# 2 questions on encrypt mode and crl distribution

**URL:** <https://community.ciphermail.com/t/2-questions-on-encrypt-mode-and-crl-distribution/152>\
**Category:** Gateway\
**Created:** [December 20, 2010, 12:30pm UTC](https://community.ciphermail.com/t/2-questions-on-encrypt-mode-and-crl-distribution/152 "2010-12-20T12:30:42Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bernhard\_Heinzle](https://avatars.discourse-cdn.com/v4/letter/b/71e660/32.png) [@Bernhard\_Heinzle](https://community.ciphermail.com/u/Bernhard_Heinzle)\
**Post date:** [December 20, 2010, 12:30pm UTC](https://community.ciphermail.com/t/2-questions-on-encrypt-mode-and-crl-distribution/152/1 "2010-12-20T12:30:42Z")

</div>

hi,

i've got 2 questions:

issue 1:

i set up my evaluation scenario with the following values for my internal  
domain as well as gobal settings:  
encrypt mode: allow  
password - send to originator: true  
pdf encryption: true

given the case that i'm sending an email without the trigger in the subject  
line from an internal address to an external address, i'd like djigzo to:  
- encrypt the email if there is a encryption certificate availabe for the  
given external adress  
- send the email unencrypted if there is no certificate availabe  
pdf encryption shall only be used if there is the trigger in the subject  
line but no certificate available. with the settings mentioned above unkown  
external addresses receive an encryptet pdf.

in other words: how to automatically encrypt emails if there is a  
certificate available and only use pdf encryption if the trigger is used?

issue2:  
is there feature to publish crls automatically upen creation or is it  
necesarry to copy crls manually (or scripted) to the specified url  
distribution point?

many thanks in advance!

kind regards,  
bernhard

---

<div class="post-metadata">

**Author:** ![martijn](https://dub1.discourse-cdn.com/flex017/user_avatar/community.ciphermail.com/martijn/32/127_2.png) [@martijn](https://community.ciphermail.com/u/martijn)\
**Post date:** [December 20, 2010, 12:51pm UTC](https://community.ciphermail.com/t/2-questions-on-encrypt-mode-and-crl-distribution/152/2 "2010-12-20T12:51:57Z")

</div>

Hi Bernhard,

> in other words: how to automatically encrypt emails if there is a  
> certificate available and only use pdf encryption if the trigger is  
> used?

This is currently not possible 'out of the box'. It is however possible  
to manually modify an XML file containing the mail handling rules. You  
can for example add a trigger specifically for PDF encryption. I can  
send you some documentation on what to add to the config.xml file to  
trigger PDF encryption with a subject trigger.

If you want you can add a feature request to JIRA to have this option  
added to the gateway.

[https://jira.djigzo.com/secure/Dashboard.jspa](https://jira.djigzo.com/secure/Dashboard.jspa)

> is there feature to publish crls automatically upen creation or is it  
> necesarry to copy crls manually (or scripted) to the specified url  
> distribution point?

Currently the new CRL is not published automatically. The reason for  
this is that the procedure for publishing the CRL is completely  
different for every client. I could add a publish API that allows you to  
write modify a Bash script which will be executed when a new CRL is  
available.

