This article explains how to encrypt and decrypt emails with Business Mail to ensure the security of confidential information. It describes the creation of a key pair using asymmetric encryption, which involves a public and a private key. To implement encryption, the exchange of public keys is necessary, which is done through signed emails. The article provides a step-by-step guide for setting up and using encryption in everyday life, including creating and importing an S/MIME certificate.
Business Mail supports encrypting and decrypting emails. This article includes an introduction to the topic, instructions for setting up encryption, and a description of how encryption can be used in daily practice.
Introduction
Instructions
Usage
Introduction
To prevent confidential emails from being read by third parties while in transit to the recipient, emails are encrypted. To implement this encryption, the following steps are necessary:
- Create your own key pair
Emails are encrypted with a so-called key. The asymmetric encryption method is used for this, meaning that two different keys are used for encrypting and decrypting a message, but they belong together. This key pair consists of a public key and a private key, which must be created.
Example:
Hans encrypts the email with Ursi’s public key.
Ursi can decrypt and read the email with her private key.
Ursi replies and encrypts the email message with Hans’ public key.
Hans can decrypt and read the reply with his private key.
Encrypting and decrypting messages thus requires that the two public keys have been exchanged beforehand. - Exchange of the public key
Once you have your own key pair, you share your public key with your contacts. This exchange of the public key takes place via a signed email. Only after this exchange has occurred can emails be encrypted mutually.
Example:
To ensure Ursi has Hans’ public key, Hans sends a signed email to Ursi. Ursi replies to this email and also signs it so that Hans has her public key. Now Hans and Ursi can send each other encrypted emails.
Instructions
Create and import your own key pair
To create a key pair, an appropriate S/MIME certificate is required.
1. Visit a provider where you can obtain an S/MIME certificate.
Nowadays, free offers for S/MIME certificates are hardly available. For example, there is one at Secorio, but it has a very short validity period of 30 days. An S/MIME certificate for 3 years costs only 51 euros there. It is a Swiss provider.
2. Fill in all relevant data in the provider’s form, including the email address from which you want to send encrypted emails.
3. You will now receive an email from the registration authority, which usually contains a link to install the certificate. Open the link using the same browser you used to order the certificate because the key pair was generated there. Some issuing authorities also require authentication via a confirmation code and link; follow the instructions in the email.
4. You will receive a message that the certificate has been installed in the browser.
5. Save the certificate installed in the browser to your computer.
Firefox
Menu Tools → "Settings" → "Advanced" → "Certificates" → "View Certificates," select the appropriate certificate (in this example 'COMODO CA Limited') and click "Backup...". Enter a certificate backup password and remember it because you will need it for the installation later.
Internet Explorer
Menu "Internet Options" → "Content" → "Certificates," select the appropriate certificate (in this example 'COMODO CA Limited') and click "Export...".
In the Certificate Export Wizard, proceed as follows:
- "Next"
- "Yes, export the private key" → "Next"
- "Personal Information Exchange - PKCS #12 (.PFX)" → "Next"
- Enter a password and remember it because you will need it for the installation later → "Next"
- Choose the file name and location → "Next"
- "Finish"
6. The .p12 or .pfx certificate file you just saved can now be imported in Webmail. To do this, log in to Webmail and go to "Settings" via your username → "Secure Messages".
7. If you have not yet set a password for the certificate store, enter a desired password. Please remember this password because it is needed to access your certificates.
8. Now import the saved certificate
9. Enter the password you entered when backing up/exporting the certificate from the browser (step 5).
The certificate is now stored in the certificate store and can be used when composing emails.
Usage
Exchange of the public key (sending a signed message)
Note the following two points:
1. Make sure that the people to whom you want to send encrypted messages are saved in your contacts.
2. When you receive a signed message, it must be opened by double-clicking in a separate window, as this is the only way the sender’s public key is saved.
Sign all outgoing emails:
To do this, go to "Settings" under your username, then to the "Secure Messages" menu, and enter the password for your certificate store. Select the option "Sign all outgoing messages":
Sign individual emails:
When composing a new email, activate the "Sign icon":
Send encrypted message
Once the exchange of public keys has taken place by sending each other signed emails, you can send encrypted emails to that contact. Whether the public key has been correctly stored for the contact is visible under the contacts.
To send an encrypted email to the contact, simply activate the "lock icon" when composing an email: