콘텐츠로 이동

S/MIME 지원

BlueMail의 S/MIME 지원은 디지털 서명 및 암호화된 이메일을 보내고 받을 수 있게 해 주므로 수신자는 메시지가 정말로 당신으로부터 왔다는 것을 입증할 수 있고, 민감한 메일은 수신자에게만 읽을 수 있습니다.

Where S/MIME lives

Go to Settings | Privacy & Security | End-to-End Encryption, then tap S/MIME Encryption & Signing and choose the account you are setting up. The same screen holds PGP Encryption if you use that instead; see PGP keys.

S/MIME is part of BlueMail Enterprise. Where it is not yet included, the screen shows an Enterprise license required note with a Billing link.

Adding your certificate

BlueMail uses .p12 and .pfx certificate files, and there are two slots on the account: Signing certificate and Encryption certificate. Tap Select… beside either one, pick your file, and enter the password that protects it at the Certificate password prompt. Many certificates cover both jobs, in which case you import the same file into both slots.

Once imported, BlueMail shows the certificate's validity dates and its SHA-256 fingerprint so you can confirm you loaded the right one.

The certificate has to be issued to the same address as the account. If it is not, BlueMail says so directly rather than leaving you to guess.

Step by step for your platform: iPhone and iPad · Android · Windows · Mac · Linux

Rolling S/MIME out to managed devices

On BlueMail Enterprise, nobody needs to handle certificate files by hand. An administrator can deliver each user's S/MIME identity with the app itself, through iOS Managed App Configuration or Android Enterprise managed configurations, so staff open BlueMail with signing and decryption already working. No file to distribute, and no password passed around.

BlueMail matches a pushed certificate to the right account by the email address inside the certificate, so it reaches the correct mailbox without per-device setup. The import runs once and is then skipped, so reopening the app never repeats it, while publishing a replacement at renewal rolls the new certificate out on its own.

For administrators. Managed configuration is part of BlueMail Enterprise and is switched on for your organization as part of setting you up, so arrange it with your BlueMail contact first. It is enabled per customer rather than being on for everyone. Once live for your tenant, set these keys in the configuration you deliver to BlueMail:

KeyTypeWhat it does
enableSmimebooleanGrants the S/MIME entitlement to the account
smimeP12stringThe identity, as a base64-encoded .p12
smimeP12PasswordstringThe password protecting that .p12

enableSmime is the managed equivalent of the license grant, so a managed device needs no separate entitlement. Booleans may be sent as real booleans or as the strings "true" and "false".

The same channel carries BlueMail's other managed settings, so S/MIME goes out alongside the rest of your policy in one payload. For the full and current list, and example payloads for your console, see Can I deploy BlueMail with MDM?.

The two platforms differ only in timing: Android broadcasts restriction changes, so BlueMail picks up a new configuration as soon as your EMM applies it, while iOS re-reads it when BlueMail next comes to the foreground.

Signing or encrypting a message

When you compose, a security button sits to the right of the Subject line. Tap it for the S/MIME encryption sheet and pick how to send this particular email:

  • None: 서명이나 암호화 없이 발송
  • Sign: 수신자에게 당신의 정체성을 확인시키기
  • Encrypt: 키가 있는 수신자만 읽을 수 있음
  • Sign & Encrypt: 권장

초기 기본 설정으로, S/MIME 화면에서 Outgoing mail에 대한 기본 동작을 사용합니다: 모든 발신 메시지에 디지털 서명, 모든 수신자가 S/MIME를 지원하는 경우 기본으로 암호화, 그리고 호환을 위해 서명된 사본을 보내기.

암호화에는 수신자의 인증서가 필요합니다. BlueMail은 메시지를 보낼 때 이를 조회하고, 하나가 사용 가능하지 않으면 보낼 수 없는 수신자를 대신에 Missing S/MIME certificates 아래에 이름을 표시합니다. 가장 쉬운 방법은 서명된 메일을 교환하여 보내는 것이므로, 서명된 메일은 발신자의 인증서를 함께 담고 있습니다.

Signed 및 encrypted 메일 읽기

메시지 헤더에는 BlueMail가 확인되었다는 배지가 표시됩니다: Signed, Encrypted, Signed & Encrypted, 또는 서명이 신뢰할 수 있는 기관과 연결될 수 없을 때는 Signed · unverified sender. 그것을 탭하면 S/MIME Message Information이 열리고, 서명 또는 복호화한 메시지를 서명한 인증서와 그 지문을 보여줍니다.

신뢰할 수 있는 CAs

다른 사람의 서명 확인은 그것들을 발급한 기관을 신뢰하는 데서 비롯됩니다. Trusted CAs 섹션이 이를 처리하며, 자체 .p12을 가져오는 것도 발급 체인을 신뢰하게 하며, 일반적으로 발급기관을 공유하는 동료를 포함합니다. 다른 사람의 경우, Import CA certificate를 탭하고 그들의 .pem 또는 .cer 파일을 선택합니다.

이것이 바로 암호화를 가능하게 만드는 핵심이며, 단지 정리만은 아닙니다. BlueMail은 발신자의 인증서를 보관하고, 서명된 메시지가 도착했을 때도 신뢰할 수 있는 기관과 대조되어 확인됩니다. 따라서 그 발급기관이 이 목록에 없으면 인증서는 보관되지 않으며, 그 사람에게 암호화하는 것도 그들이 보낸 서명된 메시지가 아무리 많아도 사용할 수 없게 남습니다. 그들의 CA를 한 번 가져오면 두 가지를 동시에 해결할 수 있습니다: 그들의 서명이 확인되기 시작하고, 당신은 그들에게 암호화를 시작할 수 있습니다.

주의가 필요한 경우

  • 서명이 확인되지 않는 것으로 표시됩니다. BlueMail가 원인을 아래에 제시하며, 보통은 "서명의 인증서는 신뢰할 수 있는 기관에서 발급되지 않았습니다. 신뢰하도록 그 CA를 가져오세요." 같은 해결 방법을 가리킵니다. 다른 이유로는 발신자와 주소가 일치하지 않거나, 인증서가 만료되었거나 아직 유효하지 않거나 이메일에 사용 승인되지 않은 경우가 있습니다.
  • 임포트가 적용되지 않았습니다. BlueMail는 *"가져오기 실패. 비밀번호가 잘못되었거나 파일이 유효한 인증서가 아닙니다."*를 보고합니다. 인증서 비밀번호는 대소문자를 구분합니다; 비밀번호를 잃어버리면 인증서 공급자에게 새 파일을 요청하세요.
  • 누군가에게 암호화할 수 없습니다. 그들에게 먼저 서명된 이메일을 보내 달라고 요청하고, 그들의 인증서는 함께 옵니다.