During S/MIME decoding, some errors and warnings are recorded for handling later; other 'fatal' errors prevent further processing.
if S/MIME decoding has been specified, the first step is to load the decryption certificate(s) extracted from $email_decrypt_keyfile command(s) and passed in the MIF. Up to four files may be specified, to allow for expired certificates to be made available. S/MIME errors are recorded on load failure (-31), validation failure (-34), and e-mail address absent (-35), but if one of the specified certificates has no errors, these errors are ignored.
The message is then checked to see if S/MIME is in use. If not, no further S/MIME processing is done, and SMIME_RESULT is 0. An error (-39) is recorded if the S/MIME check fails. Otherwise the SMIME_RESULT is set to either signed only (1). or encrypted (2) or that it is both signed and encrypted (3). This result may be revised during the processing.
If the message is signed only, the signature is verified using the public key in the message; an error (-39) is recorded if the signature was invalid or missing and (-42) if verification fails. Otherwise the signature is saved with a filename sender#domain.cer. A warning is recorded expiring (4) or expired (8) certificate is found, or if saving the certificate file fails (16).
If the message is encrypted, decryption is attempted; an error (-44) is reported if decodeSMIME was not specified in $email_security, (40 or 41) if the decryption block in the message was invalid, and (43) if decryption failed.
After decryption, and depending on the sequence in which the message was encoded, a message signature in one of two formats may be found in the decrypted message. If so, the signature is then verified as described above. In addition, the SMIME_RESULT would change from 2 to 3 at this time.
Finally an SMIME_RESULT error value (negative value) is analyzed:
•if the message was signed, errors 36, 38 and 42 (no certificate, no e-mail in certificate, validation failure) are recorded for processing after the sender and recipient template have been examined.
•if the message was encrypted, all S/MIME errors result in a message error (27) which prevents further processing of the message.
•any other SMIME_RESULT negative value result in a message error (4) which prevents further processing of the message.
The decoded message (without its main part headers) is then ready for further processing.