EJBCA with GemSAFE Toolbox Part2 Sign. and Encrypt Email



Similar documents
EJBCA with GemSAFE Toolbox Part1 Workstation Logon

EJBCA with GemSAFE Toolbox Part3 SSL

To configure Outlook Express for your InfoMetrics address:

Versions Addressed: Microsoft Office Outlook 2010/2013. Document Updated: Copyright 2014 Smarsh, Inc. All right reserved

Instructions for Microsoft Outlook 2003

Using TLS Encryption with Microsoft Outlook 2007

Outlook Express. Make Changes in Red: Open up Outlook Express. From the Menu Bar. Tools to Accounts - Click on Mail Tab.

Patriots Outlook Configuration

Configuring Outlook to send mail via your Exchange mailbox using an alternative address

Outlook 2010 Setup Guide (POP3)

Knights Outlook 2013 Configuration

NeoMail Guide. Neotel (Pty) Ltd

PaperClip. em4 Cloud Client. Manual Setup Guide

Knights Outlook Configuration

Toll Free: International:

Setup Guide. network support pc repairs web design graphic design Internet services spam filtering hosting sales programming

Outlook Express. Make Changes in Red: Open up Outlook Express. From the Menu Bar. Tools to Accounts - Click on. User Information

Outlook Express. Make Changes in Red: Open up Outlook Express. From the Menu Bar. Tools to Accounts - Click on Mail Tab.

Update Instructions

1. Open the preferences screen by opening the Mail menu and selecting Preferences...

How To Send Mail From A Macbook Access To A Pc Or Ipad With A Password Protected Address (Monroe Access) On A Pc (For Macbook) Or Ipa (For Ipa) On Pc Or Macbook (For

Update Instructions

Yale Software Library

Exchange Outlook Profile/POP/IMAP/SMTP Setup Guide

HGC SUPERHUB HOSTED EXCHANGE

Client configuration and migration Guide Setting up Thunderbird 3.1

Update Instructions

Microsoft Outlook 2010

Update Instructions

Instructions. Outlook (Windows) Mail (Mac) Webmail Windows Live Mail iphone 4, 4S, 5, 5c, 5s Samsung Galaxy S4 BlackBerry

Configuring Microsoft Outlook for First Time Use. with POP3 provided by Blue Tangerine Solutions

Windows Live Mail Setup Guide

Instructions: Configuring Outlook 2003 with Exchange 2010 on the FIUMail

Using etoken for Securing s Using Outlook and Outlook Express

Configuration Manual for Lime Domains

Set up Outlook for your new student e mail with IMAP/POP3 settings

Standard Mailbox Software Setup Guide

How to configure your client

setup information for most domains hosted with InfoRailway.

Here are the steps to configure Outlook Express for use with Salmar's Zimbra server. Select "Tools" and then "Accounts from the pull down menu.

Getting Started Configuring Your Computer Network Settings

How to set up Outlook Anywhere on your home system

StarterPlus Mailbox Software Setup Guide

Configuring Outlook Express

Check Point FDE integration with Digipass Key devices

How to Setup your Account -Apple Mail for Mac OS X 1- Open Mail

OUTLOOK EXPRESS ACCOUNT SETUP FOR USE WITH ELLIPSE ADVANCED SPAM FILTER

ConnectMail Mobile Configuration

Set Up Setup with Microsoft Outlook 2007 using POP3

Configuring Outlook for IMAP. Creating a New IMAP Account. Modify an Existing Account

Outlook Express. Instructional Manual

Exchange Outlook Profile/POP/IMAP/SMTP Setup Guide

700 Fox Glen Barrington, Illinois ph: [847] fx: [847]

CHARTER BUSINESS custom hosting faqs 2010 INTERNET. Q. How do I access my ? Q. How do I change or reset a password for an account?

Adding Digital Signature and Encryption in Outlook

Microsoft Outlook 2013 & Microsoft Outlook Microsoft Outlook Windows Live Mail 2012 & MAC Mail. Mozilla Thunderbird

How to configure your Windows PC post migrating to Microsoft Office 365

How to configure your Desktop Computer and Mobile Devices post migrating to Microsoft Office 365

3. On the Accounts wizard window, select Add a new account, and then click Next.

How to Set Up Your. Account

How to Pop to Outlook

Outlook Express POP Instructions - Bloomsburg University Students

User Guide Microsoft Exchange Remote Test Instructions

5. For Display name, Your Full Name or the name you want to appear in the from box when writing or responding to click Next

You may use port 587 if port 25 is blocked by your internet provider. This does not apply to customers using PolarComm internet.

