Initial situation:
On the SEPPmail Secure E-Mail Gateway, a domain encryption is to be set up for a communication partner who is a DATEV customer and uses the DATEV email encryption (DEMV) product extension.
Question:
How can the email traffic between the communication partners be secured bidirectionally by means of domain encryption?
Answer:
DATEV DEMV customers have automatic access to the managed domain certificates and thus the domain encryption option to participating managed domains.
However, since DATEV does not provide DEMV customers with managed domain certificates, if applicable, the respective personal S/MIME certificate is to be queried from the DATEV key server for encryption to the corresponding recipients.
This can be realised in the SEPPmail Secure E-Mail Gateway, under Mail Processing Ruleset generator Key server as follows:
Type:
S/MIME
Recipient mask (regexp) :
Email domain of the DEMV customer(s) as regular expression
URI:
'ldap://ldap.crl.esecure.de
Bind DN:
<empty>
Bind PW:
<empty>
Base DN:
dc=esecure,dc=de
Ignore failure:
<according to the desired processing method>