# Release candidate 2.1.1 available

**URL:** <https://community.ciphermail.com/t/release-candidate-2-1-1-available/225>\
**Category:** Gateway\
**Created:** [July 27, 2011, 3:56pm UTC](https://community.ciphermail.com/t/release-candidate-2-1-1-available/225 "2011-07-27T15:56:16Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![martijn](https://dub1.discourse-cdn.com/flex017/user_avatar/community.ciphermail.com/martijn/32/127_2.png) [@martijn](https://community.ciphermail.com/u/martijn)\
**Post date:** [July 27, 2011, 3:56pm UTC](https://community.ciphermail.com/t/release-candidate-2-1-1-available/225/1 "2011-07-27T15:56:16Z")

</div>

Hi,

A new Djigzo Gateway release candidate (2.1.1) is available.

[http://www.djigzo.com/beta.html](http://www.djigzo.com/beta.html)

Release notes:

New

\* Advanced S/MIME setting "Always use freshest signing certificate"  
&nbsp;&nbsp;added. If checked, every time the sender needs to sign a message,  
&nbsp;&nbsp;the most recent (i.e., the latest "not before" date) signing  
&nbsp;&nbsp;certificate will be used (GATEWAY-14).  
\* Advanced PDF setting "Only encrypt if mandatory" added (GATEWAY-22).  
&nbsp;&nbsp;If checked, PDF encryption will only be activated if encryption is  
&nbsp;&nbsp;mandatory.  
\* DLP setting "Quarantine on failed encryption" added. If checked and  
&nbsp;&nbsp;encryption is mandatory and a message cannot be encrypted, the  
&nbsp;&nbsp;message will be quarantined and not "bounced". Note: this required  
&nbsp;&nbsp;minor changes to the "DLP quarantine" template.  
\* Quarantined emails can now be "released as-is". When a quarantined  
&nbsp;&nbsp;email is released as-is, no further processing of the email is done  
&nbsp;&nbsp;and the email is immediately delivered.  
\* The admin can now specify how many rows the grid should show per  
&nbsp;&nbsp;page (users, certificates, MTA queue) (GATEWAY-23)  
\* The admin can now filter for specific email in the MTA queue.  
\* The MTA logs are now by default shown in "raw" format (i.e., in  
&nbsp;&nbsp;exact same order as the log file). To view the MTA logs grouped on  
&nbsp;&nbsp;queue ID (the old behavior), the admin should select "Grouped".  
\* If a certificate chain is valid, the issuer of the certificate in  
&nbsp;&nbsp;the certificate view can be clicked to open the issuer certificate  
&nbsp;&nbsp;view.

Improvements

\* The BlackBerry and mobile settings are moved to a specialized mobile  
&nbsp;&nbsp;settings page. New role ROLE\_MOBILE\_MANAGER added.  
\* Some settings are moved to advanced settings.  
\* New charsets can be added to the PDF encryption module (should be  
&nbsp;&nbsp;enabled from the command line) to support charsets not supported  
&nbsp;&nbsp;"out of the box" by Acrobat reader. For example certain Turkish  
&nbsp;&nbsp;characters are not supported "out of the box" by Acrobat reader  
&nbsp;&nbsp;(GATEWAY-20)  
\* If a certificate was available for a recipient, a user object was  
&nbsp;&nbsp;always created for that recipient. The user is no longer added by  
&nbsp;&nbsp;default.

Bug fix

\* With S/MIME "strict mode" enabled, S/MIME messages were only handled  
&nbsp;&nbsp;by the S/MIME handler if the recipient had a valid certificate with  
&nbsp;&nbsp;private key. If a digitally signed message was received for a  
&nbsp;&nbsp;recipient not having a private key, the certificates were not  
&nbsp;&nbsp;extracted from the message and the signature was not removed when  
&nbsp;&nbsp;"Remove signature" was enabled for that recipient. The message is  
&nbsp;&nbsp;now always handled by the S/MIME handler. (GATEWAY-27)  
\* Under certain special conditions, the base64 encoder of Javamail  
&nbsp;&nbsp;sometimes created lines with more than 76 characters (only a few  
&nbsp;&nbsp;characters extra). OpenSSL (which is used by some S/MIME gateways)  
&nbsp;&nbsp;cannot handle base64 encoded parts containing lines longer than 76  
&nbsp;&nbsp;characters. Javamail has been updated (GATEWAY-29)

This release has been extensively tested. If no "show stoppers" are  
found within the next two weeks, it will be released as the new stable  
version.