Kind regards,

Martijn

> **···**
>
> On 12/20/2010 01:30 PM, Bernhard Heinzle wrote:
> 
> > hi,
> > 
> > i've got 2 questions:
> > 
> > issue 1:
> > 
> > i set up my evaluation scenario with the following values for my internal  
> > domain as well as gobal settings:  
> > encrypt mode: allow  
> > password - send to originator: true  
> > pdf encryption: true
> > 
> > given the case that i'm sending an email without the trigger in the subject  
> > line from an internal address to an external address, i'd like djigzo to:  
> > - encrypt the email if there is a encryption certificate availabe for the  
> > given external adress  
> > - send the email unencrypted if there is no certificate availabe  
> > pdf encryption shall only be used if there is the trigger in the subject  
> > line but no certificate available. with the settings mentioned above unkown  
> > external addresses receive an encryptet pdf.
> > 
> > in other words: how to automatically encrypt emails if there is a  
> > certificate available and only use pdf encryption if the trigger is used?
> > 
> > issue2:  
> > is there feature to publish crls automatically upen creation or is it  
> > necesarry to copy crls manually (or scripted) to the specified url  
> > distribution point?
> > 
> > many thanks in advance!
> > 
> > kind regards,  
> > bernhard
> > 
> > \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_  
> > Users mailing list  
> > Users(a)lists.djigzo.com  
> > [http://lists.djigzo.com/lists/listinfo/users](http://lists.djigzo.com/lists/listinfo/users)
> 
> --  
> Djigzo open source email encryption

---

<div class="post-metadata">

**Author:** ![Bernhard\_Heinzle](https://avatars.discourse-cdn.com/v4/letter/b/71e660/32.png) [@Bernhard\_Heinzle](https://community.ciphermail.com/u/Bernhard_Heinzle)\
**Post date:** [January 7, 2011, 11:34am UTC](https://community.ciphermail.com/t/2-questions-on-encrypt-mode-and-crl-distribution/152/3 "2011-01-07T11:34:43Z")

</div>

Hi Martin,

many thanks for your advice.

> This is currently not possible 'out of the box'. It is however possible  
> to manually modify an XML file containing the mail handling rules. You  
> can for example add a trigger specifically for PDF encryption. I can  
> send you some documentation on what to add to the config.xml file to  
> trigger PDF encryption with a subject trigger.

i'd appreciate it if you could send me this documentation

i've got a further question about encryption mode:  
is there a way to automatically reject incoming unencrypted email, so  
that only encrypted emails are processed and forwarded?

kind regards,  
bernhard

---

<div class="post-metadata">

**Author:** ![martijn](https://dub1.discourse-cdn.com/flex017/user_avatar/community.ciphermail.com/martijn/32/127_2.png) [@martijn](https://community.ciphermail.com/u/martijn)\
**Post date:** [January 11, 2011, 11:18am UTC](https://community.ciphermail.com/t/2-questions-on-encrypt-mode-and-crl-distribution/152/4 "2011-01-11T11:18:32Z")

</div>

Hi Bernhard,

> > This is currently not possible 'out of the box'. It is however  
> > possible to manually modify an XML file containing the mail  
> > handling rules. You can for example add a trigger specifically for  
> > PDF encryption. I can send you some documentation on what to add to  
> > the config.xml file to trigger PDF encryption with a subject  
> > trigger.
> 
> i'd appreciate it if you could send me this documentation

By adding the following lines to the configuration file  
/usr/share/djigzo/conf/james/SAR-INF/config.xml PDF encryption will be  
skipped if the subject trigger is not specified:

\<mailet  
match="MailAttributeEvaluator=matchOnError=false,#{runtime.mustEncrypt}!='true'"  
class="GotoProcessor"\>  
&nbsp;&nbsp;&nbsp;&nbsp;\<processor\> checkMustEncrypt \</processor\>  
\</mailet\>

The above lines should be added at the start of the checkPDFEncrypt  
processor:

\<processor name="checkPDFEncrypt"\>  
&nbsp;&nbsp;&nbsp;&nbsp;\<mailet match="All" class="Log"\>  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\<comment\> checkPDFEncrypt \</comment\>  
&nbsp;&nbsp;&nbsp;&nbsp;\</mailet\>

&nbsp;&nbsp;&nbsp;&nbsp;\<!-- only PDF encrypt when the subject trigger is set --\>

&nbsp;&nbsp;&nbsp;&nbsp;\<mailet  
match="MailAttributeEvaluator=matchOnError=false,#{runtime.mustEncrypt}!='true'"  
class="GotoProcessor"\>  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\<processor\> checkMustEncrypt \</processor\>  
&nbsp;&nbsp;&nbsp;&nbsp;\</mailet\>

