system encryption ibe
Use this command to configure Identity-Based Encryption (IBE) services for encrypted email messages.
Syntax
config system encryption ibe
set auth-mode {password | token | two-factor}
set auth-max-attempt <attempts_int>
set two-factor-auth-method {email | sms}
set sms-provider {etisalat | twilio}
set sms-account-id <account-id_str>
set secure-token-ttl <minutes_int>
set etisalat-username <username_str>
set etisalat-password <password_str>
set etisalat-sender <sender_email>
set account-notification {activation deletion expiration registration-confirmation reset-confirmation}
set expire-registration <days_int>
set expire-inactivity <days_int>
set expire-passwd-reset <hours_int>
set expire-alert {<days_int> ...}
set read-notification {enable | disable}
set unread-notification {enable | disable}
set unread-notif-sender <from_email>
set unread-notif-rcpt <to_email>
set secure-reply {enable | disable}
set secure-forward {enable | disable}
set secure-compose {enable | disable}
set url-base-type {domain | system}
set custom-user-control-status {enable | disable}
set url-custom-user-control <user-check_url>
set url-forgot-pwd <forgot-password_url>
end
|
Variable |
Description |
Default |
|
account-notification {activation deletion expiration registration-confirmation reset-confirmation} |
Select which types of account notifications to send to users. |
activation expiration |
|
Enter the maximum number of tries a user is allowed for authentication. |
3 |
|
|
Select the IBE user authentication method, either:
|
password |
|
|
If your organization has its own user authentication tools, enable this setting. Then configure url-custom-user-control <user-check_url> and url-forgot-pwd <forgot-password_url>. |
disable |
|
|
Enter the password for the Etisalat username. This setting is available if sms-provider {etisalat | twilio} is |
|
|
|
Enter the Etisalat sender name. This setting is available if sms-provider {etisalat | twilio} is |
|
|
|
Enter the Etisalat username. This setting is available if sms-provider {etisalat | twilio} is |
|
|
|
Enter the number of days before the user account's expiry date to send an alert email notification to the user. Valid range is 0 to 7, where 0 means the account expires with no notification. Optionally, for multiple alert email intervals, separate each entry with a space. For example, the default value ( |
0 7 |
|
|
Enter the number of days that the secured mail will be saved on the FortiMail unit. |
180 |
|
|
Enter the number of days the secured mail recipient can access the FortiMail unit without registration. |
90 |
|
|
Enter the password reset expiry time in hours. |
24 |
|
|
Enter the number of days that the secured mail recipient has to register on the FortiMail unit to view the mail before the registration expires. The starting date is the date when the FortiMail unit sends out the first notification to a mail recipient. |
30 |
|
|
Enable to send the read notification the first time the mail is read. |
disable |
|
|
Select to allow the secure mail recipient to compose an email. The FortiMail unit will use policies and mail delivery rules to determine if this mail needs to be encrypted. For encrypted email, the domain of the composed mail’s recipient must be a protected one, otherwise an error message will appear and the mail will not be delivered. |
disable |
|
|
Enable to allow the secured mail recipient to reply to the email with IBE encryption. |
enable |
|
|
Enable to allow the secured mail recipient to forward the email with IBE encryption. |
disable |
|
|
Enter the secure token timeout value in minutes. Valid range is 1-1440. |
30 |
|
|
Enter the name for the IBE service. This is the name the secure mail recipients will see once they access the FortiMail unit to view the secure mail. |
Identity Based Encryption |
|
|
Enter the account or service plan ID provided by your SMS provider. |
|
|
|
Enter the authentication token or API key provided by your SMS provider. |
|
|
|
Enter the phone number from which to send SMS messages. |
|
|
|
Select the name of the SMS provider for two-factor authentication. Then configure related settings such as etisalat-username <username_str>. |
twilio |
|
|
Enable or disable the IBE secure mail service. |
disable |
|
|
Select the verification method for two-factor authentication: email or SMS. This setting is not available when auth-mode {password | token | two-factor} |
|
|
|
Enter the time threshold in days for notification about unread email. This setting is only available when unread-notification {enable | disable} is |
14 |
|
|
Enable to send the unread notification to the recipient. This setting is only available when unread-notification {enable | disable} is |
disable |
|
|
Enable to send the unread notification to the sender. This setting is only available when unread-notification {enable | disable} is |
disable |
|
|
Enable to send the unread notification if the message remains unread after the period of time that you configure in unread-days <days_int>. |
disable |
|
|
If you want to create a custom file about IBE secure mail, enter the URL for the file. The mail recipient can click the "About" link in the secure mail notification to view your file. If you leave this setting empty, a link to the default file about FortiMail IBE secure mail will be added to the secure mail notification. |
|
|
|
Enter the base URL where mail recipients can register and authenticate to access IBE secured mail and IBE notifications. If this setting is empty, the default base URL is used. This setting is available if url-base-type {domain | system} is |
|
|
|
Select the type of base URL where mail recipients register and access IBE secured mail and IBE notifications, either:
|
system |
|
|
Enter the URL where you can determine if an IBE user exists. This setting is available if custom-user-control-status {enable | disable} is |
|
|
|
Enter the URL where IBE users authenticate. This setting is available if custom-user-control-status {enable | disable} is |
|
|
|
If you want to create a custom help file on how to access the IBE secure email, enter the URL for your file. The mail recipient can click the "Help" link from the secure mail notification to view your file. If you leave this setting empty, a link to the default help file will be added to the secure mail notification. |
|