Setting up S/MIME
S/MIME does the same job as PGP (encrypting and signing mail), but organizes trust differently: instead of exchanging keys among yourselves, a certificate authority vouches for your identity. Which is why S/MIME is the standard in companies and public agencies, wherever Outlook and Exchange set the tone.
As a rule of thumb: in business environments with a certificate infrastructure, S/MIME is a given; among private users and in the open-source world, PGP is more common. YouniqMail speaks both.
What you need
Section titled “What you need”A personal S/MIME certificate for your email address. You get one:
- from your employer, if a certificate infrastructure exists there: the most common case,
- from commercial certificate authorities issuing personal mail certificates,
- sometimes from professional associations or universities for their members.
The usual form is a file in .p12 or .pfx format, protected by a
password, which contains the certificate and the private key.
Setting up
Section titled “Setting up”- Open Settings → Security → S/MIME, tab My certificates.
- Click Import .p12 / .pfx, choose the file and enter its password. In the same dialog you assign the certificate to an account right away.
- Set what the account uses it for: Use for signing and Use for decryption, usually it is the same certificate.
Assignment happens per account; different accounts can carry different certificates.
In daily use
Section titled “In daily use”Signing and encrypting are toggled in the compose window, as with PGP. The switches for this only appear when the sending account has a certificate of its own assigned. If PGP and S/MIME are both switched on, S/MIME takes precedence. Encrypting requires the recipient’s certificate. It conveniently collects itself: every signed mail that reaches you carries its sender’s certificate along.
YouniqMail keeps the certificate only when the signature is valid. It is ready for encrypting right away when it was issued for the sender’s address by a certificate authority YouniqMail trusts. Otherwise it appears under Settings → Security → S/MIME as Pending review. Check it with the sender and confirm it with Trust, then you can reply encrypted.
Received S/MIME mail is verified and decrypted automatically. Above the text you see what the signature check found:
- S/MIME signature verified: the signature holds, the certificate was issued for the sender’s address, and it comes from a trusted certificate authority or you confirmed it.
- S/MIME signature valid, certificate not confirmed: the signature holds, but nobody vouches for the certificate, for example because the sender issued it themselves. Compare the fingerprint with the sender and confirm the certificate with Trust.
- S/MIME signature from someone else: the signature holds, but the certificate was not issued for the sender’s address, or you rejected it.
- S/MIME signature invalid: the check failed; the mail may have been changed after signing.
YouniqMail checks the signature inside an encrypted mail the same way. The mail list shows the result on its shield icon. When you trust or reject a certificate, the display changes right away.
Pro feature
Section titled “Pro feature”Importing certificates and sending signed or encrypted mail belong to the Pro feature set. YouniqMail decrypts and verifies received S/MIME mail even without Pro, and you can still export or delete existing certificates. PGP, by contrast, is fully open to everyone.