basedglobalsign

globalsign  时间:2021-01-11  阅读:()
CenterforBiologicsEvaluationandResearchSOPP8119Page1of9SOPP8119:UseofEmailforRegulatoryCommunicationsVersion:7EffectiveDate:February17,2020TableofContentsI.
Purpose1II.
Scope.
1III.
Background.
1IV.
Definitions.
2V.
Policy.
3VI.
Responsibilities.
6VII.
Procedures.
7VIII.
Appendix8IX.
References8X.
History.
9I.
PurposeA.
ThisStandardOperatingPolicyandProcedure(SOPP)servesasaguideforCenterforBiologicsEvaluationandResearch(CBER)staffonthehandlingofregulatoryelectronicmessages(emails).
Regulatoryemailsmaybeeitherinternalcommunicationsormessagesreceivedfromorsenttosponsors/applicantsorothersexternaltoFDA.
II.
ScopeA.
ThisSOPPappliestoallregulatorycommunications.
III.
BackgroundA.
IncreasingoverallproductreviewefficiencyhasbeenasignificantcomponentofthePrescriptionDrugUserFeeAct(PDUFA)fromitsinception.
Additionaleffortstoincreasereviewefficiency,includetheMedicalDeviceUserFeeandModernizationActof2002(MDUFMA),PDUFAandMDUFAreauthorizations,developmentofelectronicsubmissioninfrastructuresuchastheCBERElectronicDocumentRoom(EDR)andtheAgencyElectronicSubmissionGateway(ESG).
Allofthesenecessitatestreamliningthereviewprocess.
CenterforBiologicsEvaluationandResearchSOPP8119Page2of9B.
ThisstreamliningdoesnotdiminishtheFoodandDrugAdministration's(FDA)responsibilityformaintainingacomplete,accurate,andorganizedadministrativefiletoensurethatallregulatoryactions/decisionsareappropriatelydocumented.
AsaFederalAgency,FDAisrequiredtoadministerandmaintainitselectronicrecordsincompliancewith36CFR1236,"electronicRecordsManagement.
"TheOfficeofChiefCounsel(OCC),FDAhasdeterminedthatemailsarelegalcommunicationsacceptableasregulatorysubmissionsuponwhichregulatorydecisionscanbemadeandtransmitted.
C.
InDecember2017,theFDApublishedaguidancedocument,"BestPracticesforCommunicationBetweenINDSponsorsandFDADuringDrugDevelopment,"thatoutlinesemailpracticesthatmustbefollowedbyCBERstaff.
AlthoughthisguidancedocumentiswrittentoaddresscommunicationbetweenInvestigationalNewDrug(IND)sponsorsandFDA,theprinciplesapplytoallregulatorycommunication.
AdditionalguidancepublishedinApril2014,"TypesofCommunicationDuringtheReviewofMedicalDeviceSubmissions",outlinesappropriateuseofemailduringthereviewofmedicaldevicesubmissions.
IV.
DefinitionsA.
AdministrativeFile-Thefileorfilescontainingalldocumentspertainingtoaparticularadministrativeaction,includinginternalworkingmemoranda,andrecommendations.
(21CFR10.
3)B.
AdministrativeRecord–ThedocumentsintheadministrativefileofaparticularadministrativeactiononwhichtheCommissionerreliestosupporttheaction.
(21CFR10.
3)Administrativerecordsincludesponsor/applicantsubmissions,CBER/FDAgenerateddocuments,andCBER/FDAdatabaserecords.
C.
CommercialInformation-Privilegedorconfidentialinformationthatisvaluabledataorinformationwhichisusedinbusinessandisofatypecustomarilyheldinstrictconfidenceorregardedasprivilegedandnotdisclosedtoanymemberofthepublicbythepersontowhomitbelongs.
(21CFR20.
61(b))D.
EmailString–Includesanoriginatingemailandresponses.
Thestringcouldbeseveralcommunicationsbetweentwopeopleorseveralpeopleutilizingthe"replytoall"function.
E.
Recordcopy-Thedocumentthatiskeptonfileasanoriginalorofficialmasterrecordforthetotalretentionperiod.
AccordingtoFDA'sOfficeofChiefCouncil,theoutgoingcorrespondencerecordcopymustbeanexactduplicationofwhatthesponsor/applicantreceives.
Recordcopiesaresometimesreferredtoasthearchivalcopy.
CenterforBiologicsEvaluationandResearchSOPP8119Page3of9F.
Regulatorycommunication–Acommunicationthatcontainsregulatoryinformation,includingcorrespondencegeneratedbyCBER.
Theinclusionofasubmission'ssubmissiontrackingnumber(STN)makesacommunicationregulatoryinnature.
G.
RegulatoryEmail–Anelectronicmessagethatcontainsregulatoryinformation.
Aregulatoryemailmaybeastand-alonemessageoramessagewithanattachedfile.
Theinclusionofasubmission'sSTNmakestheemailregulatory.
H.
RegulatoryInformation–InformationrelatedtoproductsregulatedbyFDA,includingproduct,manufacturing,andfacilityorcompanyinformation,adverseevents,complianceactions,CBER-generatedcorrespondence,etc.
Thesubmission'sSTNisconsideredregulatoryinformation,particularlyifthesubmissionispendingFDAreviewandaction.
I.
SecureEmail–anelectronicmessagesentfromasponsor/applicantthathasexchangedsecurecertificateswithFDA.
Securecertificatestypicallyincludetheentirecorporateororganizationstructureofasponsor/applicantorasubsetofusers.
Secureemailmakesuseofencryptiontechnologyduringtransmissionanddecryptionuponreceiptusingapublickeywithinthecertificate.