&nbsp;&nbsp;&nbsp;&nbsp;\<mailet  
match="SenderEvaluateUserProperty=matchOnError=true,#{user.pdf.encryptionAllowed}!='true'"  
class="GotoProcessor"\>  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\<log\> Sender PDF encryption is not allowed \</log\>  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\<processor\> checkMustEncrypt \</processor\>  
&nbsp;&nbsp;&nbsp;&nbsp;\</mailet\>

I have attached the complete config.xml with these changes. You can  
replace the existing config.xml with this new version if you are using  
Djigzo version 1.4.0 or 1.4.1 (make sure you create a copy of the  
existing config.xml).

What the easiest way would be to copy the new config.xml to Djigzo  
depends on your client system. If using Linux you can use SSH or use vi  
to change the config.xml file yourself. If using Windows, the easiest  
would be to install WinSCP ([WinSCP :: Official Site :: Free SFTP and FTP client for Windows](http://winscp.net/eng/index.php)).

> i've got a further question about encryption mode:  
> is there a way to automatically reject incoming unencrypted email, so  
> that only encrypted emails are processed and forwarded?

That depends what you mean with reject. The Djigzo encryption engine  
functions as an after-queue filter. That means that the message is  
already accepted by the MTA before the encryption engine handles the  
email. The message can therefore not be rejected before accepting. The  
message can only be 'bounced' back (i.e., a message that reports that  
the message was not encrypted).

Kind regards,

Martijn

[config.xml](https://community.ciphermail.com/uploads/short-url/nFiwSMyjiU61hLglsMpivlsrWSt.xml) (79.6 KB)

> **···**
>
> On 01/07/2011 12:34 PM, Bernhard Heinzle wrote:
> 
> > Hi Martin,
> > 
> > many thanks for your advice.
> > 
> > > This is currently not possible 'out of the box'. It is however possible  
> > > to manually modify an XML file containing the mail handling rules. You  
> > > can for example add a trigger specifically for PDF encryption. I can  
> > > send you some documentation on what to add to the config.xml file to  
> > > trigger PDF encryption with a subject trigger.
> > 
> > i'd appreciate it if you could send me this documentation
> > 
> > i've got a further question about encryption mode:  
> > is there a way to automatically reject incoming unencrypted email, so  
> > that only encrypted emails are processed and forwarded?
> > 
> > kind regards,  
> > bernhard  
> > \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_  
> > Users mailing list  
> > Users(a)lists.djigzo.com  
> > [http://lists.djigzo.com/lists/listinfo/users](http://lists.djigzo.com/lists/listinfo/users)
> 
> --  
> Djigzo open source email encryption

---

<div class="post-metadata">

**Author:** ![Bernhard\_Heinzle](https://avatars.discourse-cdn.com/v4/letter/b/71e660/32.png) [@Bernhard\_Heinzle](https://community.ciphermail.com/u/Bernhard_Heinzle)\
**Post date:** [January 12, 2011, 2:07pm UTC](https://community.ciphermail.com/t/2-questions-on-encrypt-mode-and-crl-distribution/152/5 "2011-01-12T14:07:48Z")

</div>

Hi Martijn,

> I have attached the complete config.xml with these changes. You can  
> replace the existing config.xml with this new version if you are using  
> Djigzo version 1.4.0 or 1.4.1 (make sure you create a copy of the  
> existing config.xml).

