Today we are releasing CipherMail Email Encryption Gateway 6.4.0.
Highlights
Elliptic curve S/MIME (ECDH / ECDSA) The gateway can now verify, decrypt, sign and encrypt S/MIME messages with EC keys, as the German edi@energy standard (BSI TR-03116-4) requires:
- ECDSA signatures with SHA-256/384/512
- ECDH key agreement (standard and cofactor, X9.63 KDF, AES key wrap, RFC 5753), with CBC and GCM
- NIST P-256, P-384, P-521 and Brainpool P-256, P-384, P-512
- New recipient settings
smime-key-agreement-scheme,smime-key-agreement-ukmandsmime-ecdsa-signing-algorithm. The existing settings keep their meaning for RSA, so enabling EC never changes what is used for RSA certificates - RSA and EC can be disabled separately for encryption (
smime-rsa-encryption-enabled,smime-ec-encryption-enabled) and for signing (smime-rsa-signing-enabled,smime-ec-signing-enabled) - The built-in CA can generate EC keys (
ca-key-algorithm)
Two-factor authentication and sessions
- A 2FA code can be used only once, only the previous, current and next codes are accepted, and a user
is blocked after 20 failures per day (configurable)
- Changing or disabling 2FA first asks for the current code
- Changing the password or 2FA, disabling a portal login or deleting an admin ends the user's other
sessions, on every node of a cluster
- New CLI commands auth portal 2fa reset-failures and auth admin 2fa reset-failures lift a 2FA block
- With OpenID Connect, the identity provider handles multi-factor authentication
Webmail - Encrypted webmail storage now uses AES-128-GCM in AuthEnvelopedData (RFC 5083) and RSAES-OAEP with SHA-256, which standard tools such as OpenSSL can decrypt - Webmail can be decrypted with a private key on an HSM
Performance and fixes - S/MIME signing and encrypting of large messages uses much less heap; content over 1 MB spills to a temporary file - Messages larger than 100 MB are now DKIM signed - The real subject of a PGP/MIME message with protected headers (RFC 9788) is shown after decryption
Read this before upgrading
- A portal or company portal password set on a domain or globally is now ignored. Users who relied on it get an invite link (with auto-invite enabled), or they can use the password reset.
- The CLI no longer supports 2FA.
ciphermail-clion the gateway itself is not affected. An admin with 2FA should use the admin Shell in the web UI. - Portal back-end on a separate server: upgrade the portal back-end before the gateway.
- Check
ca-key-algorithmafter the upgrade.ca-key-lengthis not migrated, so an installation that had raised it now issues RSA 3072 certificates until you set the new setting. - Webmail stored after the upgrade cannot be read after a downgrade. During a rolling cluster upgrade, webmail replicated to a node that has not been upgraded yet stays unreadable there until that node is upgraded.
- With an HSM, set
ciphermail_portal_backend__webmail_keystore_aliasesto the aliases of the webmail keys. - An S/MIME message that arrives as the only attachment of a message is now delivered as an attached message, not unwrapped.
- Make sure the temporary directory has room for large messages.
- The REST endpoints for changing 2FA have changed (see the release notes).