Uploaded image for project: 'Jira Platform Cloud'
  1. Jira Platform Cloud
  2. JRACLOUD-43585

Enabling encrypted mail notifications

XMLWordPrintable

    • 11
    • 30
    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

      NOTE: This suggestion is for JIRA Cloud. Using JIRA Server? See the corresponding suggestion.

      Problem-Context

      Some of my customers are highly concerned about securing JIRA/Confluence. While accesing the tools can be easily secured through SSL a security painpont are the notfication mails. Enabling TLS for the mail server is useless in most scenarios as this only secures the transport to the next hop.

      So how to deal with it. The first strategy is to customize the mail templates and strip all content that is not allowed to be deliverd through insecure networks. There are some tickets in JIRA and confluence about this matter. However customizing the templates is to much administration as this needs to check after each update/upgrade of the tool. In addition the users really love the notifications, and stripping all content is not of much help to them.

      The second strategy applies to a scenario where mails to some domains could be delivered without any concern (e.g. secure internal domain) and some mails to external suppliers needs to be dropped or filtered. In this case I recommend my customers to setup an postfix after queue filter to do the trick - which works pretty well.

      Suggestion

      There should be a flag in the notification scheme which says "Send mails to the user only if he or she has provided a valid mail certificate". In the user profile there would be an upload feature, so that the user can upload or update his public mail certificate (as selfservice - so no additional administration efforts in caretaking of certificates). And of course if the flag is set, the mail sent would be encrypted and signed by JIRA/Confluence and if the user has not stored a certificate he gets nothing (or an advice to store a mail certificate in his profile).

              Unassigned Unassigned
              286d5d3682de Stefan Schubert
              Votes:
              45 Vote for this issue
              Watchers:
              45 Start watching this issue

                Created:
                Updated: