SMIME support in Email+ for Android for identity and encryption
8 min
email+ for android supports smime (secure multipurpose internet mail extensions) s mime allows device users to do the following digitally sign emails so that the email can be verified by the recipient verify digitally signed emails send encrypted emails using the recipient's smime encryption certificate decrypt smime encrypted emails using a configured smime encryption certificate using these smime features requires that device users import an smime certificate into email+ you can use one of the following methods to import the smime certificates importing certificates to email+ for android using app specific configuration docid\ eewgjmotv28 ptbe5cpxm importing certificates using email attachments docid\ eewgjmotv28 ptbe5cpxm the following describes smime behavior in email+ smime behavior in email+ docid\ eewgjmotv28 ptbe5cpxm importing certificates to email+ for android using app specific configuration for the best user experience, use app specific configuration to make email+ automatically import a signing certificate and encryption certificate this method does not require user action configuring s/mime certificates for android appconnect (ivanti epmm) docid\ eewgjmotv28 ptbe5cpxmconfiguring smime certificates for android appconnect (ivanti neurons for mdm) docid\ eewgjmotv28 ptbe5cpxmconfiguring smime certificates for email+ for android enterprise (ivanti epmm and ivanti neurons for mdm) docid\ eewgjmotv28 ptbe5cpxm configuring s/mime certificates for android appconnect (ivanti epmm) the following describes the configuration in ivanti epmm procedure in the ivanti epmm admin portal, go to \<font color="#323232">policy \& configs \> configurations\</font> select the appconnect app configuration for email+ for android, and click edit in app specific configurations, add the following key value pairs email signing certificate from the dropdown list, select the certificate enrollment setting you want to use to sign the email email encryption certificate from the dropdown list, select the identity certificate setting you want to use to encrypt the email click \<font color="#323232">save\</font> related topics the key value pairs are described in key value pairs for configuring email+ for android appconnect app behavior docid\ fqckqtshskvvfvl0nwfe3 configuring smime certificates for android appconnect (ivanti neurons for mdm) the following describes the configuration in ivanti neurons for mdm procedure in ivanti neurons for mdm, go to \<font color="#323232">apps \> app catalog \</font> and click on email+ for android (appconnect \<font color="#323232">)\</font> go to app configurations > email+ configuration click on the email+ configuration you want to edit, and click edit in appconnect certificate configuration, add the following key value pairs email signing certificate from the dropdown list, select the identity certificate setting you want to use to sign the email email encryption certificate from the dropdown list, select the identity certificate setting you want to use to encrypt the email click \<font color="#323232">update\</font> to save the settings related topics the key value pairs are described in key value pairs for configuring email+ for android appconnect app behavior docid\ fqckqtshskvvfvl0nwfe3 configuring smime certificates for email+ for android enterprise (ivanti epmm and ivanti neurons for mdm) the following describes the configuration for android enterprise the procedure is applicable in ivanti epmm and ivanti neurons for mdm procedure edit the email+ for android for work configuration configure the email signing certificate and email encryption certificate restrictions save the settings related topics ivanti email+ for android enterprise app configuration and distribution docid 8s2f4gmp02vr3 wqw44o2 app restrictions descriptions for ivanti email+ (android enterprise) docid\ klqsw tckaeewrj5azg1a importing certificates using email attachments using app specific configuration you can set up email+ to automatically import a signing certificate and encryption certificate alternatively, users can send themselves the certificate in an email this section describes how users can email the certificates and import the certificate into the keystore procedure from a computer, users can an email themselves, as an attachment, the certificate that they use for s/mime on their computers this certificate must be a pfx file users open the email using email+ on the device, and tapsto open the attachment email+ prompts users for the certificate’s password users enter the certificate’s password email+ imports the certificate into its keystore related topics importing certificates to email+ for android using app specific configuration docid\ eewgjmotv28 ptbe5cpxm smime behavior in email+ email+ does the following with the smime encryption key it receives imports the key into the keystore selects the certificate as the encryption certificate if you change the certificate, email+ imports the new certificate into the keystore and selects the new certificate as the encryption certificate it leaves the previous certificate in the keystore if you remove the restriction, email+ leaves the certificate in the keystore it changes its settings to specify that no certificate is selected as the encryption certificate using the email+ user interface, the device user can change the encryption certificate by manually importing one and selecting it for use encrypt all emails with the certificate or encrypt a specific email with the certificate note that email+ automatically encrypts emails if the emails in the thread are encrypted to send an encrypted email, a user needs the recipient’s public key if you provide users’ public keys in the active directory, email+ uses global address lookup to retrieve a public key as needed another way for a user to have the public key of another user is possible, but more limiting specifically, if a user receives a signed email, and the signing certificate is the same as the encryption certificate, email+ now has the sender’s public key the user can now send an encrypted email to the user who sent the signed email make sure users’ encryption certificates are the same on all devices a user needs his private key and certificate to read encrypted emails the encryption key and certificate must be the same on all email clients using s/mime, including desktop email clients when an encryption key/certificate is renewed, the existing email on a device cannot be decrypted unless the original key certificate is available keep a backup copy of the encryption key and certificate or consider using a third party escrow service to restore an encryption key and certificate from a backup, the user can send himself the key/certificate as an email attachment, as described in the following section fetching certificates from gal email+ fetches all available certificates for recipients from gal while sending encrypted email, if the certificate is not found in gal the email+ app fetches the certificate from keystore