CWOPA Broadband Users. Windows Operating System

1. Open the preferences screen by opening the Mail menu and selecting Preferences...

1. Open Thunderbird. If the Import Wizard window opens, select Don t import anything and click Next and go to step 3.

How to Set Up LSUS IMAP in Outlook 2013

BUSINESS CLASS POP3 END USER GUIDE TIME WARNER CABLE BUSINESS SERVICES VERSION 1.0, RELEASE 1.2

IMAP and SMTP Setup in Clients

MyArbonne Account Settings

UNI - WINDOWS. How to... Access your University on your Windows Computer. Introduction. Step 1/1 - Setting Up Your Windows Computer

PaperClip. em4 Cloud Client. Setup Guide

Configuring an Client to Connect to CASS Mail Servers

Microsoft Windows Server 2003 Integration Guide

How To Create A Mailbox In Windows Mail On A Pc Or Mac Or Ipad (For A Mac)


PREMIUM MAIL USER GUIDE

Webmail. Setting up your account

NODE4 SERVICE DESK SYSTEM

Using Outlook with SaderApps

Hosted Microsoft Exchange Client Setup & Guide Book

Setup a new account

Quick Reference Guide: Business Mail

All existing accounts will be listed. 2. Click Add and select Mail to add a new account (see Figure 2). Figure 1. Figure 2

How To Configure Using Different Clients

Microsoft Exchange Mailbox Software Setup Guide

Configuration Task 3: (Optional) As part of configuration, you can deploy rules. For more information, see "Deploy Inbox Rules" below.

Using CertAgent to Obtain Domain Controller and Smart Card Logon Certificates for Active Directory Authentication

Installing your Digital Certificate & Using on MS Out Look 2007.

Business mail 1 MS OUTLOOK CONFIGURATION... 2

Prerequisite. Getting Started. Signing and Encryption using Microsoft outlook 2007

Setting up CatMail on Outlook 2010

aprompt User Guide Setting up a mailbox on the Apple IPhone 3G aprompt.co.uk User Guide Version 3.0 Advanced Mailbox on Apple IPhone 3G

How to make the s you Send with Outlook and Exchange Appear to Originate from Different Addresses

Neoteris IVE Integration Guide

SQL Server Setup for Assistant/Pro applications Compliance Information Systems

I. Configuring Digital signature certificate in Microsoft Outlook 2003:

Transcription:

EJBCA with GemSAFE Toolbox Part2 Sign and Encrypt Email

2 Introduction This document introduces the process of using EJBCA together with GemSAFE toolbox to encrypt and sign email. In short, there are 4 compulsory settings for signing and encryption email. 1. 2. 3. 4. The end entity s email must same with the email account you are going to use In certificate profile, Digital Signature and Key Encipherment must be chosen in key usage; Email Protection must be chosen in Extended Key usage. In end entity profile, EMail, EmailAddress in DN must be added. CA's certificate must be imported to local machine This document is a continuation form a document call EJBCA with GemSAFE Toolbox Part1 workstation logon. The forth setting, importing CA's certificate to local machine had been done in previous document. If you want to skip the previous document and directly get started from this, don't forget to import the CA's certificate to local machine yourselves.

3 Table of Content EJBCA with GemSAFE Toolbox Part2 Sign and Encrypt Email...1 Introduction...2 Table of Content...3 1 -- Configure EJBCA...4 1.1 -- Create Certificate Profile Email...5 1.2 -- Create End Entity Profile "Email"...10 1.3 -- Add "EmailSender" End Entity...14 1.4 -- Enroll Certificate to GemSAFE Smartcard...15 2 -- Configure Server...16 2.1. -- Add Server as a Email Server...17 2.2. -- Add a New Email Account...19 3 -- Configure Microsoft Outlook 2003 for Sending Encrypted and Signed Emails...20

