cancel
Showing results for 
Search instead for 
Did you mean: 

Export domino archive which has encrypted mails

vinkuma
Level 2
Partner Accredited

Team,

I need a clarification whether an adminisatrator would be able to read an encrypted mail which was exported from archive to NSF

As far i know archived mail requires USER ID to be mapped in order to view that item

 

Please clarify and provide the solution

 

Thanks,

Vinoth

1 ACCEPTED SOLUTION

Accepted Solutions

Paul_Honey
Level 5
Employee Accredited

Vinoth

No, an administrator would not be able to read that encrypted email either pre-archiving by EV, post archiving by EV, or post export from EV, or without EV in the picture at all.

The only way to read an encrypted email within Notes is to be either the sender or a recipient of that email as it will be encrypted with the public keys that only these user ids have the corresponding private keys to decrypt with.

From an EV point of view, this means that we do archive encrypted emails, by default in journaling, by policy choice in mailbox archiving, but as the archiving id generally will not have the necessary private keys to decrypt the content, we will archive and index it the email in its encrypted state (i.e. only the header / unecrypted information is actually readable / indexable). when that archiev demail is subsequently retrieved, or in your scenario exported to an NSF, it come sback in the exact same state as it was pre-archiving - i.e. encrypted - and hence can only be read by user ids with the necessary private keys to decrypt it.

EV simply respects the Domino security model with regards to encryption and is not a magic wand to bypass it and allow an admin id access to more content than it would have in normal circumstances.

Regards

Paul

View solution in original post

1 REPLY 1

Paul_Honey
Level 5
Employee Accredited

Vinoth

No, an administrator would not be able to read that encrypted email either pre-archiving by EV, post archiving by EV, or post export from EV, or without EV in the picture at all.

The only way to read an encrypted email within Notes is to be either the sender or a recipient of that email as it will be encrypted with the public keys that only these user ids have the corresponding private keys to decrypt with.

From an EV point of view, this means that we do archive encrypted emails, by default in journaling, by policy choice in mailbox archiving, but as the archiving id generally will not have the necessary private keys to decrypt the content, we will archive and index it the email in its encrypted state (i.e. only the header / unecrypted information is actually readable / indexable). when that archiev demail is subsequently retrieved, or in your scenario exported to an NSF, it come sback in the exact same state as it was pre-archiving - i.e. encrypted - and hence can only be read by user ids with the necessary private keys to decrypt it.

EV simply respects the Domino security model with regards to encryption and is not a magic wand to bypass it and allow an admin id access to more content than it would have in normal circumstances.

Regards

Paul