BlueMail's S/MIME support lets you send and receive digitally signed and encrypted email, so your recipients can prove a message really came from you, and sensitive mail can be read only by the person it was addressed to.
Where S/MIME lives
Go to Settings | Privacy & Security | End-to-End Encryption, then tap S/MIME Encryption & Signing and choose the account you are setting up. The same screen holds PGP Encryption if you use that instead; see PGP keys.
S/MIME is part of BlueMail Enterprise. Where it is not yet included, the screen shows an Enterprise license required note with a Billing link.
Adding your certificate
BlueMail uses .p12 and .pfx certificate files, and there are two slots on the account: Signing certificate and Encryption certificate. Tap Select… beside either one, pick your file, and enter the password that protects it at the Certificate password prompt. Many certificates cover both jobs, in which case you import the same file into both slots.
Once imported, BlueMail shows the certificate's validity dates and its SHA-256 fingerprint so you can confirm you loaded the right one.
The certificate has to be issued to the same address as the account. If it is not, BlueMail says so directly rather than leaving you to guess.
Step by step for your platform: iPhone and iPad · Android · Windows · Mac · Linux
Rolling S/MIME out to managed devices
On BlueMail Enterprise, nobody needs to handle certificate files by hand. An administrator can deliver each user's S/MIME identity with the app itself, through iOS Managed App Configuration or Android Enterprise managed configurations, so staff open BlueMail with signing and decryption already working. No file to distribute, and no password passed around.
BlueMail matches a pushed certificate to the right account by the email address inside the certificate, so it reaches the correct mailbox without per-device setup. The import runs once and is then skipped, so reopening the app never repeats it, while publishing a replacement at renewal rolls the new certificate out on its own.
For administrators. Managed configuration is part of BlueMail Enterprise and is switched on for your organization as part of setting you up, so arrange it with your BlueMail contact first. It is enabled per customer rather than being on for everyone. Once live for your tenant, set these keys in the configuration you deliver to BlueMail:
| Key | Type | What it does |
|---|---|---|
enableSmime | boolean | Grants the S/MIME entitlement to the account |
smimeP12 | string | The identity, as a base64-encoded .p12 |
smimeP12Password | string | The password protecting that .p12 |
enableSmime is the managed equivalent of the license grant, so a managed device needs no separate entitlement. Booleans may be sent as real booleans or as the strings "true" and "false".
The same channel carries BlueMail's other managed settings, so S/MIME goes out alongside the rest of your policy in one payload. For the full and current list, and example payloads for your console, see Can I deploy BlueMail with MDM?.
The two platforms differ only in timing: Android broadcasts restriction changes, so BlueMail picks up a new configuration as soon as your EMM applies it, while iOS re-reads it when BlueMail next comes to the foreground.
Signing or encrypting a message
When you compose, a security button sits to the right of the Subject line. Tap it for the S/MIME encryption sheet and pick how to send this particular email:
- None: trimite fără semnare sau criptare
- Sign: verifică-ți identitatea pentru destinatari
- Encrypt: doar destinatarii cu o cheie pot citi
- Sign & Encrypt: recomandat
Pentru o preferință constantă, folosește Comportament implicit pentru e-mailul iesean pe ecranul S/MIME: Semnează digital toate mesajele de ieșire, Criptarea implicită atunci când toți destinatarii sprijină S/MIME, și Trimite copii semnate pentru compatibilitate.
Criptarea necesită certificatul destinatarului. BlueMail caută aceste certificate pe măsură ce abordezi mesajul, și dacă unul lipsește numește acel destinatar sub Lipsă certificate S/MIME în loc să trimită e-mail pe care nu l-ar putea deschide. Cea mai ușoară modalitate de a construi certificate este să schimbi e-mailuri semnate, deoarece un mesaj semnat poartă certificatul expeditorului cu el.
Citirea e-mailurilor semnate și criptate
Antetul mesajului poartă o insignă care spune ce a verificat BlueMail: Semnat, ** Criptat**, Semnat și criptat, sau Semnat · expeditor neverificationat când semnătura nu poate fi încă legată de o autoritate de încredere. Apasă pe ea pentru Informații despre mesaj S/MIME, care numește certificatul care a semnat sau decriptat mesajul și arată amprenta acestuia.
CAA de încredere
Averificarea semnăturilor altor persoane se bazează pe încrederea în autoritatea care a emis acestea. Secțiunea CAA de încredere gestionează acest lucru, iar importul propriului .p12 încurajează lanțul său de emitere, care de obicei acoperă colegii care împărtășesc emitentul tău. Pentru oricine altcineva, tapă c Importă certificatul CA și alege fișierul lor .pem sau .cer.
Acesta este ceea ce face criptarea posibilă, nu doar ordonat. BlueMail păstrează certificatul expeditorului atunci când mesajul lor semnat sosește și semnătura verifică față de o autoritate în care ai încredere. Așadar dacă emitentul lor nu este în această listă, certificatul nu este păstrat, iar criptarea către acea persoană rămâne indisponibilă oricât de multe mesaje semnate trimit. Importarea CA-ului lor o dată rezolvă ambele în același timp: semnăturile încep să apară ca verificate, iar poți începe să criplezi către ei.
Dacă ceva necesită atenție
- O semnătură apare ca neverificată. BlueMail oferă motivul în jos, și indică la remediere, cel mai adesea " Certificatul expeditorului nu este dintr-o autoritate de încredere. Importă CA-ul său pentru a-l încredința." Alte motive includ o adresă care nu se potrivește cu expeditorul, și un certificat expirat, nu valid încă sau neautorizat pentru e-mail.
- O importare nu a avut efect. BlueMail raportează "Importul a eșuat. Parola poate fi incorectă, sau fișierul nu este un certificat valid." Parolele pentru certificate sunt sensibile la capitalizare; dacă parola este pierdută, cere furnizorului tău de certificate un fișier nou.
- Nu poți cripta către cineva. Roagă-i să-ți trimită mai întâi un e-mail semnat, iar certificatul lor vine împreună cu el.