Kind regards,

Martijn Brinkers

> **···**
>
> --  
> Djigzo open source email encryption

---

<div class="post-metadata">

**Author:** ![lst\_hoe021](https://avatars.discourse-cdn.com/v4/letter/l/58956e/32.png) [@lst\_hoe021](https://community.ciphermail.com/u/lst_hoe021)\
**Post date:** [July 28, 2011, 7:44am UTC](https://community.ciphermail.com/t/release-candidate-2-1-1-available/225/2 "2011-07-28T07:44:22Z")

</div>

Zitat von Martijn Brinkers \<martijn(a)djigzo.com\>:

> Hi,
> 
> A new Djigzo Gateway release candidate (2.1.1) is available.
> 
> [http://www.djigzo.com/beta.html](http://www.djigzo.com/beta.html)
> 
> Release notes:
> 
> Improvements
> 
> \* If a certificate was available for a recipient, a user object was  
> &nbsp;&nbsp;always created for that recipient. The user is no longer added by  
> &nbsp;&nbsp;default.

What is the reasoning behind this one? I found it handsome to which  
addresses where handled by S/MIME and which not by consulting the user  
list.

Regards

Andreas

---

<div class="post-metadata">

**Author:** ![martijn](https://dub1.discourse-cdn.com/flex017/user_avatar/community.ciphermail.com/martijn/32/127_2.png) [@martijn](https://community.ciphermail.com/u/martijn)\
**Post date:** [July 28, 2011, 7:52am UTC](https://community.ciphermail.com/t/release-candidate-2-1-1-available/225/3 "2011-07-28T07:52:58Z")

</div>

My thinking was that you only need to add a user when you need to  
override an inherited setting. Adding an external user when a  
certificate is available for the user resulted in a lot of pointless  
users when using domain to domain encryption since a certificate is  
available for every sender.

I can however see your point in that it helps you to see for which  
external users a certificate is available. The old behavior can be  
reenabled by replacing

RecipientHasCertificates=matchOnError=false,false

with

RecipientHasCertificates=matchOnError=false,true

but this requires you to change the config.xml file. I guess you want it  
to be configurable from the GUI? 😉

Kind regards,

Martijn

> **···**
>
> On 01/-10/-28163 08:59 PM, lst\_hoe02(a)kwsoft.de wrote:
> 
> > Zitat von Martijn Brinkers \<martijn(a)djigzo.com\>:
> > 
> > > Hi,
> > > 
> > > A new Djigzo Gateway release candidate (2.1.1) is available.
> > > 
> > > [http://www.djigzo.com/beta.html](http://www.djigzo.com/beta.html)
> > > 
> > > Release notes:
> > > 
> > > Improvements
> > > 
> > > \* If a certificate was available for a recipient, a user object was  
> > > &nbsp;&nbsp;always created for that recipient. The user is no longer added by  
> > > &nbsp;&nbsp;default.
> > 
> > What is the reasoning behind this one? I found it handsome to which  
> > addresses where handled by S/MIME and which not by consulting the user  
> > list.
> 
> --  
> Djigzo open source email encryption

---

<div class="post-metadata">

**Author:** ![martijn](https://dub1.discourse-cdn.com/flex017/user_avatar/community.ciphermail.com/martijn/32/127_2.png) [@martijn](https://community.ciphermail.com/u/martijn)\
**Post date:** [July 28, 2011, 8:34am UTC](https://community.ciphermail.com/t/release-candidate-2-1-1-available/225/4 "2011-07-28T08:34:38Z")

</div>

I will add a setting that allows you to specify whether you want a user  
to be created automatically when the recipient has a certificate. If you  
use domain to domain encryption you can then set the domain setting for  
that particular domain to not add a user for every recipient of that  
domain.

Kind regards,

Martijn

> **···**
>
> On 07/28/2011 09:52 AM, Martijn Brinkers wrote:
> 
> > On 01/-10/-28163 08:59 PM, lst\_hoe02(a)kwsoft.de wrote:
> > 
> > > Zitat von Martijn Brinkers \<martijn(a)djigzo.com\>:
> > > 
> > > > Hi,
> > > > 
> > > > A new Djigzo Gateway release candidate (2.1.1) is available.
> > > > 
> > > > [http://www.djigzo.com/beta.html](http://www.djigzo.com/beta.html)
> > > > 
> > > > Release notes:
> > > > 
> > > > Improvements
> > > > 
> > > > \* If a certificate was available for a recipient, a user object was  
> > > > &nbsp;&nbsp;always created for that recipient. The user is no longer added by  
> > > > &nbsp;&nbsp;default.
> > > 
> > > What is the reasoning behind this one? I found it handsome to which  
> > > addresses where handled by S/MIME and which not by consulting the user  
> > > list.
> > 
> > My thinking was that you only need to add a user when you need to  
> > override an inherited setting. Adding an external user when a  
> > certificate is available for the user resulted in a lot of pointless  
> > users when using domain to domain encryption since a certificate is  
> > available for every sender.
> > 
> > I can however see your point in that it helps you to see for which  
> > external users a certificate is available. The old behavior can be  
> > reenabled by replacing
> > 
> > RecipientHasCertificates=matchOnError=false,false
> > 
> > with
> > 
> > RecipientHasCertificates=matchOnError=false,true
> > 
> > but this requires you to change the config.xml file. I guess you want it  
> > to be configurable from the GUI? 😉
> 
> --  
> Djigzo open source email encryption

