An update (6.4.0) for the CipherMail Gateway is now available.

/ Martijn Brinkers

Today we are releasing CipherMail Email Encryption Gateway 6.4.0.

Highlights

Elliptic curve S/MIME (ECDH / ECDSA) The gateway can now verify, decrypt, sign and encrypt S/MIME messages with EC keys, as the German edi@energy standard (BSI TR-03116-4) requires:

Two-factor authentication and sessions - A 2FA code can be used only once, only the previous, current and next codes are accepted, and a user is blocked after 20 failures per day (configurable) - Changing or disabling 2FA first asks for the current code - Changing the password or 2FA, disabling a portal login or deleting an admin ends the user's other sessions, on every node of a cluster - New CLI commands auth portal 2fa reset-failures and auth admin 2fa reset-failures lift a 2FA block - With OpenID Connect, the identity provider handles multi-factor authentication

Webmail - Encrypted webmail storage now uses AES-128-GCM in AuthEnvelopedData (RFC 5083) and RSAES-OAEP with SHA-256, which standard tools such as OpenSSL can decrypt - Webmail can be decrypted with a private key on an HSM

Performance and fixes - S/MIME signing and encrypting of large messages uses much less heap; content over 1 MB spills to a temporary file - Messages larger than 100 MB are now DKIM signed - The real subject of a PGP/MIME message with protected headers (RFC 9788) is shown after decryption

Read this before upgrading

Release notes