Skip to content

Security

Security contains the host-wide security controls for SSL behavior, session handling, audit retention, password policies, upload restrictions, time-stamping services, and data encryption.

The tab is organized into Sessions, Policies, File Protection, and Advanced Protection. Each section is shown directly when its sub-tab is selected.

Use this page when you need to change security defaults that affect the whole application.

Environment Variable References

Sensitive values in this page can also be provided through environment-variable placeholders.

Typical examples:

1
2
3
4
${SSL_CERTIFICATE_PFX_BASE64}
${SSL_CERTIFICATE_PASSWORD}
${TIMESTAMP_SERVER_USER}
${TIMESTAMP_SERVER_PASSWORD}

This is especially useful when the same Host Administration configuration is promoted across development, staging, and production environments.

Sessions

SSL Options

SSL options configuration

Force SSL?

Redirects non-SSL traffic to HTTPS and enforces secure access.

Certificate Password

Required when a certificate has been provided and that certificate is password-protected.

Certificate

Stores the SSL certificate in PFX format.

Warning: The documentation states that the full certificate chain should be packaged in the PFX file for best mobile compatibility.

User Sessions

User session settings

Single Session

Restricts users to one active session at a time.

Controls whether Emakin uses a session cookie.

The existing documentation notes that Emakin normally uses both local storage and session cookies for session protection. It also notes that some browsers may block cookies in privacy-focused modes, which can affect login behavior.

Login Token Expiration

Defines how long login tokens remain valid for flows such as email-based or integration-based login.

Bearer Token Expiration

Defines the user-session duration for bearer tokens. The documentation notes that these tokens are renewed in the background before they expire.

Authentication Storage

Defines where bearer tokens are stored in the browser:

  • Local Storage: persists until logout or token expiry
  • Session Storage: ends when the browser window closes

Policies

Audit Log

Retention Duration

Defines how many days audit log entries remain in the database. The documented default is 180 days.

Password Policy

This policy applies to built-in Emakin authentication.

Password policy configuration

Minimum Password Length

Minimum number of characters required.

Minimum Upper Case (A..Z) Letters

Minimum number of uppercase letters required.

Minimum Numeric (0..9) Letters

Minimum number of numeric characters required.

Minimum Lower Case (a..z) Letters

Minimum number of lowercase letters required.

Required Chars

Specific characters that must appear in the password.

File Protection

Files

Antivirus Service URL

Defines the antivirus scanner endpoint.

The existing documentation states that ClamAV is currently supported and gives an example format of tcp://hostname:3310. It also notes that ClamAV must be able to reach its update sources before antivirus scanning is enabled.

Allowed File Types

Controls an allow-list for file types users can upload.

Allowed and denied file types

If this list contains entries, only matching file types are permitted.

If the Denied File Types list is left empty, Emakin applies its built-in deny-list for executable, script, HTML, and other risky file types. Do not clear this list expecting all uploads to become unrestricted.

Denied File Types

Controls a deny-list for file types users can upload. When the allow-list is empty, all file types remain permitted except the entries in this list. When both lists contain entries, a file must be allowed and must not be denied.

Extension

Defines the file extension for the selected allowed or denied list, such as pdf or docx.

Mime Type

Defines the MIME type for the selected allowed or denied list, such as application/pdf.

The current documentation also preserves a default-denied list for risky extensions and MIME types. Keep that list under review before relaxing upload rules.

Advanced Protection

Time Stamping

Time-stamping settings

This section stores connection information for time-stamping services used by electronic-signature workflows.

Timestamp Server URL

URL of the time-stamping server.

Timestamp Server User

Username used for time-stamping service authentication.

Timestamp Server Password

Password used for time-stamping service authentication.

Data Encryption

This section controls whether newly stored form data and uploaded files are encrypted.

The preserved documentation notes:

  • encryption affects newly stored data, not previously stored unencrypted data
  • disabling encryption later does not remove access to previously encrypted data
  • form data and files can be controlled separately

Encrypt Form Data

Enables or disables encryption of form data.

Encrypt Files

Enables or disables encryption of uploaded file content.