InstructionsonhowanorganizationmayobtainasecureemailcertificateareincludedinAppendixA.
J.
TradeSecrets-Consistsofanycommerciallyvaluableplan,formula,process,ordevicethatisusedforthemaking,preparing,compounding,orprocessingoftradecommoditiesandthatcanbesaidtobetheend-productofeitherinnovationorsubstantialeffortandhasadirectrelationshipbetweenthetradesecretandtheproductiveprocess.
(21CFR20.
61(a))V.
PolicyA.
SecureEmailUse1.
CBERpersonnelareresponsibleforprotectingcompanyconfidential,tradesecretandproprietaryinformation.
Therefore,CBER-generatedregulatorycommunicationsareonlysenttorecipientsviasecureemail.
Ifrecipientsdonothavesecureemail,regulatorycommunicationswillbesentbyU.
S.
postalserviceorcommercialcarrierwithafollow-upfacsimileallowedasarapidmeansoftransmittingtheinformation.
a.
Exceptions-thefollowingareexceptionsandcommunicationforthesepurposesdonotrequireemailtobesecure:CenterforBiologicsEvaluationandResearchSOPP8119Page4of9i.
RequestsforIndividualPatientINDsunderExpandedAccess,includingforemergencyuseandforoncologyproducts.
ii.
CompassionateUseIDEs.
iii.
RequestsforEmergencyUseAuthorizations(EUAs)andPre-EUAs.
iv.
Responsestorequestsforinformationthataregeneralinnature,suchasprovidinginformationinaguidancedocument,logisticalinformationabouthowtoattendameetingattheWhiteOakcampusorwheretofindinformationontheFDAwebsite.
v.
Emergencyalternativeproceduresorexemptionsunder21CFR640.
120.
b.
CBERstaffwillutilizeavailableinternalresourcestovalidatewhetheranyoneexternaltoFDAhasestablishedsecureemailwiththeAgency(refertoJA820.
05:SecureEmailVerificationandEmailBestPracticesforRegulatoryCommunicationsforinformation).
c.
RequeststoestablishsecureemailwithFDAshouldbesenttoSecureEmail@fda.
hhs.
gov.
B.
IncomingRegulatoryEmails1.
SubmissionsrequiredtobeinelectronicformatasdescribedinFDA'sguidancedocument"ProvidingRegulatorySubmissionsinElectronicFormat–SubmissionsUnderSection745A(a)oftheFederalFood,Drug,andCosmeticAct"shouldbesubmittedelectronicallyineCTDformatviatheElectronicSecureGateway(ESG).
Submissionsforbloodandbloodcomponents(notrequiredtobeineCTDformat)shouldbesubmittedasdirectedontheFDA'seSubmitterwebsite(https://www.
fda.
gov/ForIndustry/FDAeSubmitter/default.
htm).
2.
Formalsubmissions(e.
g.
,newINDs,originalBLAs,etc.
,),informationthatisunsolicited,orthatFDAdidnotagreetoreceiverelatedtopendingapplicationsarenottobetransmittedviaemail,unlessaserioussafetyissueisinvolved.
a.
Anysuchemailswillnotbeacceptedorincludedintheadministrativefile.
Regulatoryactions/decisionswillnotbemadebasedonthesetypesofemails.
CenterforBiologicsEvaluationandResearchSOPP8119Page5of9i.
TheCBERrecipientwillrespond(eitherbyteleconorviasecureemail)toacknowledgereceiptoftheemailandtoletthesponsor/applicantknowtheappropriatemeansofsubmission,e.
g.
,ESG,eSubmitter.
ii.
Emailsreceivedfromthesponsor/applicantandnotacceptedastheofficialdocumentarenottrackedinCBER'sregulatorydatabases.
iii.
SuchemailswillbedeletedfromOutlookmailboxesaftercontactingthesponsor/applicanttopreventinadvertentdisclosure.
iv.
CBERpersonnelshoulddiscouragesponsors/applicantsfromprovidingemailswithoutpriorapproval.
b.
Exception–CBERwillacceptformalINDsubmissionsviaemailforIndividualPatientUseundertheExpandedAccessprovisionsfoundat21CFR312.
310[alsoreferredtoassinglepatientexpandedaccess(SPIND)].
i.
Foroncologyproductrelatedsubmissionsthatarereceivedfrom"ProjectFacilitate,"CBERstaffmustfollowtheproceduresbelowforincomingregulatoryemailstoensureproperuploadingintoCBER'sEDRinatimelymanner.
ii.
SPINDssubmittedbyasponsor/investigatormaybeemailedtoCBERSPIND@fda.
hhs.
gov.
Allnewsubmissionsshouldbeclearlyidentifiedinthesubjectlineasanewrequest,e.
g.
,OriginalSubmissionSPIND.
AnysubsequentINDamendmentsshouldincludetheassignedINDnumberinthesubjectline,e.
g.
,AmendmenttoINDxxxxx.
3.
ForMDUFAsubmissions,includingBLAsubmissionsforIVDdevices,mostofwhicharesubjecttotheeCopyrequirementsformedicaldevicesasrequiredbySection745A(b)oftheFederalFood,Drug,andCosmeticAct(FD&CAct),addedbysection1136oftheFoodandDrugAdministrationSafetyandInnovationAct(FDASIA)(Pub.
L.
112-144),incomingemailswillbeacceptedandthenmanagedaccordingtoDCCProcedureGuide26:UseofEmailforRegulatoryCommunicationsexceptthatemailswithmanyorlargeattachmentsshouldbesubmittedonelectronicmediathroughDCC.
