<section title="17.6. Secure Multipurpose Internet Mail Extension"><subsection title="Objective"><paragraph
    title="17.6.1."


><![CDATA[<p>Secure Multipurpose Internal Mail Extension (S/MIME) is implemented correctly as an approved cryptographic protocol.</p>]]></paragraph>
 </subsection>
<subsection title="Context"> <block title="Scope"><paragraph
    title="17.6.2."


><![CDATA[<p>This section covers information on the conditions under which S/MIME can be used as an approved cryptographic protocol.</p>]]></paragraph>
<paragraph
    title="17.6.3."


><![CDATA[<p>When using a product that implements S/MIME, requirements for using approved cryptographic protocols will also need to be referenced from <a href="http://nzism.gcsb.govt.nz/ism-document#Section-15924">Section 17.3 - Approved Cryptographic Protocols</a>.</p>]]></paragraph>
<paragraph
    title="17.6.4."


><![CDATA[<p>Information relating to the development of password selection policies and password requirements can be found in <a href="http://nzism.gcsb.govt.nz/ism-document#Section-15349">Section 16.1 - Identification and Authentication</a>.</p>]]></paragraph>
</block>
</subsection>
<subsection title="References"><paragraph
    title="17.6.5."


><![CDATA[<p>Further information on S/MIME can be found at:</p><table class="table-main">
<tbody>
<tr>
<td><strong>Reference</strong></td>
<td><strong>Title</strong></td>
<td><strong>Publisher</strong></td>
<td><strong>Source</strong></td>
</tr>
<tr>
<td>&nbsp;</td>
<td>
<p><strong>Secure/Multipurpose Internet Mail Extensions (S/MIME) Version 3.2 Message Specification</strong></p>
</td>
<td style="text-align: center;">IETF</td>
<td>
<p><a title="Secure/Multipurpose Internet Mail Extensions (S/MIME) Version 3.2 Message Specification" rel="noopener noreferrer" href="https://datatracker.ietf.org/doc/html/rfc5751" target="_blank">https://datatracker.ietf.org/doc/html/rfc5751</a></p>
</td>
</tr>
<tr>
<td><strong>SP 800-57</strong></td>
<td><strong>Recommendations for Key Management</strong></td>
<td style="text-align: center;">&nbsp;NIST</td>
<td>&nbsp;<a rel="noopener noreferrer" href="https://csrc.nist.gov/publications/sp" target="_blank">https://csrc.nist.gov/publications/sp</a></td>
</tr>
</tbody>
</table>]]></paragraph>
 </subsection>
<subsection title="Rationale &amp; Controls"> <block title="Decommissioning"><paragraph
    title="17.6.6.R.01."

    tags="Cryptography,Technical,System Decomissioning"


><![CDATA[<p>Decommissioning MUST ensure any remanent cryptographic data is destroyed or unrecoverable.</p>]]></paragraph>
<paragraph
    title="17.6.6.C.01."

    tags="Cryptography,Technical,System Decomissioning"


    classification="All Classifications"
    compliance="Must"
    cid="2769"
><![CDATA[<p>Decommissioning of faulty or redundant equipment MUST comply with media sanitisation requirements described in <a href="http://nzism.gcsb.govt.nz/ism-document#Chapter-14397">Chapter 12 – Product Security</a>.</p>]]></paragraph>
</block>
<block title="Using S/MIME"><paragraph
    title="17.6.7.R.01."

    tags="Cryptography,Technical"


><![CDATA[<p>S/MIME 2.0 used weaker cryptography (40-bit keys) than is approved for use by the government.  Version 3.0 was the first version to become an Internet Engineering Taskforce (IETF) standard.</p>]]></paragraph>
<paragraph
    title="17.6.7.R.02."

    tags="Cryptography,Technical"


><![CDATA[<p>Agencies choosing to implement S/MIME should be aware of the inability of many content filters to inspect encrypted messages and any attachments for inappropriate content, and for server-based antivirus software to scan for viruses and other malicious code.</p>]]></paragraph>
<paragraph
    title="17.6.7.R.03."

    tags="Cryptography,Technical"


><![CDATA[<p>Improper decommissioning and sanitisation presents opportunities for harvesting Private Keys.  Products that hosted multiple Private Keys for the management of multiple identities should be considered points of aggregation with an increased “target value”.  Where cloud based computing services have been employed, media sanitisation may be problematic and require the revocation and re-issue of new keys.</p>]]></paragraph>
<paragraph
    title="17.6.7.C.01."

    tags="Cryptography,Technical"


    classification="All Classifications"
    compliance="Must Not"
    cid="2780"
><![CDATA[<p>Agencies MUST NOT allow versions of S/MIME earlier than 3.0 to be used.</p>]]></paragraph>
</block>
</subsection>
</section>