---

<div class="post-metadata">

**Author:** ![lst\_hoe021](https://avatars.discourse-cdn.com/v4/letter/l/58956e/32.png) [@lst\_hoe021](https://community.ciphermail.com/u/lst_hoe021)\
**Post date:** [July 28, 2011, 8:38am UTC](https://community.ciphermail.com/t/release-candidate-2-1-1-available/225/5 "2011-07-28T08:38:55Z")

</div>

Zitat von Martijn Brinkers \<martijn(a)djigzo.com\>:

> > Zitat von Martijn Brinkers \<martijn(a)djigzo.com\>:
> > 
> > > Hi,
> > > 
> > > A new Djigzo Gateway release candidate (2.1.1) is available.
> > > 
> > > [http://www.djigzo.com/beta.html](http://www.djigzo.com/beta.html)
> > > 
> > > Release notes:
> > > 
> > > Improvements
> > > 
> > > \* If a certificate was available for a recipient, a user object was  
> > > &nbsp;&nbsp;always created for that recipient. The user is no longer added by  
> > > &nbsp;&nbsp;default.
> > 
> > What is the reasoning behind this one? I found it handsome to which  
> > addresses where handled by S/MIME and which not by consulting the user  
> > list.
> 
> My thinking was that you only need to add a user when you need to  
> override an inherited setting. Adding an external user when a  
> certificate is available for the user resulted in a lot of pointless  
> users when using domain to domain encryption since a certificate is  
> available for every sender.
> 
> I can however see your point in that it helps you to see for which  
> external users a certificate is available. The old behavior can be  
> reenabled by replacing
> 
> RecipientHasCertificates=matchOnError=false,false
> 
> with
> 
> RecipientHasCertificates=matchOnError=false,true
> 
> but this requires you to change the config.xml file. I guess you want it  
> to be configurable from the GUI? 😉

It isn't that important to clutter the GUI with just another setting i  
guess, it just was "handsome" to quickly alter problematic receivers  
because the user already exists. Would it be possible to not auto  
create users for domains the domain-to-domain encryption is configured  
or something like "auto-create-user-strict-mode" so only users are  
auto created when exactly matching certificates are involved?

Regards

Andreas

> **···**
>
> > On 01/-10/-28163 08:59 PM, lst\_hoe02(a)kwsoft.de wrote:

---

<div class="post-metadata">

**Author:** ![martijn](https://dub1.discourse-cdn.com/flex017/user_avatar/community.ciphermail.com/martijn/32/127_2.png) [@martijn](https://community.ciphermail.com/u/martijn)\
**Post date:** [July 28, 2011, 9:09am UTC](https://community.ciphermail.com/t/release-candidate-2-1-1-available/225/6 "2011-07-28T09:09:49Z")

</div>

> Zitat von Martijn Brinkers \<martijn(a)djigzo.com\>:
> 
> > > Zitat von Martijn Brinkers \<martijn(a)djigzo.com\>:
> > > 
> > > > Hi,
> > > > 
> > > > A new Djigzo Gateway release candidate (2.1.1) is available.
> > > > 
> > > > [http://www.djigzo.com/beta.html](http://www.djigzo.com/beta.html)
> > > > 
> > > > Release notes:
> > > > 
> > > > Improvements
> > > > 
> > > > \* If a certificate was available for a recipient, a user object was  
> > > > &nbsp;&nbsp;always created for that recipient. The user is no longer added by  
> > > > &nbsp;&nbsp;default.
> > > 
> > > What is the reasoning behind this one? I found it handsome to which  
> > > addresses where handled by S/MIME and which not by consulting the user  
> > > list.
> > 
> > My thinking was that you only need to add a user when you need to  
> > override an inherited setting. Adding an external user when a  
> > certificate is available for the user resulted in a lot of pointless  
> > users when using domain to domain encryption since a certificate is  
> > available for every sender.
> > 
> > I can however see your point in that it helps you to see for which  
> > external users a certificate is available. The old behavior can be  
> > reenabled by replacing
> > 
> > RecipientHasCertificates=matchOnError=false,false
> > 
> > with
> > 
> > RecipientHasCertificates=matchOnError=false,true
> > 
> > but this requires you to change the config.xml file. I guess you want it  
> > to be configurable from the GUI? 😉
> 
> It isn't that important to clutter the GUI with just another setting i  
> guess, it just was "handsome" to quickly alter problematic receivers  
> because the user already exists. Would it be possible to not auto create  
> users for domains the domain-to-domain encryption is configured or  
> something like "auto-create-user-strict-mode" so only users are auto  
> created when exactly matching certificates are involved?