NotethatforMDUFAsubmissions,prioragreementontheacceptanceofincomingemailisimplicitbasedontheeCopyProgramforMedicalDeviceSubmissionsandotherguidancespertainingtomedicaldevicecommunications.
C.
OutgoingRegulatorySecureEmailsCenterforBiologicsEvaluationandResearchSOPP8119Page6of91.
CBERstaffwillsendoutgoingemailscontainingregulatoryinformation(seedefinitionabove)onlythroughsecureemailforallproducttypes,includingMDUFA/devicesubmissions.
2.
EmailsmustbesentfromofficialFDAemailaccountsonlyastheyaresecure.
3.
Theemail'ssubjectlinewillclearlydefinethetopicaddressedinthecommunicationandtherelatedsubmissiontrackingnumber(STN),ifassigned.
4.
CBERstaffisdiscouragedfromcreatingemailstringswhencommunicatinginformationtooutsideorganizationsregardingregulatoryinformation.
Ifanemailstringmustbeusedanditcontainsanattachmentwithinformationusedinregulatorydecisionmaking,theattachmentmustbeincludedinthefinaldocumentation.
5.
CBERgeneratedregulatorylettersthataresignedandlockedusingthePIVbadgemaybeissuedtothesponsor/applicantbysecureemail(refertoSOPP8116:UseofElectronicSignaturesforRegulatoryDocumentsandJA820.
01:GuideforCBER'sElectronicSignatureProcess).
Note:theemailwiththeletterattachedthatissenttotheapplicantorsponsorshouldnotbeuploadedtotheEDR.
6.
Outgoingsecureemailmaybeusedinplaceoftelephonecommunicationtorelayregulatoryissuesandrequestsforinformation.
7.
Communicationsviasecureemailshouldincludeonlyinformationpertinenttothereferencedapplicationorarelatedprecursorsubmission(e.
g.
,pre-INDorMasterFile).
Exceptionswouldincludeatrans-BLAorabundledsubmission,i.
e.
,multiplesubmissions"bundled"consistentwithMDUFAprovisionsforbundlingandthecitingofpredicates.
VI.
ResponsibilitiesA.
DocumentControlCenter(DCC)1.
Processanyemailsubmissions/amendmentsasappropriateforthesubmissiontype.
2.
Sendloadnotificationswhendocumentloadingiscomplete.
B.
RegulatoryProjectManager(RPM)1.
ProvideCBER'sDCCwithafullelectronicversionofemailsacceptedasregulatorysubmissions.
Note:thisonlyappliestosubmissionsnotrequiredtobeinelectronicformatasdescribedinPolicySectionB(2),above.
CenterforBiologicsEvaluationandResearchSOPP8119Page7of92.
EnsureallemailcommunicationsarecapturedintheappropriateregulatorydatabaseandimportedintoCBER'sEDR.
3.
Sendregulatorycommunicationsviasecureemailonlyandensurecorrectrecipientisselectedifauto-completefunctionofMSOutlookisused.
C.
CBERrecipients(ofemailsfromsponsors/applicants)andauthorsofsecureemail1.
IncludetheRPMonalloutgoingsecureemailspertainingtoaregulatorysubmission.
2.
Ensureemailisonlysenttorecipientsthathavesecureemailandthatcorrectrecipientisselectedifauto-completefunctionofMSOutlookisused.
3.
Provideinformationabouthowtoobtainsecureemailtothosethatneedinstructions(seeAppendixA).
4.
EnsureincomingemailsubmissionsmeettheacceptabilityrequirementsdescribedinthePolicySectionofthisSOPP.
5.
Respondtothesponsor/applicantintheappropriatetimeframesasdocumentedintheproceduressection.
6.
ForwardallemailsthatdidnotincludetheRPMofaregulatorysubmissionasanaddresseewithinonebusinessdaytotheRPMandremindthesponsor/applicanttoincludetheappropriateRPMonallfutureemails.
7.
Processinternalemailsthatcaptureregulatoryactionsordecisionsaspartoftheadministrativefile,i.
e.
,logthemintotheappropriateregulatorydatabaseandtheEDR.
8.
Documentallemailsappropriatelyasdescribedintheproceduressection.
9.
SetOut-of-Officereplieswithanavailablepointofcontactfortimeperiodsawayfromemailonedayormore.
VII.
ProceduresA.
IncomingRegulatoryEmails1.
Notifythesponsor/applicantbyphonewithinonebusinessdayofreceiptofanemailifitisinadequateorcannotberead.
CBERwillreachadecisiononwhethertheemailshouldberesent,rejected,referredtoDCC,orshouldbesubmittedinanotherformat.
[RPM,CBERrecipient]CenterforBiologicsEvaluationandResearchSOPP8119Page8of92.
Remindthesponsor/applicantthatallemailsshouldbesubmittedtotheappropriateRPM.
[CBERrecipient]a.
ForwardtheemailwithinonebusinessdaytotheRPMforprocessing.
[CBERrecipient]3.
IfCBERagreedtoacceptasubmissionastheofficialdocument,ifitisaMDUFAproductcommunicationorifitisanoncologyproductSinglePatientINDunderexpandedaccess,provideCBER'sDocumentControlCenter(DCC)withafullelectronicversionoftheemailperDCCProcedureGuide26:UseofEmailforRegulatoryCommunications.
[RPMordesignee]B.
OutgoingRegulatoryEmails1.
AlwaysincludetheRPMasacourtesycopy(cc:)onsecureemailssenttosponsors/applicantsrelatedtoaregulatorysubmissionandinformthesponsor/applicantinthesecureemailtoincludetheRPMonanyresponsesorfutureemails,iftheRPMwasnotincludedintheoriginalemail.
