πŸ“‹ SecuRooms: Restoring E2EE access after forgetting SecuPass

This article explains the multi-step process for administrators to restore access to end-to-end encrypted SecuRooms after a user has forgotten their SecuPass, and describes the specific requirements for initial sharing.

Specifics for sharing E2EE data rooms

Sharing end-to-end encrypted (E2EE) data rooms is done as usual by entering the email address in the sharing dialog. The invited person receives a notification and can access the data room after logging in.

However, there is a special case: If the invited person does not yet have an FTAPI account or has not yet activated their SecuPass for SecuRooms, additional approval by the data room owner is required. This approval can only take place after the invited person has registered in the system and activated their SecuPass for the first time.

Restoring access after a forgotten SecuPass

If a user forgets their SecuPass, access to E2EE data rooms can only be restored through a multi-step process that requires the involvement of an administrator.

Step 1: Reset SecuPass via administrator

An administrator must reset the SecuPass of the affected user.

  1. Navigate to Administration > Users and select the corresponding user.
  2. In the "SecuPass Status" section, click the Reset SecuRooms end-to-end encryption button and confirm the process.

By taking this step, the user immediately loses access to all content that was encrypted with their old SecuPass. This affects both E2EE data rooms and security level 3 and 4 deliveries.

Step 2: User must re-activate E2EE

After the administrator has reset the old key, the user must re-activate end-to-end encryption for their SecuRooms. To do this, they log in to the FTAPI web interface and are prompted to set a new SecuPass.

Step 3: Re-grant access to the data room

As soon as the user has set their new SecuPass, one final step is necessary: An owner of the E2EE data room must re-grant the user access to the desired data room. Only after this renewed sharing can the user access the contents of the data room again.

Important note: Data loss with sole access

Attention: Resetting the SecuPass is an irreversible process. If an end-to-end encrypted data room contained data that only the affected user had access to, this data is irretrievably lost after the reset.

Related articles

Sharing process for E2EE deliveries (SecuMails)