<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PDF with a qualified electronic signature in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDF-with-a-qualified-electronic-signature/m-p/220470#M42192</link>
    <description>&lt;P&gt;Hello Team!&lt;/P&gt;
&lt;P&gt;we finally solved that mystery. interesting is .. Check Point TE/TX solution is already capable of processing digitally signed emails!&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;SPAN&gt;there are three scenarios:&lt;BR /&gt;1. you send a digital singed email with an unsigned document in it. &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;This will bypassed if you set "allow encrypted email" in the SmartConsole / Threat Prevention Profile / Threat Extraction / "Encrypted Allow"&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;but this can be dangerous because the attachment will just be bypassed. And not people do have a digital signature to signed their email!&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;2. you send a normal mail (unsigned) but the attachment with the email is digitally signed. you applied setting like it scenario 1.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;The attachment will get processed by TX and destroyed.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;3. You have a digital signed email and digital attachment. &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;M&lt;/SPAN&gt;&lt;SPAN&gt;ore or less scenario 1 strikes again and it a bypass regardless what kind of attchment you send! Highly dangerous in my eyes!&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;solution provided by TAC:&lt;BR /&gt;on all affected machines: Security GW (MTA) and Sandblast change this:&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;1. We need to change the values in both of these files:&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;* /var/opt/CPsuit-R81.10/fw1/conf/file_convert.conf&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;* /var/log/jail/opt/CPsuite-R81.10/fw1/conf/file_convert.conf&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;2. Please locate " ignore_signed_pdfs (0) , change the value, in both files to (1), save and exit the file. &lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;3. Redirect PDF document to the sanitization engine in /var/opt/CPsuit-R81.10/fw1/conf/file_convert.conf:&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;...&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;:sanitization_engine_file_types (&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;: (docx)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;: (doc)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;: (docm)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;: (xls)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;: (xlsx)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;: (xlsm)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;: (rtf)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;: (pdf) #add this line&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;) #EOF&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;4. fw kill scrubd&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;this has helped us to send digital signed emails in all scenarios and keep the digital signature.&lt;BR /&gt;what we did no achieve is to digitally sign a malicious PDF and send it through Sandblast appliance.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jul 2024 06:09:29 GMT</pubDate>
    <dc:creator>Thomas_Eichelbu</dc:creator>
    <dc:date>2024-07-12T06:09:29Z</dc:date>
    <item>
      <title>PDF with a qualified electronic signature</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDF-with-a-qualified-electronic-signature/m-p/46736#M13452</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Is there a way that sandblast wont remove or ignore PDFs with a&amp;nbsp;qualified electronic signature (&lt;SPAN&gt;compliant to EU Regulation No 910/2014).. At the moment the "Threat Extraction" removes the signature and recreates the PDF.. The best way will be if ThreatExtraction will bypass PDF with such a signature or wont think this is "evil"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 11:50:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDF-with-a-qualified-electronic-signature/m-p/46736#M13452</guid>
      <dc:creator>Robert_Mueller</dc:creator>
      <dc:date>2019-03-13T11:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: PDF with a qualified electronic signature</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDF-with-a-qualified-electronic-signature/m-p/47228#M13453</link>
      <description>If the signature is considered "active content" then Threat Extraction would definitely remove it. If you can provide a sample document (possibly through the TAC), someone can take a look at it.</description>
      <pubDate>Sun, 17 Mar 2019 04:36:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDF-with-a-qualified-electronic-signature/m-p/47228#M13453</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-03-17T04:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: PDF with a qualified electronic signature</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDF-with-a-qualified-electronic-signature/m-p/150396#M24415</link>
      <description>&lt;P&gt;After 3 years -have you received any answer form TAC? I have similar problems with signed pdf and active content, like fast save data. "Normal" signed pdfs are ok and unchanged, but signed pdfs with a various active content are sanitized, what is not bad, as long as the signed version is available "long enough" - but "long enough" is being defined individually by each user. So I'm excited to know if you have received any good solution from TAC.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2022 09:07:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDF-with-a-qualified-electronic-signature/m-p/150396#M24415</guid>
      <dc:creator>chrominek</dc:creator>
      <dc:date>2022-06-08T09:07:31Z</dc:date>
    </item>
    <item>
      <title>Re: PDF with a qualified electronic signature</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDF-with-a-qualified-electronic-signature/m-p/212242#M40272</link>
      <description>&lt;P&gt;Hello Folks,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;i have the same use case ...&lt;BR /&gt;digitally signed PDF are loosing their digital signed integrity and the digital signature is corrupted when PDF´s are passing through TE/TX.&lt;BR /&gt;Even when the setting on the Threat Prevention profile for encrypted mails are set to "Allow".&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;has somebody managed to get this running?&lt;BR /&gt;&lt;BR /&gt;best regards&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 07:09:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDF-with-a-qualified-electronic-signature/m-p/212242#M40272</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2024-04-25T07:09:27Z</dc:date>
    </item>
    <item>
      <title>Re: PDF with a qualified electronic signature</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDF-with-a-qualified-electronic-signature/m-p/220470#M42192</link>
      <description>&lt;P&gt;Hello Team!&lt;/P&gt;
&lt;P&gt;we finally solved that mystery. interesting is .. Check Point TE/TX solution is already capable of processing digitally signed emails!&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;SPAN&gt;there are three scenarios:&lt;BR /&gt;1. you send a digital singed email with an unsigned document in it. &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;This will bypassed if you set "allow encrypted email" in the SmartConsole / Threat Prevention Profile / Threat Extraction / "Encrypted Allow"&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;but this can be dangerous because the attachment will just be bypassed. And not people do have a digital signature to signed their email!&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;2. you send a normal mail (unsigned) but the attachment with the email is digitally signed. you applied setting like it scenario 1.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;The attachment will get processed by TX and destroyed.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;3. You have a digital signed email and digital attachment. &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;M&lt;/SPAN&gt;&lt;SPAN&gt;ore or less scenario 1 strikes again and it a bypass regardless what kind of attchment you send! Highly dangerous in my eyes!&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;solution provided by TAC:&lt;BR /&gt;on all affected machines: Security GW (MTA) and Sandblast change this:&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;1. We need to change the values in both of these files:&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;* /var/opt/CPsuit-R81.10/fw1/conf/file_convert.conf&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;* /var/log/jail/opt/CPsuite-R81.10/fw1/conf/file_convert.conf&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;2. Please locate " ignore_signed_pdfs (0) , change the value, in both files to (1), save and exit the file. &lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;3. Redirect PDF document to the sanitization engine in /var/opt/CPsuit-R81.10/fw1/conf/file_convert.conf:&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;...&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;:sanitization_engine_file_types (&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;: (docx)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;: (doc)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;: (docm)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;: (xls)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;: (xlsx)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;: (xlsm)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;: (rtf)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;: (pdf) #add this line&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;) #EOF&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;4. fw kill scrubd&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;this has helped us to send digital signed emails in all scenarios and keep the digital signature.&lt;BR /&gt;what we did no achieve is to digitally sign a malicious PDF and send it through Sandblast appliance.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 06:09:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDF-with-a-qualified-electronic-signature/m-p/220470#M42192</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2024-07-12T06:09:29Z</dc:date>
    </item>
  </channel>
</rss>