[CBERrecipient,author]2.
Determinetheappropriatecommunicationtypefortheemailfordataentrypurposes.
Emailswillbeenteredasteleconsonlyiftheinformationwouldgenerallyhavebeendiscussedinatelecon.
RefertoSOPP8104:DocumentationofTelephoneContactswithRegulatedIndustryforadditionalinformation.
[CBERrecipient,authororRPMordesignee]VIII.
AppendixA.
AppendixA:SecureEmailSetupIX.
ReferencesA.
ReferencesbelowareCBERInternal:1.
DCCProcedureGuide#22:ProcedureforProcessing,Routing,andStoringElectronicSubmissions2.
DCCProcedureGuide#26:UseofEmailforRegulatoryCommunications3.
JA820.
01:GuideforCBER'sElectronicSignatureProcess4.
JA820.
05:SecureEmailVerificationandEmailBestPracticesforRegulatoryCommunicationsB.
ReferencesbelowcanbefoundontheInternet:1.
21CFR601.
14CenterforBiologicsEvaluationandResearchSOPP8119Page9of92.
GuidanceforIndustryandReviewStaff:BestPracticesforCommunicationBetweenINDSponsorsandFDADuringDrugDevelopment3.
SOPP8104:DocumentationofTelephoneContactswithRegulatedIndustry4.
GuidanceforIndustryandFoodandDrugAdministrationStaff:TypesofCommunicationsDuringtheReviewofMedicalDeviceSubmissions5.
GuidanceforIndustryandFoodandDrugAdministrationStaff:eCopyProgramforMedicalDeviceSubmissions6.
SOPP8116:UseofElectronicSignaturesforRegulatoryDocumentsX.
HistoryWritten/RevisedApprovedByApprovalDateVersionNumberCommentMonserChristopherJoneckis,PhDFebruary17,20207RevisedtoexemptallrequestsforindividualpatientexpandedaccessINDsMonserChristopherJoneckis,PhDAugust26,20196RevisedtochangeemailpolicyforallsinglepatientINDsandcorrectedtypographicalerrors.
MartinChristopherJoneckis,PhDJune4,20195RevisedtochangeemailpolicyforoncologyproductSinglePatientINDsMonserChristopherJoneckis,PhDApril14,20194RevisedtobeconsistentwithSOPP8116RehkopfChristopherJoneckis,PhDSeptember27,20183RevisedtoincludeuseofsecureemailandupdateBPWG/RMCCRobertA.
Yetter,PhDFebruary11,20092RevisedtoincludeadditionalinformationonsecureemailThomasRobertA.
Yetter,PhDSeptember12,20081FirstIssuanceofthisSOPPCenterforBiologicsEvaluationandResearchSOPP8119AppendixAPage1of10SOPP8119AppendixA:SecureEmailSetupForFDAtosendregulatoryinformationviaemail,theemailmustbesenttoaSecureE-mailpartner,toallowFDAtodigitallysignandencryptthemessage.
RequeststoestablishsecureemailwithFDAshouldbesenttoSecureEmail@fda.
hhs.
gov.
AdequatetimeshouldbeallottedforSecureEmailset-upbeforeexpectingemailresponsesfromFDA.
TosetupsecureemailwiththeFDAyoumusthaveanon-ISPemaildomain.
Thus,@yahoo.
com,@gmail.
com,@hotmail.
com,@earthlink.
net,@verizon.
net,etc.
,accountscannotbesecured.
Ifyouhaveanon-ISPemaildomain:TherearetwowaystosecurelysendemailtoandfromtheFDA:1.
S/MIMEEncryptiona.
S/MIMEencryptionisdifficulttosetup,use,andmaintainaseverythingisdoneattheworkstationlevel.
Typically,yourcertificatewillneedtoberepurchased/renewedonce-a-year.
ThiswillrequirethenewcertificatetobeinstalledonyourworkstationandcoordinationwiththeFDAtoattachittoyourSecureEmailprofile.
Thus,overa5yearperiod,youwillswitchoutyourcertificate5times.
Ifyouchangeworkstationsorwhenyourenewyourdigitalcertificate,youroldcertificatesmustbepreservedotherwiseyouwilllosetheabilitytoreadoldencryptedemails.
IfyouhaveaBlackberry(orothermobiledevice),youwillnotbeabletoreadtheencryptedemailsunlessyouinstalltheBlackberry(orsimilar)S/MIMEapplicationandcopyyourcertificateover.
Anynewcertificateswillneedtobecopiedover.
ForeachFDAuserormailboxyouwishtosecurelycommunicatewith,aone-timesetupprocessisrequiredtocreateanFDAOutlookcontactandcorrespondingFDAproxycertificate.
S/MIMEissetuponaperuserbasis.
Thus,ifyouwish10ofyouruserstosendsecureemailtotheFDA,thentheyeachhavetobeconfiguredindividually.
Youremailservermayapplydisclaimersorlegalnoticesonalloutboundemails.
Anexceptionwillneedtobeappliedtotheemailserver'stransportruletoavoiddoingthiswhensendingtotheFDA.
ThereasonisdisclaimersaffecthowS/MIMEprotectedemailisrepackaged.
ThesealternationscannotbeprocessedcorrectlybytheFDAS/MIMEEmailFirewall.
Therefore,addthedisclaimersviayouremailclient(i.
e.
makeitpartofyourdefaultsignature.
)Ifyourorganizationrequiresthesedisclaimerstobeappendedbyyouremailserver,thenyoucannotuseS/MIMEandmustuseTLS.
CenterforBiologicsEvaluationandResearchSOPP8119AppendixAPage2of10b.
