AS2 Encryption
AS2 supports encryption of both the message itself and the connection carrying it. Message encryption protects the payload for its intended recipient; HTTPS protects the transmission between endpoints. Agree with your trading partner on message encryption and signature requirements separately, because encrypting a message does not establish who signed it.
Message Encryption
Message level encryption is implemented using S/MIME. S/MIME (Secure/Multipurpose Internet Mail Extensions) is a standard for public-key encryption and signing of MIME data.
Files.com signs outgoing messages using your AS2 identity's private key and encrypts them using your trading partner's public AS2 certificate. Your partner uses their private key to decrypt the message and your public certificate to validate its signature.
Incoming messages can be signed or unsigned, with or without S/MIME message encryption. This allows Files.com to receive the message format agreed with your partner. The partner's incoming signature validation level determines whether a valid signature is required; it does not require message encryption. Normal requires a valid signature even when the message is encrypted, while None permits unsigned messages.
When message encryption is used, the payload remains encrypted independently of the connection carrying it. Without S/MIME message encryption, the HTTPS connection still protects the transmission, but the message itself has no separate S/MIME encryption.
Transmission Encryption
Transmission level encryption is implemented using HTTPS (HTTP over a TLS/SSL encrypted connection).
The connection to the AS2 endpoint uses an AS2 endpoint SSL certificate and TLS/SSL ciphers to protect data in transit. HTTPS transport encryption is independent of whether the AS2 message is encrypted or signed.
The AS2 endpoint of your Files.com sites will use the same certificate and ciphers as your site's web portal (https://MYSITE.files.com) and custom domain.