85.1.50. pepsi-secure-link¶

inspect and manage messages held in the portal

Manual section:

1

85.1.50.1.1. Name¶

pepsi-secure-link - operator CLI for the secure-link fallback portal.

85.1.50.1.2. Synopsis¶

pepsi-secure-link [GLOBAL-OPTIONS] list [–limit N] [–expired] [–json]
pepsi-secure-link [GLOBAL-OPTIONS] show TOKEN [–json]
pepsi-secure-link [GLOBAL-OPTIONS] revoke TOKEN
pepsi-secure-link [GLOBAL-OPTIONS] prune [–grace-hours N]

85.1.50.1.3. Description¶

pepsi-secure-link inspects and manages the messages held in the secure-link fallback portal (see pepsi-stage-secure-link(1) and pepsi-httpd(1)). It is an operator tool, not a stage.

Global options (-c/--config, -L/--log, -v) come before the subcommand. Run as root the tool adopts the pepsi service account, so it authenticates to PostgreSQL as the role that owns the queue.

85.1.50.1.4. What it can and cannot show¶

It reports who and when, never what. There is no subcommand that displays a stored message, no --decrypt flag and no escrow key: the content key is derived with Argon2id from the recipient’s PIN, a per-message salt and a server-side pepper, and the PIN is never stored. Nothing an administrator holds — the database, the pepper, both together — reconstructs it.

So when a recipient loses the PIN, the sender sends the message again; a new PIN is issued and a new link mailed. There is no “resend the PIN”, because the PIN exists nowhere but in the correspondents’ hands.

85.1.50.1.5. Commands¶

list

Outstanding messages, newest first: token, sender, recipient, expiry, read count, failed-PIN count and any lockout. --expired also shows messages that have run out but have not been pruned yet. --limit caps the listing (50 by default) and --json prints the same fields as JSON.

show TOKEN

One message’s metadata plus its access log: when each attempt happened, from which address, and how it ended (read, bad-pin, locked, reply). The log is capped per message by [pepsi-secure-link] ACCESS_LOG_ROWS, which is also how many rows show prints, and is deleted with the message.

revoke TOKEN

Destroy one message. This does not put the mail back in the queue — it withdraws it, and the recipient’s link stops working. If it was a mistake, the sender re-sends.

prune

Delete every message past its expiry, and with it the only copy. Intended for a daily cron job or systemd timer, like pepsi-tlsrpt prune. --grace-hours keeps expired messages a little longer. A deployment that never prunes keeps unreadable ciphertext in the database for ever: the portal already refuses an expired token, so this is a database-size problem rather than a confidentiality one, but it is still a problem.

85.1.50.1.6. Privileges¶

The tool runs as the pepsi database role, which is granted INSERT and DELETE on pepsi.secure_message and SELECT on every column of it except ciphertext. That is why list and show work and why nothing here can print a message even by accident; pepsi-setup verifies the boundary against the live database on every run.

85.1.50.1.7. Exit status¶

0 on success, non-zero on error (including show/revoke for a token that does not exist).

85.1.50.1.8. See also¶

pepsi-stage-secure-link(1), pepsi-stage-encrypt(1), pepsi-httpd(1), pepsi-setup(1), pepsi.conf(5)

Logo

Pepsi 0.0.0

Languages

  • English
  • Deutsch
  • français

Navigation

Contents

  • 1. Introduction
  • 2. Getting started on a cheap VPS
  • 3. Installation
  • 4. Debian packages
  • 5. The Wizard
  • 6. Configuration
  • 7. Operating Pepsi
  • 8. Troubleshooting
  • 9. Supported Features
  • 10. SMTP Protocol Extensions
  • 11. Key management
  • 12. The secure-link fallback portal
  • 13. Client interoperability
  • 14. Threat model
  • 15. Security model
  • 16. Microsoft Exchange as a gateway
  • 17. Mailing lists
  • 18. Archives
  • 19. The GNU Mailman 3 REST API
  • 20. The administrative API
  • 21. The administration console
  • 22. Architecture
  • 23. The message state
  • 24. Extending the Pipeline
  • 25. Test Suite
  • 26. Benchmark Suite
  • 27. Performance
  • 28. pepsi-ingress
  • 29. pepsi-dispatch
  • 30. pepsi-httpd
  • 31. pepsi-stage-arc
  • 32. pepsi-stage-srs
  • 33. pepsi-stage-encrypt
  • 34. pepsi-stage-decrypt
  • 35. pepsi-stage-dkim-sign
  • 36. pepsi-stage-bounce
  • 37. pepsi-stage-aliases
  • 38. pepsi-stage-relay-to-internet
  • 39. pepsi-stage-relay-to-smarthost
  • 40. pepsi-stage-relay-to-maildir
  • 41. pepsi-stage-dot-forward
  • 42. pepsi-stage-relay-to-lmtp
  • 43. pepsi-stage-discard
  • 44. pepsi-stage-anti-spam
  • 45. pepsi-stage-auto-pay
  • 46. pepsi-stage-check-whitelist
  • 47. pepsi-stage-auto-whitelist
  • 48. pepsi-stage-autocrypt-learn
  • 49. pepsi-stage-reencrypt
  • 50. pepsi-stage-detect-language
  • 51. pepsi-detect-language
  • 52. pepsi-stage-block-language
  • 53. pepsi-stage-vacation
  • 54. pepsi-stage-secretary
  • 55. pepsi-stage-edit-settings
  • 56. pepsi-stage-if
  • 57. pepsi-stage-milter
  • 58. pepsi-stage-route
  • 59. pepsi-stage-vks-confirm
  • 60. pepsi-stage-secure-link
  • 61. pepsi-setup
  • 62. pepsi-queue
  • 63. pepsi-status
  • 64. pepsi-sendmail
  • 65. pepsi-whitelist
  • 66. pepsi-keys
  • 67. pepsi-keydisc
  • 68. pepsi-settings
  • 69. pepsi-list
  • 70. pepsi-archive
  • 71. pepsi-stage-list
  • 72. pepsi-stage-list-post
  • 73. pepsi-stage-list-deliver
  • 74. pepsi-stage-list-command
  • 75. pepsi-stage-list-bounce
  • 76. pepsi-tlsrpt
  • 77. pepsi-secure-link
  • 78. pepsi-failure-bouncer
  • 79. pepsi-quota
  • 80. pepsi-helper-token-refresh
  • 81. pepsi-telemetry
  • 82. pepsi-telemetry-client
  • 83. pepsi-config
  • 84. Feature stability
  • 85. Manual pages
    • 85.1. Commands (section 1)
    • 85.2. Configuration file (section 5)
    • 85.3. Message state (section 7)
  • 86. RFC Index

Related Topics

  • Documentation overview
    • 85. Manual pages
      • Previous: 85.1.49. pepsi-tlsrpt
      • Next: 85.1.51. pepsi-failure-bouncer

Quick search

©2026, GNUnet e.V.. | Powered by Sphinx 8.1.3 & Alabaster 0.7.16 | Page source