S/MIMEdoeshavethefollowingadvantages:Technicallyadeptuserscansetthisupthemselvesandnotinvolvetheiremailadministrators.
"End-to-end"encryptioncanbeachieved.
Thus,fromyouremailclienttoanFDAinternalS/MIMEEmailFirewall,themessageisencrypted.
Thisencryptionistypicallypreservedregardlessoftheintermediateinfrastructure.
EmailsenttoandreceivedfromtheFDAwillremainencryptedinyourInbox.
Thus,evenifyouremailsarestolen,theywillremainencrypted.
Aoneyeardigitalid(emailcertificate)foronepersonisaround$60.
Afterthecertificateispurchasedandinstalled,typicalsetupwithaknowledgeableITstaffisacouplehours.
Afterthefirstuserinyourorganizationissetup,theFDAS/MIMEinstructionscanbesharedanduserscansetupthemselves;nointerventionbytheFDAEmailTeamisrequired.
2.
SecureSMTPoverTLSencryptiona.
SecureSMTPoverTLSencryption(RFC3207)isfarsimplertosetupfromtheuserperspective.
Theconfigurationisdoneattheemailserverlevelandonlyinvolvesyouremailadministrator.
Itwillbeyouremailadministrator'sresponsibilitytoensurealltheintermediatelinksbetweenyourinfrastructureandtheFDA(andvice-versa)areTLSencrypted.
EveryoneatyourorganizationwillbeabletosendemailsecurelytotheFDA.
AoneyearDigiCertSSLcertificateis$175.
Athreeyearcertificateis$420.
Ifyourorganization'semailsystemisallinternal,thentotalsetuptimeis:-Certificatepurchaseandreceiptistypicallyonetotwodaysastheprovidermayneedtoperformverification.
-CertificateinstallationandTLSsetupwithaknowledgeableemailadministratorisacoupleofhoursandafewemails.
Ifpartsofyourorganization'semailsystemareoutsourced,thensetuptimemaybeconsiderablylongerascoordinationwithathirdpartyandmultiplelinksareinvolved.
S/MIMEInstructionsListedbelowisanoverviewofthestepsofsettingupS/MIMEencryptionwiththeFDA.
1.
TheFDAproxyS/MIMEserverhasbeentestedwiththefollowingclients:Windows10withOutlook2016TheseinstructionshavebeentestedwithWindows10andOutlook2016.
PreviousversionsofWindowsandOutlookhaveworked.
Therefore,youneedtoadapttheseinstructionstoyourparticularCenterforBiologicsEvaluationandResearchSOPP8119AppendixAPage3of10combinationofWindowsandOutlook.
Forassistance,pleasecontactyourlocalITHelpDeskresources.
MacOSX10.
12.
3(Sierra)withOutlook2016TheseinstructionshavebeentestedwithMacSierraandOutlook2016.
ItisunlikelypreviousversionsofOutlookwillworkcorrectly.
ItisunknownifpreviousversionsofMacwillwork.
Forassistance,pleasecontactyourlocalITHelpDeskresources.
2.
ObtainandinstalladigitalIDfromaCertificateAuthoritythathasagoodreputation(i.
e.
GlobalSign,DigiCert,etc.
)(IfalreadyhaveadigitalIDonanothercomputer,youshouldusethatcertificateanditsprivatekeyotherwiseyouwillnotbeabletoreadolder,encryptedemails.
)https://www.
globalsign.
com/secure-email/SHA256certificatesarethecurrentstandard.
IfyouhaveanolderSHA1certificatethathasnotyetexpired,youmaycontinuetousethat.
Ifyouarethefirstinyouremaildomain(i.
e.
@yourcompany.
com)torequestS/MIMESecureEmail,pleaseproceedtostep#3otherwise,proceedtostep#4.
Ifyouareunsureifyouarethefirstinyourcompany,youcanproceedwithstep#3.
3.
Sendadigitallysignedonly(noencryption)messageto:To:SecureEmail@fda.
hhs.
govSubject:S/MIMErequestSpecifythatyouwouldliketobeconfiguredtouseS/MIMEwiththeFDAWindows10+Outlook2016clientPresstheOptionstab,andthenpresstheSignbuttonMac10.
12.
3(Sierra)+Outlook2016clientsPresstheOptionstab,thenpressSecurityandthenselectDigitallySignMessageTheFDAEmailTeamwillthenconfigureinternalemailroutingtoallowyouremaildomaintosend/receiveemailfromtheFDAproxyS/MIMEsystem.
WhenyoureceiveconfirmationfromtheFDAEmailTeamthatthishasbeendone,pleaseproceedwiththenextstep…4.
Sendadigitallysignedonly(noencryption)messageto:To:cert-query@fda.
hhs.
govSubject:{theemailaddressoftheFDArecipientyouwishtosecurelycommunicatewith}Windows10+Outlook2016clientCenterforBiologicsEvaluationandResearchSOPP8119AppendixAPage4of10PresstheOptionstab,andthenpresstheSignbuttonMac10.
12.
3(Sierra)+Outlook2016clientsPresstheOptionstab,thenpressSecurityandthenselectDigitallySignMessageWithin5minutesyouwillreceiveanemailbackwithaproxyFDAcertificate…5.
Fromthatemail:Windows10+Outlook2016clientIfyouseeayellowtrianglewithanexclamationmarkontherightside:a.
Clickontheyellowtriangle,aDigitalSignatureInvaliddialogboxwillopen.
b.
IntheTrustingtheCertificateAuthority,clickTrustc.
IntheSecurityWarningdialogbox,readthewarningandifyouagree,clickYesd.
RestartOutlook.
