इसे छोड़कर कंटेंट पर जाएं

S/MIME समर्थन

BlueMail's S/MIME सपोर्ट आपको digitally signed और encrypted ईमेल भेजने और प्राप्त करने की अनुमति देता है, ताकि आपके प्राप्तकर्ता यह प्रमाणित कर सकें कि संदेश वास्तव में आपसे आया है, और संवेदनशील मेल केवल उसी व्यक्ति के लिए पढ़ी जा सके जिसे वह संबोधित किया गया था।

Where S/MIME lives

Go to Settings | Privacy & Security | End-to-End Encryption, फिर tap S/MIME Encryption & Signing and choose the account you are setting up. The same screen holds PGP Encryption if you use that instead; see PGP keys.

S/MIME is part of BlueMail Enterprise. Where it is not yet included, the screen shows an Enterprise license required note with a Billing link.

Adding your certificate

BlueMail uses .p12 and .pfx certificate files, and there are two slots on the account: Signing certificate and Encryption certificate. Tap Select… beside either one, pick your file, and enter the password that protects it at the Certificate password prompt. Many certificates cover both jobs, in which case you import the same file into both slots.

Once imported, BlueMail shows the certificate's validity dates and its SHA-256 fingerprint so you can confirm you loaded the right one.

The certificate has to be issued to the same address as the account. If it is not, BlueMail says so directly rather than leaving you to guess.

Step by step for your platform: iPhone and iPad · Android · Windows · Mac · Linux

Rolling S/MIME out to managed devices

On BlueMail Enterprise, nobody needs to handle certificate files by hand. An administrator can deliver each user's S/MIME identity with the app itself, through iOS Managed App Configuration or Android Enterprise managed configurations, so staff open BlueMail with signing and decryption already working. No file to distribute, and no password passed around.

BlueMail matches a pushed certificate to the right account by the email address inside the certificate, so it reaches the correct mailbox without per-device setup. The import runs once and is then skipped, so reopening the app never repeats it, while publishing a replacement at renewal rolls the new certificate out on its own.

For administrators. Managed configuration is part of BlueMail Enterprise and is switched on for your organization as part of setting you up, so arrange it with your BlueMail contact first. It is enabled per customer rather than being on for everyone. Once live for your tenant, set these keys in the configuration you deliver to BlueMail:

KeyTypeWhat it does
enableSmimebooleanGrants the S/MIME entitlement to the account
smimeP12stringThe identity, as a base64-encoded .p12
smimeP12PasswordstringThe password protecting that .p12

enableSmime is the managed equivalent of the license grant, so a managed device needs no separate entitlement. Booleans may be sent as real booleans or as the strings "true" and "false".

The same channel carries BlueMail's other managed settings, so S/MIME goes out alongside the rest of your policy in one payload. For the full and current list, and example payloads for your console, see Can I deploy BlueMail with MDM?.

The two platforms differ only in timing: Android broadcasts restriction changes, so BlueMail picks up a new configuration as soon as your EMM applies it, while iOS re-reads it when BlueMail next comes to the foreground.

Signing or encrypting a message

जब आप लिखते हैं, तो सुरक्षा बटन Subject लाइन के दाईं तरफ रहता है। इसे टैप करके S/MIME encryption शीट खोलें और चुनें कि इस विशिष्ट ईमेल को कैसे भेजना है:

  • None: sign या encryption के बिना भेजें
  • Sign: प्राप्तकर्ताओं के लिए अपनी पहचान सत्यापित करें
  • Encrypt: केवल जिनके पास कुंजी है वही पढ़ सकता है
  • Sign & Encrypt: अनुशंसित

स्थाई प्राथमिकता के लिए, S/MIME स्क्रीन पर Outgoing mail के लिए Default behavior का उपयोग करें: सभी आउटगोइंग संदेशों पर डिजिटल हस्ताक्षर करें, जब सभी प्राप्तकर्ता S/MIME का समर्थन करें तो डिफ़ॉल्ट रूप से संदेशों को Encrypt करें, और सुरक्षा के लिए स्पष्ट-हस्ताक्षरित प्रतियाँ भेजें

एन्क्रिप्शन को प्राप्तकर्ता के प्रमाणपत्र की आवश्यकता है। BlueMail इन्हें संदेश को संबोधित करते समय खोजता है, और यदि कोई उपलब्ध नहीं है तो वह उस प्राप्तकर्ता को बताता है कि Missing S/MIME certificates के तहत संदेश खोला नहीं जा सकता। प्रमाणपत्र बनाने का सबसे आसान तरीका है हस्ताक्षरित मेल का आदान-प्रदान करना, क्योंकि एक हस्ताक्षरित संदेश में Sender का certificate उसके साथ ही आता है।

Reading signed and encrypted mail

संदेश हेडर एक बैज दिखाता है जो बताता है कि BlueMail सत्यापित है: Signed, Encrypted, Signed & Encrypted, या Signed · unverified sender जब हस्ताक्षर अभी भी एक trusted authority से जुड़ा नहीं हो पाया हो। इसे टैप करें ताकि आप पढ़ें S/MIME Message Information, जो वह प्रमाणपत्र बताता है जिसने संदेश पर हस्ताक्षर किया या उसे डिक्रिप्ट किया और उसकी फिंगरप्रिंट दिखता है।

Trusted CAs

दूसरे लोगों के हस्ताक्षर सत्यापित करने के लिए उस authority पर निर्भरता आवश्यक है जिसने उन्हें जारी किया है। Trusted CAs अनुभाग इसे संभालता है, और अपनी own .p12 को आयात करना भी इसकी जारी करने की श्रृंखला भरोसेमंद मानी जाती है, जो सामान्यतः उन सहकर्मियों को कवर करता है जो आपके issuer को साझा करते हैं। किसी और के लिए, टैप करें Import CA certificate और उनके .pem या .cer फ़ाइल चुनें।

यह वही बात है जो encryption संभव बनाती है, न कि सिर्फ साफ-सुथरा। BlueMail एक संदेश के arrive होते ही sender के certificate को बनाए रखता है और signature एक authority पर भरोसा कर सत्यापित हो जाए तो। इसलिए यदि उनका issuer इस list में नहीं है, तो certificate को रखा नहीं जाएगा, और उस व्यक्ति के लिए encryption भी तब तक असंभव रहती है जब तक कि उनके signatures सत्यापित न हो जाएं। एक बार उनके CA को आयात करने से दोनों एक ही समय में ठीक हो जाते हैं: उनके signatures सत्यापित के रूप में पढ़ने लगते हैं, और आप उनके लिए encryption शुरू कर सकते हैं।

If something needs attention

  • A signature shows as unverified. BlueMail कारण बताता है, और यह अक्सर ठीक करने के लिए "The signer's certificate isn't from a trusted authority. Import its CA to trust it." के कारण होता है। अन्य कारणों में वह पता शामिल है जो sender से मेल नहीं खाता, और एक certificate जो expired हो गया हो, अभी मान्य नहीं हो, या ईमेल के लिए अधिकृत नहीं हो।
  • An import did not take. BlueMail बताता है "Import failed. The password may be incorrect, or the file isn't a valid certificate." Certificate passwords case-sensitive होते हैं; अगर password खो गया हो, तो अपने certificate provider से fresh file माँगें।
  • You cannot encrypt to someone. उनसे पहले signed ईमेल भेजने के लिए कहें, और उनके साथ उसका certificate आता है।