We have been seeing some strange TLS errors for messages going to domains with MX Records in the *.iphmx.com domain recently. Whois says it belongs to "Cloud Email Security - Cisco Systems" so it would appear to be part of the Ironport Cloud Service. Some of the partner domains I ran tlsverify against came back with this:
Certificate verification failed: self signed certificate in certificate chain.
I decided to try and help out so I sent a note to the ARIN contacts for the IP network and then I got this in response:
Delivery is delayed to these recipients or distribution lists:
Not saying this is the answer, but when Cisco provision a cloud email security system for a customer they provide self signed certs for all SSL/TLS protected transactions including TLS. One of the actions the customer has to perform is to replace those self signed certs with CA signed certs (if they wish). It may be that the domains you are looking at are trials or POCs and they haven't got round to providing signed certs, or they may have decided not to have CA signed TLS certs. It is perfectly valid to use self-signed certs, with the risk that if the "other end" requires signed certs then emails will be bounced or sent over unencrypted channels, according to policy.
What is SecureX?
Cisco SecureX is included with all Secure Endpoint (formerly AMP for Endpoints) subscriptions. SecureX is a cloud-native platform that aggregates capabilities across your security environment. It’s designed to simplify your environment, ...
Cisco ISE Secure Wired Access Prescriptive Deployment Guide
Authors: Hariprasad Holla (until June 2018), Mahesh Nagireddy (until Dec 2018)
For an offline or printed copy of this document, simply choose ⋮ Options > Printer ...
Meet the Authors Slides- SecureX and the Evolution of Security Orchestration Automation and Response
(Live event – Wednesday, 20th, 2021 at 10:00 a.m. Pacific / 1:00 p.m. Eastern / 6:00 p.m. Paris)
This event had place on Wednesday 20th, January 202...
The following guide goes over the in and out of the Cisco Endpoints Security Analytics Dashboard as an overview and faq page
For more information on the product offering, licensing, support, and how to solution (TAC) guide links and more please visit the...
Join us live on Tuesday, January 19 at 10:00 am PT (and on demand after) as we discuss the latest version of ATT&CK and the expansion of TTPs in v8.
As a security expert, you are tasked with protecting your environment. You see the value of...