IfyoudecidedearlierintheTrustingtheCertificateAuthoritynottoTrusttheFDACertificateAuthority,completethefollowingstepsforeveryFDAcontact:a.
Anewcontactwillopen,pressSavetheninViewSourceclickonOutlook(Contacts)b.
Alargecontactboxwillopenthathasmanyoptions.
Intheribbon,locatetheCertificatesbutton.
c.
Forthefda.
hhs.
gov(proxy)(Default)certificate,clickProperties,thentheTrusttab.
d.
InEditTrust,selectExplicitlyTrustthisCertificatethenOKIfyouseearedribbonontherightside:a.
Opentheemailandlocatethefromfieldandright-clickontheFDAperson'snameandselectAddtoOutlookContactsMac10.
12.
3(Sierra)+Outlook2016clients(https://technet.
microsoft.
com/en-us/library/jj984223(v=office.
16).
aspx)Ifyouseeayellowtrianglewithanexclamationmarkontheleftsidewiththemessage"Thesigningcertificateforthismessageisnotvalidortrusted"a.
ClickontheDetailsbuttonandselectViewSigningCertificateb.
IntheViewCertificatedialogbox,inthetoppane,clickonthefda.
hhs.
govcertificate,theninthebottompane,dragtherootCAcertificatetoyourdesktopCenterforBiologicsEvaluationandResearchSOPP8119AppendixAPage5of10c.
OpentheMacKeychainAccessapplet.
d.
Inthetopleftside,selectKeychains/loginandinthebottomleftside,selectCategory/Certificatese.
Draganddropthefda.
hhs.
gov.
cerrootCertificateintotherightpanef.
LocatethenewlycopiedcertificateandintheTrustsection,selectWhenusingthiscertificate:AlwaysTrustCenterforBiologicsEvaluationandResearchSOPP8119AppendixAPage6of10g.
Youmaybepromptedforuserusernameandpasswordtoauthorizethechange.
EnterthisandpressUpdateSettingsh.
CloseandrestartOutlook.
i.
TheemailthatwasreceivedearliershouldnolongerdisplaytheyellowtrianglewiththeexclamationmarkandinsteadshouldhaveapadlockandnotationThismessagewasdigitallysignedby…IfyouseeayellowtrianglewithanexclamationmarkontheleftsidewiththemessageThesigningcertificateforthismessageisnotvalidortrustedj.
ClicktheDetailsbuttonandselectAddEncryptionCertificatetoContactsk.
PressOK6.
YouarenowconfiguredtouseS/MIMEsecuredemailwithyourFDAcontact.
IMPORTANT:ItisyourresponsibilitytokeepyourS/MIMEcertificateup-to-date.
Ifyourcertificateexpires,itispossiblethatfutureemailsyoureceivefromtheFDAwillnolongerbeencrypted.
SMTPoverTLSInstructions:FoodandDrugAdministration(FDA)InstructionsforUsingSecureSMTPoverTLSTogetSecureSMTPoverTLS(EnforcedTLS/TLSRequire)workingbetweenyourorganizationandtheFoodandDrugAdministration(FDA),pleasefollowtheinstructionsbelow:Requirements1.
Yourorganization'sconnectionmustsupportSecureSMTPoverTLS(EnforcedTLS/TLSRequire)—TheFoodandDrugAdministration(FDA)onlysupportsSecureSimpleMailTransferProtocol(SMTP)overTransportLayerSecurity(TLS)(EnforcedTLS/TLSRequire)forsecureconnectionsbetweenyourorganizationandtheFDA.
MostmodernMTAsuse"OpportunisticTLS"or"TLSPreferred"whensendingemail.
OtherTLSconfigurationssuchasOpportunisticTLSorTLSPreferredarenotconsideredsecureemailfortworeasons:a.
OpportunisticTLSopensthepossibilityofman-in-the-middleattacks—RefertoRFC3207,Section6(http://www.
ietf.
org/rfc/rfc3207.
txt)b.
IfMessageTransferAgents(MTAs)aretoobusyorexceedtheirglobalTLSconnectionlimit,MTAscandropTLSandsendorreceivethemessageincleartextwhichisnotsecure.
Therefore,theFDAwillonlysupportSecureSMTPoverTLS(EnforcedTLS/TLSRequire)forsecureconnections.
CenterforBiologicsEvaluationandResearchSOPP8119AppendixAPage7of101.
Yourorganization'scertificatekeysmustbeofsufficientlengthtomeettheFIPS140-2requirementsandyourMTAmusthaveciphersuitesthatarecompatiblewithFIPS140-2.
Refertohttp://csrc.
nist.
gov/publications/PubsFIPS.
html.
PleaseNotethefollowing:Bydefault,Office365willuseopportunisticTLS–theFDAdoesnotconsiderthisconnectiontobesecure,andinsteadmandatestheuseofTLSrequired.
Pleaseseebelow–youshouldbeabletorequestthatyourhostsetupthenecessaryTLSrequiredconnectorstothevariousFDAdomains/sub-domains.
Asof12/13/2012,KeriosConnectdoesnotappeartosupport"TLSRequire"connection;organizationsusingthisemailserverwillneedtouseS/MIMEencryptioninstead.
InstructionsPleasereadthefollowinginstructionscarefullyandfollowthemtoensureasecureend-to-endconnectionbetweenyourcompanyandtheFDA.
1.
Forin-houseemailservers:OnyouremailserverormailapplianceobtainandinstallacommercialgradecertificatesuchasVerisignorThawte.
DigicertisalowercostalternativethatistrustedbyourMTA.
Donotuseaself-signedcertificateoraprivateCAsignedcertificate.
