Skip to content

Security

Security contains the host-wide security controls for SSL behavior, session handling, audit retention, password policies, upload restrictions, time-stamping services, and data encryption.

The tab is organized into Sessions, Policies, File Protection, and Advanced Protection. Each section is shown directly when its sub-tab is selected.

Use this page when you need to change security defaults that affect the whole application.

Environment Variable References

Sensitive values in this page can also be provided through environment-variable placeholders.

Typical examples:

1
2
3
4
${SSL_CERTIFICATE_PFX_BASE64}
${SSL_CERTIFICATE_PASSWORD}
${TIMESTAMP_SERVER_USER}
${TIMESTAMP_SERVER_PASSWORD}

This is especially useful when the same Host Administration configuration is promoted across development, staging, and production environments.

Sessions

SSL Options

Force SSL?

Redirects non-SSL traffic to HTTPS and enforces secure access.

Certificate Password

Required when a certificate has been provided and that certificate is password-protected.

Certificate

Stores the SSL certificate as Base64-encoded PFX content. Provide Certificate Password when the PFX is password-protected.

Warning: Package the full certificate chain in the PFX file for best mobile compatibility.

User Sessions

Single Session

Restricts users to one active session at a time.

Controls whether Emakin uses a session cookie.

Emakin normally uses both local storage and session cookies for session protection. Some browsers may block cookies in privacy-focused modes, which can affect login behavior.

Login Token Expiration

Defines how long login tokens remain valid for flows such as email-based or integration-based login.

Bearer Token Expiration

Defines the user-session duration for bearer tokens. These tokens are renewed in the background before they expire.

Authentication Storage

Defines where bearer tokens are stored in the browser:

  • Local Storage: persists until logout or token expiry
  • Session Storage: ends when the browser window closes

Policies

Audit Log

Retention Duration

Defines how many days audit log entries remain in the database. The default is 180 days.

Password Policy

This policy applies to built-in Emakin authentication.

Minimum Password Length

Minimum number of characters required. Host Administration accepts values from 1 to 50.

Minimum Upper Case (A..Z) Letters

Minimum number of uppercase letters required. Host Administration accepts values from 0 to 10.

Minimum Numeric (0..9) Letters

Minimum number of numeric characters required. Host Administration accepts values from 0 to 10.

Minimum Lower Case (a..z) Letters

Minimum number of lowercase letters required. Host Administration accepts values from 0 to 10.

Required Characters

Defines a set of special characters, such as !%@. A password must contain at least one character from this set; it does not have to contain every listed character.

File Protection

Files

Antivirus Service URL

Defines the antivirus scanner endpoint.

ClamAV is currently supported. Use an address such as tcp://hostname:3310. ClamAV must be able to reach its update sources before antivirus scanning is enabled.

Allowed File Types

Controls an allow-list for file types users can upload.

If this list contains entries, only matching file types are permitted.

If the Denied File Types list is left empty, Emakin applies its built-in deny-list for executable, script, HTML, and other risky file types. Do not clear this list expecting all uploads to become unrestricted.

Denied File Types

Controls a deny-list for file types users can upload. When the allow-list is empty, all file types remain permitted except the entries in this list. When both lists contain entries, a file must be allowed and must not be denied.

Extension

Defines the file extension for the selected allowed or denied list, such as pdf or docx.

Mime Type

Defines the MIME type for the selected allowed or denied list, such as application/pdf.

Use * as a wildcard for either value. For example, an extension with * can apply a MIME-type rule to every file extension. In the denied list, a wildcard denies the matching range; it does not allow it.

Emakin also applies a built-in default-denied list for risky extensions and MIME types. Review the security impact before relaxing upload rules.

Advanced Protection

Time Stamping

This section stores connection information for time-stamping services used by electronic-signature workflows.

Timestamp Server URL

URL of the time-stamping server.

Timestamp Server User

Username used for time-stamping service authentication.

Timestamp Server Password

Password used for time-stamping service authentication.

Data Encryption

This section controls whether newly stored form data and uploaded files are encrypted.

Important behavior:

  • encryption affects newly stored data, not previously stored unencrypted data
  • disabling encryption later does not remove access to previously encrypted data
  • form data and files can be controlled separately

Encrypt Form Data

Enables or disables encryption of form data.

Encrypt Files

Enables or disables encryption of uploaded file content.