4 1 -- Configure EJBCA

5 1.1 -- Create Certificate Profile Email 1. 2. 3. 4. 5. On server, go to EJBCA Administration GUI Click Edit Certificate Profiles Type "Email" in the text box under Add Profile. Click Add a) Choose Email under Current Certificate Profiles b) Click Edit Certificate Profile c) Set Email certificate profile s parameters i. Under "Key Usage" select "Digital Signatures" and Key Encipherment ii. Check "Use Extended Key Usage" iii. Under "Extended Key Usage" select " Email Protection " iv. Under "Available CAs" select only "GS_SCL_CA_v1" Leave all other setting by default, click save The following is the screen capture of the settings

6

7

8

9

10 1.2 -- Create End Entity Profile "Email" 1. 2. 3. 4. 5. On server, go to EJBCA Administration GUI Click Edit End Entity Profiles Type "Email" in the text box under Add Profile. Click Add a) Choose Email under Current End Entity Profiles b) Click Edit End Endtity Profile c) Set email end entity profile s parameters i. Under "Subject DN" fields, add Email, EmailAddress in DN ii. Under Email, EmailAddress in DN, check Required iii. Under Default certificate profile select Email iv. Under Available certificate profiles select Email v. Under Default CA select GS_SCL_CA_v1 vi. Under "Available CAs" select only "GS_SCL_CA_v1" Leave all other setting by default, click save The following is the screen capture of the settings

11

12

13

14 1.3 -- Add "EmailSender" End Entity 1. 2. 3. 4. 5. 6. 7. 8. 9. On server, go to EJBCA Administration GUI Click Add End Entity Under End Entity Profile choose GS SmartCardLogon User Name= EmailSender01 Password= foo123 Confirm Password= foo123 CN, Common Name= EmailSender01 MS UPN, User Principal Name = emailsender01@testing.company.cn The following is the screen capture of the settings 10. Leave all other setting by default, click Add End Entity

15 1.4 -- Enroll Certificate to GemSAFE Smartcard 1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. On work station, open Internet Explorer Go to EJBCA's Public Web Pages, http://testing.company.cn:8080/ejbca/ plug in GemSAFE token Click Create Browser Certificate Username: =EmailSender01 Password: =foo123 Click OK Another webpage will be shown Under Options, choose Provider as Gemplus GemSAFE Card CSP Click OK A potential script violation warning may be shown, Click Yes Enter smart card s PIN Click OK A potential script violation warning may be shown, Click Yes Click OK

16 2 -- Configure Server

17 2.1. -- Add Server as a Email Server 1. 2. Go to Domain Controller\start\Manage Your Server\Add or Remove a Role\Click Next \ Chose Mail server (POP3, SMTP) 3. Click Next

18 4. In E-mail domain name: field, input testing.company.cn 5. 6. Click Next 2 times You may be prompted to locate the Windows Server 2003 image or CD location 7. Click Finish

19 2.2. -- Add a New Email Account 1. 2. 3. 4. 5. At server, go to Start\Administrative Tools\POP3 Service Click CLEAN2003 node\click testing.company.cn \ Add MailBox Maillbox Name: EmailSender01 Password: foo123@ Confirm Password: foo123@ 6. 7. Click OK Click OK

20 3 -- Configure Microsoft Outlook 2003 for Sending Encrypted and Signed Emails

21 1. 2. Install Microsoft Outlook 2003 on Workstation Add email account EmailSender01, to Microsoft Outlook 2003 a) At workstation, open Microsoft Outlook 2003\ tools\e-mail Accounts b) Click Next

22 c) d) e) f) g) h) i) j) Choose POP3 \Click Next > Your Name = EmailSender01 E-mail Address = emailsender01@testing.company.cn Incoming mail Server (POP3): = testing.company.cn Outgoing mail Serve (SMTP): = testing.company.cn Username= emailsender01 Password = foo123@ Check logon using Secure Password Authentication (SPA)

23 k) Click Test Account Settings l) Click Close m) Click Next > n) Click Finish

24 a) b) c) In Microsoft Outlook 2003, Tools\ Options \ Security Check Encrypt contents and attachments for outgoing messages Check Add digital signature to outgoing messages d) e) f) Click Setting Click Choose Select the EmailSender01 s certificate

25 g) h) 3. Click OK Select Hash Algorithm: as MD5 i) Click OK j) Click Apply k) Click OK Now you can use Microsoft Outlook 2003 to send a signed email to yourself (for illustration purpose)

26 4. When you received a signed email, you can reply with a signed and encrypted email