Inthefuture,theFDAwillbeenablingFIPS140-2ontheInternet-facingMTA's.
Therefore,youmustensurethatyourcertificatekeysaregeneratedwithsufficientlength.
IfusingRSAastheasymmetricalgorithm,youmustuseatleasta2048-bitkeysizewhengeneratingthepublic/privatekeys.
OnyourMTA,youmustensurethatyouhaveciphersuitesthatarecompatiblewithFIPS140-2.
http://csrc.
nist.
gov/publications/PubsFIPS.
htmlWheninstallingthecertificateitisimportanttoinstallanyintermediate/issuingCA's(therootcertisoptional).
Failuretoinstalltheintermediate/issuingCA'smayresultinacertificateverification/validationfailure:"unabletogetlocalissuercertificate".
Note:IfyouuseaBarracudaMTA,youmayneedtocombineyourleafandintermediate/issuingCAcertificatesintoasingle.
pemfile,installit,andthenreboottheappliance.
YourcertificateshouldhavethenamesspecifiedinyourexternalDNS.
Thus,ifyourexternalDNSnameissmtp.
pharma.
com,thatshouldbetheCommonNameand,ifyouusethem,oneoftheSubjectAlternativeNames.
Or,ifyouareusingmultipleemailservers,youcanuseawildcardcertificatebyspecifying*.
pharma.
comforyourCommonName.
TheFDAwillusetheMTA(s)specifiedinyourorganization'sMXrecordsandwillnotcreatespecialroutesto"TLSonly"MTA(s).
PartoftheverificationprocessistodoareverseDNSlookuponyourmailserver/appliancespecifiedbyyourorganization'sMXrecords.
Thus,ifsmtp.
pharma.
comisat100.
100.
15.
16,thenareverselookupofCenterforBiologicsEvaluationandResearchSOPP8119AppendixAPage8of10100.
100.
15.
16shouldreturnsmtp.
pharma.
com.
YoucanonlyhaveonePTRrecordperIPaddress.
YoumaywanttoverifyyourTLSconfigurationwithhttp://www.
checktls.
com/perl/TestReceiver.
pl.
Putyouremailaddressinandfor"LevelofOutput"select"CertDetail".
Addressanyissuesthatarehighlightedinyellow.
Oneproblemthiswebsitetoolhasisthatitdoesnotverifywildcardcertificates.
However,theFDA'sMTAwillacceptwildcardcertificates.
Therefore,althoughthiswebsite'sTLSverificationmethodsdifferslightlyfromtheFDA'smethods;itisusefulinidentifyingthemajorityofTLSproblems.
ItmaybehelpfultoexaminehowTLSissetup(MXrecords,Public-Keykeylength,etc.
)ontheFDA'sboundaryMTAs.
Toexaminethis,gotohttp://www.
checktls.
com/perl/TestReceiver.
pl,typein:SecureEmail@fda.
hhs.
govandfor"LevelofOutput",select"CertDetail".
TheFDAMTA'suseDigiCertcertificates.
ThisshouldbetrustedbymostMTA's.
However,ifyouneedtoinstalltherootcertificate,youcandownloadithere:https://www.
digicert.
com/CACerts/DigiCertGlobalRootCA.
crt2.
Certificates:Configureyourorganization'sMTAtouse"TLSrequire"whensendingtotheFDA.
ThefollowingaretheFDAnamespacesthatmayneedtobeconfiguredonacustomTLS"send"or"SMTP"connector(ifusingExchange)fda.
hhs.
govfda.
govcber.
fda.
govcder.
fda.
govcdrh.
fda.
govcfsan.
fda.
govcvm.
fda.
govnctr.
fda.
govoc.
fda.
govoci.
fda.
govora.
fda.
govAtthistimedonotconfigureMTLSwiththeFDA.
Thisisnotcurrentlysupported.
IfyouuseExchangeasyourinternet-edgeMTA,youmayfindthefollowinghelpful:TLSwithExchange2003:http://support.
microsoft.
com/kb/829721TLSwithExchange2007/2010:Ifyouconfigureacustom"TLSRequire"sendconnector,thenyouwillneedtorunthisPowerShellcommand:CenterforBiologicsEvaluationandResearchSOPP8119AppendixAPage9of10Set-SendConnector–identity"nameofconnector"-RequireTLS:$trueFollowingtherecommendationsinIETFRFC7525:MTAsmustnotnegotiateSSLv3(duetoPOODLErisk).
TLS1.
0and1.
1donotsupportsomeofthestrongciphers,shouldbeusedonlywhenTLS1.
2orhigherversionisnotavailable.
Implementationsshouldnotusesymmetricciphersuiteswithkeylengthlessthan256bits.
IncaseofRSA,theminimumis2048bits.
3.
OutsourcedServices:Isanypartofyouremailflow(sendingorreceiving)outsourcedIsyouremailhostedbya3rdpartyIfsothenyoumayneedtocontactyourproviderforassistance.
TheywillalsoneedtoensurethatanylinksthatconnectthroughtheInternetfromtheFDAtoyouareencrypted.
Forexample:SendingtotheFDAa.
Doyouusea"smarthost"onyourin-houseemailserverIfso,youshouldensurethattheconnectionbetweenyouremailserverandthesmarthostis"TLSRequire"(not"TLSPreferred")encrypted.
Also,thehopbetweenyour"smarthost"andtheFDAshouldalsobe"TLSRequire"encrypted(not"TLSPreferred").
Anylinksthatyour"smarthost"providerexposestotheInternetwhenroutingyouremailshouldalsobeencrypted.
b.
