Had a customer come to us with an interesting question. Deep in the Outlook settings for connecting with Exchange, they found this option: (click to enlarge).

Now what was this encryption supposed to protect? What algorithm(s) are used? Who manages the keys? Why aren’t these boxes checked by default?

It seems that the Exchange 2000 Resource Kit had some of our answers.

Encrypted RPC uses a 40-bit RSA algorithm called RC4 to encrypt data while it is on the network. You can configure Outlook to use encrypted RPC so communication between clients and servers is secure and no users can tamper with messages during transit.

Exchange 2003 seems to allow you to improve on the limited security of 40-bit RC4 with unknown key management by allowing you to run RPC over HTTPS if you want. In that case, we’re at least using a common, well-tested protocol.

Bottom line is that vendors should be clear up-front about any security services being provided—technologies, algorithms, key sizes, key management, etc. The experts will always want to know these answers. If the vendor is afraid the answers won’t satisfy an expert, perhaps the vendor should reconsider the usefulness of the feature in the first place.