SecureIT S/MIME Gateway

SecureIT® gives you transparent and easy to use policy based S/MIME signing and encryption of e-mail at the gateway.

SecureIT® works with Clearswift's MIMEsweeper for SMTPTM to ensure that:

  • Message content remains confidential during transmission over the public network
  • Recipients can be certain about the authenticity and integrity of messages they receive
  • Control and management of the Public Key Infrastructure (PKI) necessary for this process is maintained at a single point

Encryption provides privacy for content as it passes across the public network. Digital signatures provide proof that a message is from who it appears to be from and that it has not been tampered with during transmission. But these processes can create problems like exposure to content threats, orphaned data that can't be decrypted, unauthorised transfer of confidential information and the complexity of managing and synchronising all the public and private keys necessary to run the process.

 

Together SecureIT® and MIMEsweeper for SMTP help solve these problems.

What SecureIT® does

SecureIT® is an S/MIME extension to MIMEsweeper for SMTP's powerful, policy-based content security engine. This helps to prevent damage from threats that might be hidden in the content of encrypted e-mail.

 

SecureIT® provides encryption/decryption and signing/signature verification to S/MIME standards at the gateway. This avoids the high cost, complexity and security pitfalls associated with desktop solutions.

 

SecureIT® automates the process for establishing and maintaining links to other S/MIME gateways. This guarantees security policy is always applied and makes the set up and operation of links transparent to end users and administrators.

 

Because SecureIT® is integrated with MIMEsweeper for SMTP, lexical analysis can be used to trigger S/MIME encryption and signing policy.

How SecureIT® works

For large dynamic networks, SecureIT® automates site-to-site link set up and maintenance via periodic reference to an authoritative LDAP directory. Certificates and other data obtained from the directory are cached locally. For smaller static networks SecureIT® provides simplified manual link set up.

 

SecureIT® permits:

  • More than one active certificate per domain
  • Different certificates for signing and encryption
  • Different signing and encryption algorithms for each link
  • Multiple internal domains/users with their own certificates, proxy signing
  • Automatic retrieval of replacements for expired public certificates
  • Intelligent handling of external List Server messages
  • Annotation of message From: and Subject: fields to show secure arrival
  • Concealment of Subject
  • Outbound subject line commands select policy & change sender address
  • Collection and optional activation of certificates from inbound messages
  • Retention of before and after encryption copies for archive purposes
  • Detailed reporting of signature verification and decryption status is used to create meaningful messages and activity logs.
  • Messages failing policy to be annotated (message text prepended and appended) or attached to an informative message.
  • Automatic retry when outbound certificate problems occur

 

For large dynamic secure communities policy rules are stored, updated and disseminated centrally. SecureIT® automates link set up and maintenance, and automatically obtains and caches certificates via LDAP and CRLs via HTTP.

 

For smaller static secure communities SecureIT provides local policy and simplified manual link set up and maintenance.

 

Link policy is stored, updated and disseminated centrally.

 

Detailed signature verification and decryption status indicators are reported and can be used to create very meaningful error messages for recipients. Messages failing encryption/signature policy can be annotated (message text prepended and appended) or encapsulated (added to an informative message as an attachment).

 

SecureIT® uses Certificate Revocation Lists (CRL) and automatically changes the status of revoked certificates.

 

SecureIT® Standards

SecureIT® is accredited by the New Zealand Government for use in its Secure Electronic Environment.

 

SecureIT® provides encryption with a choice of: RC2 (40, 64 and 128-Bit), DES (56-Bit), Triple DES (168-Bit) and AES algorithms with X9.31 PRNG.

 

Digital signing uses RSA with MD5 and SHA-1. Both clear signing and opaque signing are supported.

 

SecureIT® supports X.509 v3 certificates with key lengths of 512, 1024, 2048 or 4096-Bit. These can be issued by any of the major Certificate Authorities, or self-signed certificates can be generated by SecureIT®. Private key import from PKCS#12 containers and storage in an encrypted vault. Public key import from P7C, P7B, CER, PEM and PKCS#12 containers and LDAP directories.

 

SecureIT® supports S/MIME v3 capabilities.

 

More Information

Scientific Software and Systems Limited

New Zealand

Telephone +64 4 917-6670

e-mail: info@sss.co.nz   

web: http://www.secureit.co.nz/