Detecting whether the recipient is using domain to domain encryption is  
possible but a lot more work than using a setting and slower since  
instead of just retrieving the list of all certs, a check should be done  
to see whether the cert was a domain cert or not. It's doable but if I  
have to choose between an extra advanced setting or checking for domain  
certs etc. I prefer the extra setting.

Yesterday there was a question about syncing with LDAP and getting a  
list of users that are using S/MIME encryption so I guess you are not  
the only one that likes that feature so I guess it's better to allow the  
admin to decide whether to automatically add a user or not.

> It isn't that important to clutter the GUI with just another setting..

I moved some settings (the mobile settings) to a specialized page. This  
Perhaps I can move certain properties to a specialized page?

Kind regards,

Martijn

> **···**
>
> On 01/-10/-28163 08:59 PM, lst\_hoe02(a)kwsoft.de wrote:
> 
> > > On 01/-10/-28163 08:59 PM, lst\_hoe02(a)kwsoft.de wrote:
> 
> --  
> Djigzo open source email encryption

---

<div class="post-metadata">

**Author:** ![lst\_hoe021](https://avatars.discourse-cdn.com/v4/letter/l/58956e/32.png) [@lst\_hoe021](https://community.ciphermail.com/u/lst_hoe021)\
**Post date:** [July 28, 2011, 10:14am UTC](https://community.ciphermail.com/t/release-candidate-2-1-1-available/225/7 "2011-07-28T10:14:17Z")

</div>

Zitat von Martijn Brinkers \<martijn(a)djigzo.com\>:

> > Zitat von Martijn Brinkers \<martijn(a)djigzo.com\>:
> > 
> > > > Zitat von Martijn Brinkers \<martijn(a)djigzo.com\>:
> > > > 
> > > > > Hi,
> > > > > 
> > > > > A new Djigzo Gateway release candidate (2.1.1) is available.
> > > > > 
> > > > > [http://www.djigzo.com/beta.html](http://www.djigzo.com/beta.html)
> > > > > 
> > > > > Release notes:
> > > > > 
> > > > > Improvements
> > > > > 
> > > > > \* If a certificate was available for a recipient, a user object was  
> > > > > &nbsp;&nbsp;always created for that recipient. The user is no longer added by  
> > > > > &nbsp;&nbsp;default.
> > > > 
> > > > What is the reasoning behind this one? I found it handsome to which  
> > > > addresses where handled by S/MIME and which not by consulting the user  
> > > > list.
> > > 
> > > My thinking was that you only need to add a user when you need to  
> > > override an inherited setting. Adding an external user when a  
> > > certificate is available for the user resulted in a lot of pointless  
> > > users when using domain to domain encryption since a certificate is  
> > > available for every sender.
> > > 
> > > I can however see your point in that it helps you to see for which  
> > > external users a certificate is available. The old behavior can be  
> > > reenabled by replacing
> > > 
> > > RecipientHasCertificates=matchOnError=false,false
> > > 
> > > with
> > > 
> > > RecipientHasCertificates=matchOnError=false,true
> > > 
> > > but this requires you to change the config.xml file. I guess you want it  
> > > to be configurable from the GUI? 😉
> > 
> > It isn't that important to clutter the GUI with just another setting i  
> > guess, it just was "handsome" to quickly alter problematic receivers  
> > because the user already exists. Would it be possible to not auto create  
> > users for domains the domain-to-domain encryption is configured or  
> > something like "auto-create-user-strict-mode" so only users are auto  
> > created when exactly matching certificates are involved?
> 
> Detecting whether the recipient is using domain to domain encryption is  
> possible but a lot more work than using a setting and slower since  
> instead of just retrieving the list of all certs, a check should be done  
> to see whether the cert was a domain cert or not. It's doable but if I  
> have to choose between an extra advanced setting or checking for domain  
> certs etc. I prefer the extra setting.

In this case the extra setting is the better way to go of course.

> Yesterday there was a question about syncing with LDAP and getting a  
> list of users that are using S/MIME encryption so I guess you are not  
> the only one that likes that feature so I guess it's better to allow the  
> admin to decide whether to automatically add a user or not.
> 
> > It isn't that important to clutter the GUI with just another setting..
> 
> I moved some settings (the mobile settings) to a specialized page. This  
> Perhaps I can move certain properties to a specialized page?

Maybe it's time to group the S/MIME special settings like  
"strict-mode", "skip-invites" and the like on one page...

Regards

Andreas

> **···**
>
> > On 01/-10/-28163 08:59 PM, lst\_hoe02(a)kwsoft.de wrote:
> > 
> > > > On 01/-10/-28163 08:59 PM, lst\_hoe02(a)kwsoft.de wrote:
