Configuring encryption settings : Configuring IBE encryption : About FortiMail IBE
About FortiMail IBE
The FortiMail unit encrypts an email message using the public key generated with the recipient’s email address. The email recipient does not need to install any software or generate a pair of keys in order to access the email.
What happens is that when an email reaches the FortiMail unit, the FortiMail unit applies its IP-based policies and recipient-based policies containing IBE-related content profiles as well as the message delivery rules to the email. If a policy or rule match is found, the FortiMail unit encrypts the email using the public key before sending a notification to the recipient. Figure 39 shows a sample notification.
The notification email contains an HTML attachment, which contains instructions and links telling the recipient how to access the encrypted email.
If this is the first time the recipient receives such a notification, the recipient must follow the instructions and links to register on the FortiMail unit before reading email.
If this is not the first time the recipient receives such a notification and the recipient has already registered on the FortiMail unit, the recipient only needs to log in to the FortiMail unit to read email.
When the recipient opens the mail on the FortiMail unit, the email is decrypted automatically. Figure 38 shows how FortiMail IBE works:
Figure 38: How FortiMail works with IBE
Figure 39: Sample secure message notification