Answered by:
SMTP Log show TLS 1.2 while no change was done to enable TLS 1.2???

Question
-
Hello,
I was just researching to find out how to upgrade my Exchange 2010 SP3 server to TLS 1.2 but I found out from the SMTP log that I can already be running it!
I am simply baffled!
Can someone please help me?
1) I found this in the SMTP Send and Receive Log.
2) The SChannel Registry Entries
3) .NET Framework 3.5
Friday, May 15, 2020 6:30 AM
Answers
-
Thanks Joyce for your response.
After going through the SEND and RECEIVE log in detail, I finally figured out something.
The installation of Exchange 2010 comes with 2x self-signed certificates.
One of them is used for Web Management and another one is for communication with other fellow Exchange Servers.The TLS 1.2 communications I saw are between fellow Exchange Servers like between Edge and CAS servers.
I also saw TLS 1.2 communicatons between my Edge Server and mail.protection.outlook.comSo, definitely TLS 1.2 is running even though I did not make any change.
- Proposed as answer by Joyce_ShenMicrosoft contingent staff Thursday, May 21, 2020 9:18 AM
- Marked as answer by Blue Tongue Saturday, June 6, 2020 12:55 PM
Tuesday, May 19, 2020 6:24 AM
All replies
-
Hi,
According to your information above, the value of "Enabled" seems not setting correctly. The value should be 1
Did you set the value before? You may have edited it already.
The default value should be like the below
For more information: EXCHANGE 2010 AND TLS 1.2
Please Note: Since the web site is not hosted by Microsoft, the link may change without notice. Microsoft does not guarantee the accuracy of this information.
Regards,
Joyce Shen
Please remember to mark the replies as answers if they helped. If you have feedback for TechNet Subscriber Support, contact tnsf@microsoft.com.
Monday, May 18, 2020 2:32 AM -
Thanks Joyce for your response.
After going through the SEND and RECEIVE log in detail, I finally figured out something.
The installation of Exchange 2010 comes with 2x self-signed certificates.
One of them is used for Web Management and another one is for communication with other fellow Exchange Servers.The TLS 1.2 communications I saw are between fellow Exchange Servers like between Edge and CAS servers.
I also saw TLS 1.2 communicatons between my Edge Server and mail.protection.outlook.comSo, definitely TLS 1.2 is running even though I did not make any change.
- Proposed as answer by Joyce_ShenMicrosoft contingent staff Thursday, May 21, 2020 9:18 AM
- Marked as answer by Blue Tongue Saturday, June 6, 2020 12:55 PM
Tuesday, May 19, 2020 6:24 AM -
Hi,
Thanks for sharing the information above, you could mark the reply above as answer.
We could also refer to the official document to learn more about TLS/SSL Settings
Regards,
Joyce Shen
Please remember to mark the replies as answers if they helped. If you have feedback for TechNet Subscriber Support, contact tnsf@microsoft.com.
Friday, May 22, 2020 8:36 AM