Ifyouremailserversarehosted,doesyouremailclienthaveanencryptedconnectiontothehostedemailserverAlso,youwillneedtocontactyouremailvendortoensurethatanyemailsenttotheFDAdomains(listedabove)issentonly"TLSRequire".
ReceivingfromtheFDATheFDAcanonlyguaranteethatthefirstlinkbetweentheFDAandtheserversspecifiedinyourpublicMXrecordsare"TLSRequire"encrypted,beyondthatitisyourresponsibilitytoensuretheremaininglinksareencrypted.
Thus:a.
WheredoyourDNSMXrecordspointIftheypointtooutsourcedservers,youwillneedtocontactthevendortoensurethatwhentheyrouteyouremailovertheInternetthatthepathisover"TLSRequire"links.
ThesamewouldapplyifyourMXrecordspointtooutsourcedanti-virus/anti-spamservers.
Whentheydelivertheemailtoyou,itshouldbedoneover"TLSRequire"links.
IfyouuseGoogleGSuite,pleasenotethefollowing:https://support.
google.
com/a/answer/2520500hl=enKeepinmindthatwheneveryouswitchemailand/oranti-malwareprovidersthattheaboveprecautionsareadheredto.
ThiswillensurethatanyInternetlinksareencrypted.
CenterforBiologicsEvaluationandResearchSOPP8119AppendixAPage10of10IfyourproviderrequiresanyinformationonhowtheFDAisconfigured(CertificateAuthorityused,certificatekeysize,IPaddresses,etc.
),thengotohttp://www.
checktls.
com/perl/TestReceiver.
pl,typein:SecureEmail@fda.
hhs.
govandfor"LevelofOutput"select"CertDetail".
4.
TestMessagetoFDA:Sendmeanemailindicatingthe"TLSRequire"hasbeensetupoutgoingtoFDA.
Checkyourmessagetrackinglogs.
IfthemessagefailstogetdeliveredtotheFDA,recheckyourconfiguration.
5.
TestMessagefromFDA:WhenIreceivethatemail,andafteryourconfigurationisverified,IwillcorrespondinglyswitchtheFDA'soutgoingconnectiontoyourorganizationto"TLSRequire"andsendyouanemail.
Ifthereareanyissues,Iwilldroptheconnectionbackto"TLSPreferred"andcontactyou.
6.
S/MIMEUsage:IfTLSisworkingandyouarecurrentlyusingproxyS/MIMEwiththeFDA:a.
YourS/MIMEsecureemailconfigurationwillberemovedfromtheFDAservers.
b.
YouwillneedtoremovetheFDAproxycertificatefromyourusers'OutlookFDAcontacts(iftheseexist)andinstructyourusersnottopress"encrypt"whensendingtotheFDAasencryptionwillbehandledautomaticallyfromtheserver-side.
CertificateRenewalReminder:Asasuggestion,youmaywanttocreateacalendarreminderonemonthbeforeyourTLScertificateisduetoexpire.
Thistimeframewouldbesufficienttimetorenewandinstallyournewcertificate.

香港 1核1G 29元/月 美国1核 2G 36元/月 快云科技

快云科技: 11.11钜惠 美国云机2H5G年付148仅有40台,云服务器全场7折,香港云服务器年付388仅不到五折 公司介绍:快云科技是成立于2020年的新进主机商,持有IDC/ICP/ISP等证件资质齐全主营产品有:香港弹性云服务器,美国vps和日本vps,香港物理机,国内高防物理机以及美国日本高防物理机官网地址:www.345idc.com活动截止日期为2021年11月13日此次促销活动提供...

LOCVPS-2021年6月香港便宜vps宽带升级,充值就送代金券,其它八折优惠!

LOCVPS怎么样?LOCVPS是一家成立于2011年的稳定老牌国人商家,目前提供中国香港、韩国、美国、日本、新加坡、德国、荷兰等区域VPS服务器,所有机房Ping延迟低,国内速度优秀,非常适合建站和远程办公,所有机房Ping延迟低,国内速度优秀,非常适合做站。XEN架构产品的特点是小带宽无限流量、不超售!KVM架构是目前比较流行的虚拟化技术,大带宽,生态发展比较全面!所有大家可以根据自己业务需求...

2022年最新PHP短网址生成系统/短链接生成系统/URL缩短器系统源码

全新PHP短网址系统URL缩短器平台,它使您可以轻松地缩短链接,根据受众群体的位置或平台来定位受众,并为缩短的链接提供分析见解。系统使用了Laravel框架编写,前后台双语言使用,可以设置多域名,还可以开设套餐等诸多功能,值得使用。链接: https://pan.baidu.com/s/1ti6XqJ22tp1ULTJw7kYHog?pwd=sarg 提取码: sarg文件解压密码 www.wn7...

globalsign为你推荐
域名备案查询如何查网站备案信息网络服务器租用租网络服务器在哪些平台比较合适?vps试用求个免费现成的vps(可永久可试用)什么是虚拟主机什么是“虚拟主机”?请解释祥细些!虚拟主机软件问虚拟主机用什么版本的软件比较好虚拟主机mysql如何连接虚拟主机中的MYSQL美国虚拟主机购买美国虚拟主机在国内那家卖的便宜,稳定,功能全??西安虚拟主机西安云主机/云主机与vps有哪些区别虚拟主机试用30天需要一个免费的虚拟主机,稳定的域名网怎么样申请网站域名?
域名备案只选云聚达 warez 樊云 hawkhost优惠码 themeforest 视频存储服务器 la域名 免费ftp空间 表单样式 全能主机 域名转向 服务器维护方案 工信部icp备案号 169邮箱 adroit qq云端 vip购优惠 最好的qq空间 免费dns解析 如何安装服务器系统 更多