DTOO257 - Outlook - No S/Mime interoperability with external clients for message handling.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

In some situations, administrators might wish to use an external program, such as an add-in, to handle S/MIME message decryption. If your organization works with encrypted messages that the decryption functionality in Outlook 2007 cannot handle appropriately, this setting can be used to configure Outlook to hand S/MIME messages off to an external program for decryption. If no external program has been authorized, however, misconfiguring this setting could allow unauthorized and potentially dangerous programs to handle encrypted messages, which could compromise security.

Solution

The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security -> Cryptography 'S/MIME interoperability with external clients' will be set to 'Enabled (Handle internally)'.

See Also

http://iase.disa.mil/stigs/app_security/office_auto/u_microsoft_office2007_v4r9_stig_20121026.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-8(1), CAT|II, Rule-ID|SV-19010r2_rule, STIG-ID|DTOO257, Vuln-ID|V-17790

Plugin: Windows

Control ID: 0af061e446015fb6fd68edfb4e80fdf3d751a4b0aef3d88d01fb08de89901411