77. pepsi-secure-link¶

Inspect and manage the messages held in the secure-link portal.

77.1. Role¶

pepsi-secure-link is the operator CLI for the secure-link fallback portal: list shows what is outstanding (--limit, --expired to include messages that have expired but not yet been pruned, --json), show TOKEN adds one message’s access log, revoke TOKEN destroys a message and prune deletes what has expired (--grace-hours keeps it a while longer). It is not a stage. Reference: pepsi-secure-link(1).

77.2. What it will not do¶

It reports who and when, never what. There is no subcommand that shows a stored message, no --decrypt and no escrow key: the content key is derived from the recipient’s PIN, which this server never stores, so there is nothing for an administrator to look up. When a PIN is lost, the answer is that the sender sends the message again. See The secure-link fallback portal for the whole argument and its consequences.

77.3. Running it¶

Run as root it adopts the pepsi service account. That role can read every column of pepsi.secure_message except ciphertext, which is why listing works and why nothing here can print a message even by accident; pepsi-setup verifies the boundary against the live database on every run.

prune belongs in a daily cron job or systemd timer: the portal already refuses an expired token, but nothing deletes the bytes until the job runs.

Logo

Pepsi 0.0.0

Languages

  • English
  • Deutsch
  • français

Navigation

Contents

  • 1. Introduction
  • 2. Getting started on a cheap VPS
  • 3. Installation
  • 4. Debian packages
  • 5. The Wizard
  • 6. Configuration
  • 7. Operating Pepsi
  • 8. Troubleshooting
  • 9. Supported Features
  • 10. SMTP Protocol Extensions
  • 11. Key management
  • 12. The secure-link fallback portal
  • 13. Client interoperability
  • 14. Threat model
  • 15. Security model
  • 16. Microsoft Exchange as a gateway
  • 17. Mailing lists
  • 18. Archives
  • 19. The GNU Mailman 3 REST API
  • 20. The administrative API
  • 21. The administration console
  • 22. Architecture
  • 23. The message state
  • 24. Extending the Pipeline
  • 25. Test Suite
  • 26. Benchmark Suite
  • 27. Performance
  • 28. pepsi-ingress
  • 29. pepsi-dispatch
  • 30. pepsi-httpd
  • 31. pepsi-stage-arc
  • 32. pepsi-stage-srs
  • 33. pepsi-stage-encrypt
  • 34. pepsi-stage-decrypt
  • 35. pepsi-stage-dkim-sign
  • 36. pepsi-stage-bounce
  • 37. pepsi-stage-aliases
  • 38. pepsi-stage-relay-to-internet
  • 39. pepsi-stage-relay-to-smarthost
  • 40. pepsi-stage-relay-to-maildir
  • 41. pepsi-stage-dot-forward
  • 42. pepsi-stage-relay-to-lmtp
  • 43. pepsi-stage-discard
  • 44. pepsi-stage-anti-spam
  • 45. pepsi-stage-auto-pay
  • 46. pepsi-stage-check-whitelist
  • 47. pepsi-stage-auto-whitelist
  • 48. pepsi-stage-autocrypt-learn
  • 49. pepsi-stage-reencrypt
  • 50. pepsi-stage-detect-language
  • 51. pepsi-detect-language
  • 52. pepsi-stage-block-language
  • 53. pepsi-stage-vacation
  • 54. pepsi-stage-secretary
  • 55. pepsi-stage-edit-settings
  • 56. pepsi-stage-if
  • 57. pepsi-stage-milter
  • 58. pepsi-stage-route
  • 59. pepsi-stage-vks-confirm
  • 60. pepsi-stage-secure-link
  • 61. pepsi-setup
  • 62. pepsi-queue
  • 63. pepsi-status
  • 64. pepsi-sendmail
  • 65. pepsi-whitelist
  • 66. pepsi-keys
  • 67. pepsi-keydisc
  • 68. pepsi-settings
  • 69. pepsi-list
  • 70. pepsi-archive
  • 71. pepsi-stage-list
  • 72. pepsi-stage-list-post
  • 73. pepsi-stage-list-deliver
  • 74. pepsi-stage-list-command
  • 75. pepsi-stage-list-bounce
  • 76. pepsi-tlsrpt
  • 77. pepsi-secure-link
    • 77.1. Role
    • 77.2. What it will not do
    • 77.3. Running it
  • 78. pepsi-failure-bouncer
  • 79. pepsi-quota
  • 80. pepsi-helper-token-refresh
  • 81. pepsi-telemetry
  • 82. pepsi-telemetry-client
  • 83. pepsi-config
  • 84. Feature stability
  • 85. Manual pages
  • 86. RFC Index

Related Topics

  • Documentation overview
    • Previous: 76. pepsi-tlsrpt
    • Next: 78. pepsi-failure-bouncer

Quick search

©2026, GNUnet e.V.. | Powered by Sphinx 8.1.3 & Alabaster 0.7.16 | Page source