Many thanks for your great support!  
This makes your nice gateway even better! 😉

> > i've got a further question about encryption mode:  
> > is there a way to automatically reject incoming unencrypted email, so  
> > that only encrypted emails are processed and forwarded?
> 
> That depends what you mean with reject. The Djigzo encryption engine  
> functions as an after-queue filter. That means that the message is  
> already accepted by the MTA before the encryption engine handles the  
> email. The message can therefore not be rejected before accepting. The  
> message can only be 'bounced' back (i.e., a message that reports that  
> the message was not encrypted).

i'm sorry for not using the right terms. i'd like djigzo to bounce the  
message and notifiy the sender that emails must be encryptet for the  
specific recipient.

kind regard,  
bernhard

> **···**
>
> Am 11.01.2011 12:18, schrieb Martijn Brinkers:

---

<div class="post-metadata">

**Author:** ![martijn](https://dub1.discourse-cdn.com/flex017/user_avatar/community.ciphermail.com/martijn/32/127_2.png) [@martijn](https://community.ciphermail.com/u/martijn)\
**Post date:** [January 12, 2011, 4:04pm UTC](https://community.ciphermail.com/t/2-questions-on-encrypt-mode-and-crl-distribution/152/6 "2011-01-12T16:04:30Z")

</div>

> i'm sorry for not using the right terms. i'd like djigzo to bounce the  
> message and notifiy the sender that emails must be encryptet for the  
> specific recipient.

Do you want this for all incoming messages? You can add a matcher that  
detects whether the message is encrypted and if not send a notification  
back to the sender. If you really want this, you must be sure that you  
block 99.99% of all incoming spam otherwise you will be sending  
notifications to 'fake' users.

Kind regards,

Martijn

> **···**
>
> --  
> Djigzo open source email encryption

---

<div class="post-metadata">

**Author:** ![lst\_hoe021](https://avatars.discourse-cdn.com/v4/letter/l/58956e/32.png) [@lst\_hoe021](https://community.ciphermail.com/u/lst_hoe021)\
**Post date:** [January 12, 2011, 4:13pm UTC](https://community.ciphermail.com/t/2-questions-on-encrypt-mode-and-crl-distribution/152/7 "2011-01-12T16:13:03Z")

</div>

Zitat von Martijn Brinkers \<martijn(a)djigzo.com\>:

> > i'm sorry for not using the right terms. i'd like djigzo to bounce the  
> > message and notifiy the sender that emails must be encryptet for the  
> > specific recipient.
> 
> Do you want this for all incoming messages? You can add a matcher that  
> detects whether the message is encrypted and if not send a notification  
> back to the sender. If you really want this, you must be sure that you  
> block 99.99% of all incoming spam otherwise you will be sending  
> notifications to 'fake' users.

This discussion came up on an other list some time ago. It is useless  
to try to enforce encryption at the \*receiving\* side. If you bounce  
the (unencrypted) message, it travels the net two times in clear  
instead only once. Force encryption is the job of a Gateway at  
\*sender\* side, so convice the remote site to use Djigzo would be a  
solution....

Regards

Andreas

---

<div class="post-metadata">

**Author:** ![Bernhard\_Heinzle](https://avatars.discourse-cdn.com/v4/letter/b/71e660/32.png) [@Bernhard\_Heinzle](https://community.ciphermail.com/u/Bernhard_Heinzle)\
**Post date:** [January 12, 2011, 4:22pm UTC](https://community.ciphermail.com/t/2-questions-on-encrypt-mode-and-crl-distribution/152/8 "2011-01-12T16:22:34Z")

</div>

true words, didn't think about that.

> **···**
>
> Am 12.01.2011 17:13, schrieb lst\_hoe02(a)kwsoft.de:
> 
> > Zitat von Martijn Brinkers \<martijn(a)djigzo.com\>:
> > 
> > > Do you want this for all incoming messages? You can add a matcher that  
> > > detects whether the message is encrypted and if not send a notification  
> > > back to the sender. If you really want this, you must be sure that you  
> > > block 99.99% of all incoming spam otherwise you will be sending  
> > > notifications to 'fake' users.
> > 
> > This discussion came up on an other list some time ago. It is useless to  
> > try to enforce encryption at the \*receiving\* side. If you bounce the  
> > (unencrypted) message, it travels the net two times in clear instead  
> > only once. Force encryption is the job of a Gateway at \*sender\* side, so  
> > convice the remote site to use Djigzo would be a solution....
> > 
> > Regards
> > 
> > Andreas
