 points))Duty
If your SMTP server doesn't understand either SSL or STARTTLS it is almost certainly misconfigured or mis-installed. More likely, you are being misinformed.Pfeiffer

© 2022 - 2024 — McMap. All rights reserved.