49. pepsi-stage-reencrypt

Seal what the gateway decrypted to the recipient’s own key before it is filed.

49.1. Role

pepsi-stage-decrypt opens mail encrypted to a user’s gateway (MTA) key so that the stages after it can read the content. pepsi-stage-reencrypt runs once they have, immediately before local delivery, and seals the message again — to the key the user registered for their own mail client (a custody = client identity, the MUA key). The mailbox then holds ciphertext only that client can open. Reference: pepsi-stage-reencrypt(1).

49.2. Features

  • Only what the gateway opened. state.crypto.in must say the message arrived encrypted and was decrypted; mail that arrived in plaintext, and mail decrypt left unopened for the client, are passed through untouched.

  • One recipient, one key. A message whose recipients are treated differently is split into one row per recipient first; each copy is sealed to that recipient’s newest active MUA key, OpenPGP or S/MIME.

  • Headers. The sender’s Autocrypt: header, the transport trace, the addressing fields and X-Pepsi-Crypto stay outside; the content fields and Autocrypt-Gossip: go inside. PROTECT_HEADERS also hides the subject.

  • No signature is added: the decrypt stage’s verdict is already recorded in state.crypto.in and X-Pepsi-Crypto, and a gateway signature would only claim that the gateway sealed the message.

  • A policy for users with no key (ON_NO_CLIENT_KEY): deliver plaintext (default) or refuse with a 5.7.5 DSN that returns neither body nor subject. Settable per recipient through pepsi-settings.

  • Unprivileged: sealing to a public key needs no private material, so unlike the other crypto stages it is folded into the multi-call pepsi binary and runs as the ordinary pepsi user.

49.3. Configuration

A mandatory NEXT_STAGE (local delivery), BOUNCE_STAGE (for refusals), ON_NO_CLIENT_KEY (plaintext/bounce), PROTECT_HEADERS (default no), ENABLED and the locality options LOCAL_DOMAINS / TARGETS / RECIPIENT_DELIMITER / REQUIRE_ACCOUNT with the decrypt stage’s defaults. The whole message is loaded. See Configuration.

[stage-reencrypt]
PROGRAM = pepsi-stage-reencrypt
NEXT_STAGE = local
BOUNCE_STAGE = bounce

49.4. Placement

After everything that reads the message or may forward a copy elsewhere — language detection, the spam gates, pepsi-stage-autocrypt-learn, aliases, vacation, ~/.forward — and directly in front of pepsi-stage-relay-to-maildir or pepsi-stage-relay-to-lmtp. The setup wizard offers it with the cryptography question and places it there; pepsi-setup warns about any other order.