The GoTo Community is currently experiencing some technical issues affecting new posts and comments. We are actively working with our service provider and apologize for the frustration.
Forum Discussion
Chase Beydler1
12 years agoNew Member
TLS encryption for emails
Anyone else realize that the emails that come out of Service Desk are not being sent with any type of TLS encryption support? We just realized that all data in emails are not encrypted when they come out of the GTA mail server.
This is a dead simple thing to fix and we cannot believe that such a corporate service would not have any type of mail encryption.
Anyone have any thoughts on this?
This is a dead simple thing to fix and we cannot believe that such a corporate service would not have any type of mail encryption.
Anyone have any thoughts on this?
35 Replies
- Bcshay11 years agoActive ContributorAs we can see with all the data breaches occurring weekly security is a very serious topic. Sending sensitive information via SMTP in clear text is a huge vulnerability. A secure IT Service Desk is of high importance. Customers should not need to worry about insecure communications. Further security mechanisms to harden or lock down electronic communications would be nice too.
BTW: desk.gotoassist.com scored a C via an SSL report and is vulnerable to POODLE attacks. Citrix should be using TLS and not SSLv3 to secure communications to desk.
https://www.ssllabs.com/ssltest/analyze.html?d=desk.gotoassist.com - Chase Beydler11 years agoNew MemberPlease keep us a bit better updated on this. We were told that it was going to be completed in a matter of months when I first pointed it out to support, and it was only half implemented over a year later.
- GlennD11 years agoGoTo ManagerHi, this is planned for Q2 of this year.
- Bcshay11 years agoActive ContributorThis reply was created from a merged topic originally titled TLS connections for SMTP.
Please keep security in mind with this release. We are still waiting for the service desk to accept inbound TLS connections for SMTP.
Note: This conversation was created from a reply on: Fresh New Look Coming March 23, 2015. - Bcshay11 years agoActive ContributorAny update on this Luke? All you need to do is turn on opportunistic TLS for inbound mail.
This is still a huge security concern as un encrypted mail often contains sensitive information such as usernames and passwords. - Bcshay12 years agoActive ContributorLuke - this is fantastic news to kick off the weekend.
For those of us like Chase and I who are internal and support an organization would love it. Since we don't support external clients it would be easy for us to implement but just cost us the cost of a certificate. - Luke Grimstrup12 years agoRetired GoTo ContributorI'm following up with the ability to turn on similar secure mail delivery to our incoming mail servers. I'll keep you guys posted here.
- Chase Beydler12 years agoNew MemberThought the same thing when we first got the product. Couldn't find a way to make it work.
- Bcshay12 years agoActive ContributorSame here. I was thinking about using DNS and creating a CNAME entry for *.assist.com but the IIS site won't allow URLs to be passed through it post authentication.
Can't wait till they support SAML 2.0 for Customers. - Chase Beydler12 years agoNew MemberI would be fine with that if the links on notification emails actually took them to the portal. We use the active directory passthrough that GoToAssist "offers" and I've asked them multiple times when we'll be able to modify the notification emails because of it. If someone clicks on the link to view their ticket in the email, they just get a login screen asking for a username and password that they haven't actually been set up with.