Errors may be reported when validating PKCS12 certificates on the commands $email_dkim_keyfile, $email_sign_keyfile, $email_encrypt_keyfile and $email_decrypt_keyfile.
For errors on inbound e-mails to the Gateway, see SMTP_DECODE_RESULT values
For outbound DKIM e-mail, the following error codes and texts may be placed in a variable DKIM_ERROR in the failed FS file:
-8 Missing selector
-9 Cannot load keyfile
-20 Invalid canonicalization method
-21 Cannot get space for private key
-22 Private key is not RSA
-23 Cannot decode private key
-24 Cannot set private key
-25 Failed to process body text for DKIM
-27 Missing DK_HEADERFIELDS
For outbound S/MIME e-mail, the following error codes and texts may be placed in a variable SMIME_ERROR in the failed FS file. For inbound S/MIME e-mail, see the list in the Gateway Variables topic, where some of these codes have different meanings.
-28 Cannot re-assemble message after signing/encryption
-29 Invalid signing/encryption request
-30 Failed to parse message for S/MIME action
-31 Cannot load signing keyfile
-32 Cannot load list of keyfiles
-33 No signing certificates loaded from $email_sign_keyfile
-34 Cannot load signing certificate from keyfile
-35 Cannot find an e-mail address in signing certificate
-41 Cannot load encryption keyfile
-42 Cannot load list of encryption keyfiles
-43 No encryption certificates loaded from $email_encrypt_keyfile
-44 Cannot load encryption certificate from keyfile
-45 Cannot find an e-mail address in encryption certificate
Some messages may contain more detailed code numbers with the following meanings:
7937 File doesn't contain a valid PFX sequence
7938 The file doesn't contain any certificate
7939 Some parameters are invalid
7940 Certificate version is invalid
7941 Certificate contains invalid content
7942 AuthenticatedSafe part is invalid
7943 MAC part is invalid
7944 The entity located in the certificate has invalid content type.
7945 The entity located in the certificate has invalid format
7946 The private key contained in the certificate has invalid format
7947 Saving: invalid PBE algorithm specified
Loading: unknown PBE algorithm was used to encrypt the message.
7948 Internal error occured.
7949 PBE algorithm params (iteration count and salt) are invalid
7950 The certificate has invalid format
7951 The certificate has unsupported type
7952 The private key has invalid format
7953 MAC verification failed
7954 Saving: nothing to save
7955 Invalid password was specified. Can not decrypt certificate.
7956 Not enough space to store encoded certificate
7957 Invalid PKCS12 Bag structure.
7958 Unsupported CRL type.
Other code numbers which may be mentioned in the EMAIL_ERROR variable have the following meanings:
73731 ERROR_SSL_UNSUPPORTED_MAC_ALGORITHM
73732 ERROR_SSL_CLIENT_KEX_COMPUTATION_ERROR
73733 ERROR_SSL_COMPRESSION_ERROR
73734 ERROR_SSL_CRYPTO_NOT_INITIALIZED
73735 ERROR_SSL_PRIVATE_KEY_OPERATION_FAILED
75780 ERROR_SSL_RECORD_OVERFLOW
75781 ERROR_SSL_DECOMPRESSION_FAILURE
75782 ERROR_SSL_HANDSHAKE_FAILURE
75783 ERROR_SSL_NO_CERTIFICATE
75784 ERROR_SSL_BAD_CERTIFICATE
75786 ERROR_SSL_CERTIFICATE_REVOKED
75787 ERROR_SSL_CERTIFICATE_EXPIRED
75788 ERROR_SSL_CERTIFICATE_UNKNOWN
75789 ERROR_SSL_ILLEGAL_PARAMETER
75790 ERROR_SSL_UNKNOWN_CA
75791 ERROR_SSL_ACCESS_DENIED
75793 ERROR_SSL_DECRYPT_ERROR
75794 ERROR_SSL_EXPORT_RESTRICTION
75795 ERROR_SSL_PROTOCOL_VERSION
75796 ERROR_SSL_INSUFFICIENT_SECURITY
75797 ERROR_SSL_INTERNAL_ERROR
75798 ERROR_SSL_USER_CANCELED
75799 ERROR_SSL_NO_RENEGOTIATION
75800 ERROR_SSL_CLOSE_NOTIFY
75801 ERROR_SSL_UNKNOWN_PROTOCOL_ERROR