# New release of the CipherMail gateway (3.2.7-5)

**URL:** <https://community.ciphermail.com/t/new-release-of-the-ciphermail-gateway-3-2-7-5/542>\
**Category:** Gateway\
**Created:** [April 25, 2017, 7:57am UTC](https://community.ciphermail.com/t/new-release-of-the-ciphermail-gateway-3-2-7-5/542 "2017-04-25T07:57:52Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![martijn](https://dub1.discourse-cdn.com/flex017/user_avatar/community.ciphermail.com/martijn/32/127_2.png) [@martijn](https://community.ciphermail.com/u/martijn)\
**Post date:** [April 25, 2017, 7:57am UTC](https://community.ciphermail.com/t/new-release-of-the-ciphermail-gateway-3-2-7-5/542/1 "2017-04-25T07:57:52Z")

</div>

A new version of the CipherMail email encryption gateway has been  
released (3.2.7-5)

Release notes:

New

\* IsSMIMEDeepScan matcher added. The IsSMIMEDeepScan matcher can be  
&nbsp;&nbsp;used to detect whether the email is S/MIME and/or whether the email  
&nbsp;&nbsp;contains an attached message (message/rfc822) which is S/MIME.  
\* Add special header to the message if the message could not be  
&nbsp;&nbsp;decrypted (S/MIME or PGP) because there was no suitable decryption  
&nbsp;&nbsp;key for the message.  
\* CertStore command line tool added which can be used to manage the  
&nbsp;&nbsp;certificate store from the command line. CertManager command line  
&nbsp;&nbsp;tool is removed because it's functionality is replaced by the  
&nbsp;&nbsp;CertStore tool.  
\* SMTPSink command line tool added which can be used to test incoming  
&nbsp;&nbsp;email.  
\* CheckKeyStore command line too added which can be used to check  
&nbsp;&nbsp;whether keys are accessible (only used when using an HSM for secure  
&nbsp;&nbsp;key storage).  
\* conf/spring/spring.properties.d directory added from which properties  
&nbsp;&nbsp;files are read. This allows you to use ${...} placeholders in spring  
&nbsp;&nbsp;xml config files which will be replaced by the values defined in the  
&nbsp;&nbsp;properties files. This allows for easier configuration without having  
&nbsp;&nbsp;to change any xml file.  
\* REST service API added [enterprise only]  
\* Respool option added. This can for example be used to retry to  
&nbsp;&nbsp;decrypt a message which could not be decrypted because the private  
&nbsp;&nbsp;key was not available when the message was received [enterprise only]  
\* Meta certificate request resolver added which can be used to try  
&nbsp;&nbsp;multiple certificate request resolvers in succession until one  
&nbsp;&nbsp;returns a valid Distinguished Name (DN) for the certificate request  
&nbsp;&nbsp;[enterprise only]  
\* Static certificate request resolver added. This allows you to specify  
&nbsp;&nbsp;a static mapping from domain or email address to Distinguished Name  
&nbsp;&nbsp;(DN) parameters [enterprise only]  
\* Milter added which can check the MTA queue size and temp error (450)  
&nbsp;&nbsp;if MTA queue size exceeds the max size. This can for example be used  
&nbsp;&nbsp;in a clustered setup to refuse incoming connections if a server is  
&nbsp;&nbsp;too busy [enterprise only]  
\* Thales (nCipher) HSM can now be used in clustered mode where the HSM  
&nbsp;&nbsp;keys are replicated between nodes of the cluster [enterprise only]  
\* "On demand key store" added. This key store can be extended with  
&nbsp;&nbsp;client code to retrieve decryption keys on demand from external  
&nbsp;&nbsp;resources (for example an external key store) [enterprise only]

Bugs/Improvements/Changes

\* Every CRL is now imported in a separate transaction instead of one  
&nbsp;&nbsp;transaction containing all new CRLs. This improves memory usage and  
&nbsp;&nbsp;makes it less likely that the transaction is rolled back in a  
&nbsp;&nbsp;clustered setup because the CRL was already imported on another node.  
\* A "do nothing" post-smime-incoming processor added. This can be used  
&nbsp;&nbsp;to dynamically add new mail rules without having to change the xml  
&nbsp;&nbsp;config file.  
\* CLI command line tool functionality added to manage users.  
\* Some libraries (jar files) updated.  
\* PDF encryption now supports deep scanning which scans the complete  
&nbsp;&nbsp;MIME message (this fixes bug GATEWAY-89)  
\* system.trustAnchorBuilder.updateCheckInterval changed from 30 min to  
&nbsp;&nbsp;5 min. This was needed to make sure that in a clustered setup the  
&nbsp;&nbsp;cached list of root certificates is automatically refreshed every 5  
&nbsp;&nbsp;min (was 30 min).  
\* Because some NIO classes are now used, Java 7 or up is now required.  
\* Postgres NOCREATEUSER NOCREATEDB is no longer used in the  
&nbsp;&nbsp;installation scripts. In Postgres 9.6 NOCREATEUSER is no longer  
&nbsp;&nbsp;supported (this fixes bug GATEWAY-108)  
\* The "installation guide" is renamed to "installation-reference-guide"  
&nbsp;&nbsp;and the "quick install guide" is renamed to "installation guide".  
\* Support for SLES 12 added.

Upgrade guide can be downloaded from:

[http://www.ciphermail.com/documents/upgrade-guide.pdf](http://www.ciphermail.com/documents/upgrade-guide.pdf)

Kind regards,

Martijn Brinkers

> **···**
>
> --  
> CipherMail email encryption
> 
> Open source email encryption gateway with support for S/MIME, OpenPGP  
> and PDF messaging.
> 
> [http://www.ciphermail.com](http://www.ciphermail.com)
> 
> Twitter: [http://twitter.com/CipherMail](http://twitter.com/CipherMail)
