S/MIME support in Ivanti Email+ for iOS
7 min
ivanti email+ for ios includes support for secure/multipurpose internet mail extensions (s/mime) this functionality provides the following features the device user sending the email can digitally sign the email on the receiving side, email+ for ios validates the sender’s identity and determines whether the email has been tampered with the device user sending the email can encrypt the email on the receiving side, email+ for ios decrypts the email email+ for ios automatically encrypts emails when replying to or forwarding an encrypted email thread using s/mime requires a user certificate on the device running email+ for ios you can import encryption certificates in one of two ways pushing s/mime certificates from ivanti epmm docid\ g8jnyhoejf7m mdzdb2ah or importing s/mime certificates to the device through email docid\ g8jnyhoejf7m mdzdb2ah before you set up s/mime for email+ for ios before you set up s/mime do the following make users’ public encryption keys accessible to all users to send an encrypted email, a user needs the recipient’s public key if you provide users’ public keys in the active directory, email+ for ios uses global address lookup to retrieve a public key as needed another way for one user to have the public key of another user is to receive an email from a user with one certificate for both signing and encryption when receiving a signed email where the signing certificate and encryption certificate are the same, email+ for ios now has the sender’s public key the recipient can now send an encrypted email to the sender of the signed email make sure users’ encryption certificates are the same on all devices users need their private keys and certificates to read encrypted emails a user’s encryption key and certificate must be the same on all the user’s email apps that use s/mime, including desktop email apps when an encryption key/certificate is renewed, the existing email on a device cannot be decrypted unless the original key certificate is available keep a backup copy of the encryption key and certificate or consider using a third party escrow service to restore an encryption key and certificate from backup, users can send themselves the key/certificate as an email attachment, as described in importing s/mime certificates to the device through email docid\ g8jnyhoejf7m mdzdb2ah pushing s/mime certificates from ivanti epmm pushing s/mime certificates from ivanti epmm is a two step process enabling per message s/mime for ios docid\ g8jnyhoejf7m mdzdb2ahconfiguring key value pairs docid\ g8jnyhoejf7m mdzdb2ah enabling per message s/mime for ios see the “enabling per message s/mime for ios” section in the for ios device to set up the encryption and signing certificates for s/mime configuring key value pairs the key value pairs define the encryption and signing certificates to be used in email+ the value for each key is the certificate enrollment setting you created you enter the key value pairs in the appconnect app configuration you created for email+ for ios procedure in the ivanti epmm admin portal, go to \<font color="#323232">policy \& configs \> configurations\</font> select the app configuration you created in creating an appconnect app configuration for ivanti email+ docid\ t ajkenorlnuxe9905uhw click \<font color="#323232">edit\</font> add the following key value pairs in the app specific configurations section email encryption certificate this key specifies the certificate to use for encrypting s/mime emails select the scep setting you want to use from the dropdown list email signing certificate this key specifies the certificate to use for signing s/mime emails select the scep setting you want to use from the dropdown list use of expired or revoked certificates for signing and encryption not supported also, the expired certificates are not displayed in the signing or encryption selection lists pushing s/mime certificates from ivanti neurons for mdm to enable s/mime encryption, set up the certificates you will use for s/mime in ivanti neurons for mdm you will reference the certificates in the email+ configuration to distribute the certificates to devices certificates are sent to the devices to which the configuration is distributed email+ imports the certificates into the keychain and selects the certificates as the encryption and signing certificates, respectively device users can then use the certificates in email+ for ios procedure set up certificates create a certificate or identity certificate setting from configurations > +add before creating an identity certificate, you must have also added a certificate authority in admin > certificate authority see ivanti neurons for mdm help for information about setting up certificates in ivanti neurons for mdm configure the s/mime key value pairs in the email+ configuration the key value pairs define the encryption and signing certificates to be used in email+ for ios the value for each key is the certificate setting you created in set up certificates create a certificate or identity certificate setting from configurations > +add before creating an identity certificate, you must have also added a certificate authority in admin > certificate authority see ivanti neurons for mdm help for information about setting up certificates in ivanti neurons for mdm docid\ g8jnyhoejf7m mdzdb2ah related topics see the key value pairs for customization docid\ fidbv5n89hmfjspm6wnml , for the s/mime key value pairs for the encryption and signing certificates importing s/mime certificates to the device through email device users can import the signing and encryption certificates to their device from email procedure device users email themselves the certificate they use for s/mime as an attachment the certificate must be sent as a pfx file open the email using email+ for ios on the device tap to open the attachment email+ for ios prompts the user for the certificate password enter the certificate password email+ for ios imports the certificate into its keychain enable s/mime signing and encryption in the mail settings in email+ for ios in email+ for ios, tap \<font color="#323232">settings \> mail\</font> tap \<font color="#323232">security\</font> tap \<font color="#323232">sign\</font> the user’s signing certificate is automatically selected users may optionally tap \<font color="#323232">always sign\</font> to always sign emails with their certificate, and \<font color="#323232">sign as clear text\</font> tap \<font color="#323232">encrypt\</font> the user’s signing certificate is automatically selected users may optionally tap \<font color="#323232">always encrypt\</font> to encrypt every email they send through email+ for ios
