Configuring encryption settings : Configuring IBE encryption : Configuring IBE services
Configuring IBE services
You can configure, enable, or disable IBE services which control how secured mail recipients use the FortiMail IBE function. For details about how to use IBE service, see “FortiMail IBE configuration workflow”.
To configure IBE service
1. Go to Encryption > IBE > IBE Encryption.
2. Configure the following:
 
GUI item
Description
Enable IBE service
Select to enable the IBE service you configured.
IBE service name
Enter the name for the IBE service. This is the name the secure mail recipients will see once they access the FortiMail unit to view the mail.
User registration expiry time (days)
Enter the number of days that the secure mail recipient has to register on the FortiMail unit to view the mail before the registration expires. The starting date is the date when the FortiMail unit sends out the first notification to a mail recipient.
User inactivity expiry time (days)
Enter the number of days the secure mail recipient can access the FortiMail unit without registration.
For example, if you set the value to 30 days and if the mail recipient did not access the FortiMail unit for 30 days after the user registers on the unit, the recipient will need to register again if another secure mail is sent to the user. If the recipient accessed the FortiMail unit on the 15th days, the 30-day limit will be recalculated from the 15th day onwards.
Encrypted email storage expiry time (days)
Enter the number of days that the secured mail will be saved on the FortiMail unit.
Password reset expiry time (hours)
Enter the password reset expiry time in hours.
This is for the recipients who have forgotten their login passwords and request for new ones. The secured mail recipient must reset the password within this time limit to access the FortiMail unit.
Allow secure replying
Select to allow the secure mail recipient to reply the email with encryption.
Allow secure forwarding
Select to allow the secure mail recipient to forward the email with encryption.
Allow secure composing
Select to allow the secure mail recipient to compose an email. The FortiMail unit will use policies and mail delivery rules to determine if this mail needs to be encrypted.
For encrypted email, the domain of the composed mail’s recipient must be a protected one, otherwise an error message will appear and the mail will not be delivered.
IBE base URL
Enter the FortiMail unit URL, for example, https://192.168.100.20, on which a mail recipient can register or authenticate to access the secure mail.
"Help" content URL
You can create a help file on how to access the FortiMail secure email and enter the URL for the file. The mail recipient can click the “Help” link from the secure mail notification to view the file.
If you leave this field empty, a default help file link will be added to the secure mail notification.
"About" content URL
You can create a file about the FortiMail IBE encryption and enter the URL for the file. The mail recipient can click the “About” link from the secure mail notification to view the file.
If you leave this field empty, a link for a default file about the FortiMail IBE encryption will be added to the secure mail notification.
Allow custom user control
If your corporation has its own user authentication tools, enable this option and enter the URL.
“Custom user control” URL: This is the URL where you can check for user existence.
“Custom forgot password” URL: This is the URL where users get authenticated.
Notification Settings
You can choose to send notification to the sender or recipient when the secure email is read or remains unread for a specified period of time.
Click the Edit link to modify the email template. For details, see “Customizing email templates”.
Depending on the IBE email access method (either PUSH or PULL) you defined in “Configuring encryption profiles”, the notification settings behave differently.
If the IBE message is stored on FortiMail PULL access method), the “read” notification will only be sent the first time the message is read.
If the IBE message is not stored on FortiMail (PUSH access method), the “read” notification will be sent every time the message is read, that is, after the user pushes the message to FortiMail and FortiMail decrypts the message.
There is no “unread” notification for IBE PUSH messages.