Managing S/MIME certificates and PGP keys
Manage S/MIME certificates centrally: import, issue through SwissSign or your own MPKI, renew automatically and distribute over LDAP.
SecureMail manages all certificates and keys centrally in the tenant. Public certificates of the counterparts and your own private certificates are held separately and are available to the routing for signing, encrypting, decrypting and signature verification.
Central management of the S/MIME certificates.
Importing certificates and keys
S/MIME certificates can be imported from a file, the formats crt, pem, der, p7b, p7c, p12 and pfx are supported. PGP keys are read in as gpg, pgp or asc. Private keys can additionally be held in a hardware security module. Existing certificates can be viewed and downloaded, for instance for export into other systems.
Management of the OpenPGP keys.
Issuing certificates through SwissSign or your own MPKI
Besides importing, SecureMail can issue certificates itself. Through the SwissSign connection, publicly trusted S/MIME certificates are ordered from a trust centre. Alternatively your own MPKI, that is an internal certificate authority, issues certificates for your own mail addresses. The internal CA suits infrastructures without an external provider.
Choosing the certificate authority, SwissSign or your own MPKI.
Automatic renewal
Automatic renewal checks daily for certificates about to expire and renews them in time. It is available for certificates of the internal CA and for certificates issued through SwissSign. In addition, advance notifications warn before the expiry date. Individual certificates can be renewed or revoked manually.
Distribution over LDAP
Through an LDAP connection SecureMail can look up certificates in a directory. A separate base DN for certificates can be stored for this and used as a fallback when no matching certificate is available locally. Central directories and the mail flow thus stay in sync.
How the keys are used in operation is shown in inbound messages and outbound messages. The connection to Entra ID is described in SecureMail for Microsoft 365. The SecureMail index gives an overview.