Specify File containing S/MIME Decryption Key
$email_decrypt_keyfile "pathname[;passphrase]"
This command is used to supply a key for decrypting incoming e-mail in the CopiaFacts SMTP Gateway. It is only valid in a special recipient template (.FST) file. The command is not copied to the worker-box FS file generated for the incoming mail item.
Up to 4 commands may be used, all for the same e-mail address matching the recipient mailbox name. This enables specification of certificates with different expiration dates, in case an incoming email has been encrypted using a public key matching an expired certificate. The fifth and later commands in the same FST will be ignored.
If you need to use multiple commands, we recommend that you save your keyfiles with a filename incorporating the expiration date of your certificate, as in the last example below.
The parameters on this command are used as follows:
| pathname | The full pathname of a file containing the sender's public and private keys. The file extension and format must be .PFX, .P12 or .PEM. |
| passphrase | The passphrase for the keyfile (normally required). You may use one of the SECRETx variables for this purpose, to avoid having to place the passphrase in clear in the FS file. The FST file must be authenticated in this case. The authentication command is not copied to the worker-box FS file generated for the incoming mail item. There must be no spaces on either side of the separating semicolon. |
The keyfile must contain a key which is associated with the e-mail address which is specified in the incoming e-mail as the recipient. The SMTP options will specify the disposition of the incoming mail if the decryption fails or if the incoming item for the recipient is not encrypted or not signed.
For a list of possible errors on processing the specified certificate, see the Secure E-Mail Cerificate Errors topic.
Examples:
$email_decrypt_keyfile "`FFCERTS\keyfile.pfx;xyzzy"
$email_decrypt_keyfile "`FFCERTS\keyfile.pfx;`SECRET5"
$email_decrypt_keyfile "`FFCERTS\secure20181231.p12;`SECRET1"
$email_decrypt_keyfile "`FFCERTS\secure20191231.p12;`SECRET2"