Cisco Cisco Email Security Appliance C170 Mode D'Emploi
19-20
Cisco AsyncOS 9.1 for Email User Guide
Chapter 19 S/MIME Security Services
S/MIME Certificate Requirements
•
Choose whether to retain or remove the digital signature from the messages after S/MIME
verification. If you do not want your end users to know about S/MIME gateway verification, select
Remove.
verification. If you do not want your end users to know about S/MIME gateway verification, select
Remove.
For triple wrapped messages, only the inner signature is retained or removed.
Step 5
Submit and commit your changes.
Tip
If S/MIME Decryption and Verification is enabled in the Mail Flow Policies, all the S/MIME messages
are delivered irrespective of the status of the decryption and verification. If you want to configure an
action for handling S/MIME Decrypted or Verified Messages, you can use the message filter
rules—
are delivered irrespective of the status of the decryption and verification. If you want to configure an
action for handling S/MIME Decrypted or Verified Messages, you can use the message filter
rules—
smime-gateway-verified
and
smime-gateway
. For more information, see
Configuring an Action for S/MIME Decrypted or Verified Message
After Email Security appliance performs S/MIME decryption, verification, or both, you may want to
take different actions depending on the results. You can use the message filter
rules—
take different actions depending on the results. You can use the message filter
rules—
smime-gateway-verified
and
smime-gateway
to perform actions on the messages based on the
result of decryption, verification, or both. For more information, see
Note
You can also use the content filter conditions—S/MIME Gateway Message and S/MIME Gateway
Verified to perform actions on the messages based on the result of decryption, verification, or both. For
more information, see
Verified to perform actions on the messages based on the result of decryption, verification, or both. For
more information, see
Example: Quarantine S/MIME Messages that failed Verification, Decryption, or Both
The following message filter checks if the message is an S/MIME message and quarantines it if the
verification or decryption using S/MIME fails.
verification or decryption using S/MIME fails.
quarantine_smime_messages:if (smime-gateway-message and not smime-gateway-verified) {
quarantine("Policy"); }
S/MIME Certificate Requirements
•
•
Certificate Requirements for Signing
The S/MIME certificate for signing must contain the following information:
Common Name
The fully qualified domain name.
Organization
The exact legal name of the organization.
Organizational Unit
Section of the organization.