OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Cryptographic content check

From: Jeremie Le Hen (jeremiele-hen.org)
Date: Fri Jun 01 2007 - 10:42:25 CDT


Hi,

First excuse me if these questions are FAQs, I've tried to search
the archive without success...

I've been asked to set up a mail server which should be able to
check the validity of the cryptographic content of a message.
To be clear, if a message is signed (using PGP, GPG or S/MIME),
the mail server should be able to check:
        - the validity period of the certificate associated to
          the signing private key;
        - the certificate chain of the certificate associated to
          the signing private key

I know this is not Postfix responsibility to check this and it
is designed for a peer-to-peer validation but don't blame me,
this is what the customer wants...

Besides, the customer wants to log the following tuple for each
message {From, To, Date, Subject, MessageID, TLS user}. What is
the best way to achieve this?

Thank you.
Best regards,
--
Jeremie Le Hen
< jeremie at le-hen dot org >< ttz at chchile dot org >