HostedDB - Dedicated UNIX Servers

-->
IT Baseline Protection Manual S 5.85 Use of encryption procedures for Lotus Notes e-mail

S 5.85 Use of encryption procedures for Lotus Notes e-mail

Initiation responsibility: Head of IT Section, IT Security Management

Implementation responsibility: Administrator, users

Sending e-mails is often one of the most important communication mechanisms in an office environment. Domino Server also provides facilities for sending and receiving e-mails. It is possible to send and receive e-mails both within the Notes system and also to and from persons on the Internet. As e-mail traffic can pass through a number of intermediate stations en route to the recipient and the e-mail content is transmitted in plaintext, an additional form of protection should be employed to prevent interception or modification of messages (see also Section 7.4 "E-mail").

Under Lotus Notes there are several possible ways by which a user can protect e-mail traffic.

When using e-mail protection the following points should be considered:

If a browser is used to access the e-mail database on a Notes server, encryption and signing are not available when sending outgoing e-mails. In this case it is necessary to use external e-mail programs which offer S/MIME support. On the other hand, it will then be necessary to administer the certificates (own and recipient certificates) in the relevant e-mail program. This usually means that every user needs to be trained in certificate management.

Moreover, under Lotus Notes the e-mail database of a user can be encrypted. In this way all incoming e-mails are automatically encrypted on being added to the database. Sent e-mails or draft e-mails can similarly be held encrypted too. Encryption of incoming e-mail must be enabled in the personal document (on the server).

If the e-mail database already contains any e-mail prior to enabling of encryption, then those e-mails will not be encrypted. To encrypt the old e-mails, they must be opened and closed.

Protected communication is generally to be preferred to unprotected. For this reason, consideration should be given as to whether and how messages should be encrypted and / or signed digitally. This decision must be documented in the security guidelines for Lotus Notes.

Where use is to be made of encryption procedures for Lotus Notes e-mail, the users must be trained to use the encryption products correctly.

Additional controls:


© Copyright by
Bundesamt für Sicherheit in der Informationstechnik
last update:
July 2001
home