A Microsoft Outlook email forum. Outlook Banter

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Go Back   Home » Outlook Banter forum » Microsoft Outlook Email Newsgroups » Outlook - Installation
Site Map Home Register Authors List Search Today's Posts Mark Forums Read Web Partners

certificate renew with S/MIME in Outlook



 
 
Thread Tools Search this Thread Display Modes
  #1  
Old June 15th 07, 10:25 AM posted to microsoft.public.outlook.installation
Allbe Rem's
external usenet poster
 
Posts: 1
Default certificate renew with S/MIME in Outlook

Hi,

I'm the PKI Engineer in my company and We would like to secure our mail with
S/MIME in Outlook.
I know that S/MIME save in the message the issuer and serial number of
certificate used to encrypt the mail.

And I know that if certificate is renewed with the same key pair, it's not
possible to decrypt the old messages crypted with the previous certificate.

In Outlook Web Access, we could issue this by creating a registry entry in
Exchange server by putting UseKeyIdentifier = 1.

What about Outlook in genrally (outlook 2003 and Outlook 2007)?
Is there a configuration in Outlook to locate the certificate and private
key for decrypting the message by using the same way, i mean UseKeyIdentifier?

Thank you for your help

Ads
  #2  
Old June 15th 07, 03:57 PM posted to microsoft.public.outlook.installation
Brian Tillman
external usenet poster
 
Posts: 17,452
Default certificate renew with S/MIME in Outlook

Allbe Rem's Allbe wrote:

I'm the PKI Engineer in my company and We would like to secure our
mail with S/MIME in Outlook.
I know that S/MIME save in the message the issuer and serial number of
certificate used to encrypt the mail.

And I know that if certificate is renewed with the same key pair,
it's not possible to decrypt the old messages crypted with the
previous certificate.


Not true. As long as you keep the prior certificates installed, you'll be
able to decrypt messages encrypted with them. I have certificates installed
that go back several years. Renewing adds the latest certificate and does
not remove the previous one.

What about Outlook in genrally (outlook 2003 and Outlook 2007)?
Is there a configuration in Outlook to locate the certificate and
private
key for decrypting the message by using the same way, i mean
UseKeyIdentifier?


Outlook uses the certificates you can see either from IE's ToolsInternet
OptionsContentCertificates or StartRuncertmgr.msc . I think these certs
are physically located in the folder named for your SID under
%AppData%\Microsoft\Crypto\RSA. There is a
HKEY_CURRENT_USER\Software\Microsoft\Office\xx.x\C ommon\Security\DefaultSigningCert
key, but I don't know how that relates.
--
Brian Tillman

  #3  
Old June 15th 07, 09:46 PM posted to microsoft.public.outlook.installation
Allbe Rem''s
external usenet poster
 
Posts: 1
Default certificate renew with S/MIME in Outlook

you're right brian, i make a mistake.
I would like to ask if it's possible to decrypt the message with the renewed
certificates with the same key pair as previous.
Because my users didn't saved the previous or old certificates.
I know that it's possible in OWA, but i don't know the configuration for
Outlook client.

Or if you want, we have renew certificate with the same key pair for our
users.
They have some messages crypted with their previous certificates.
And those previous certificates and private key have been renew.

NB: the certificate and private key is stored in smart card.

What's the configuration in Outlook to used renew certificate with same key
pair to decrypt old messages?

Thank you for your help because i'm desperate
"Brian Tillman" wrote:

Allbe Rem's Allbe wrote:

I'm the PKI Engineer in my company and We would like to secure our
mail with S/MIME in Outlook.
I know that S/MIME save in the message the issuer and serial number of
certificate used to encrypt the mail.

And I know that if certificate is renewed with the same key pair,
it's not possible to decrypt the old messages crypted with the
previous certificate.


Not true. As long as you keep the prior certificates installed, you'll be
able to decrypt messages encrypted with them. I have certificates installed
that go back several years. Renewing adds the latest certificate and does
not remove the previous one.

What about Outlook in genrally (outlook 2003 and Outlook 2007)?
Is there a configuration in Outlook to locate the certificate and
private
key for decrypting the message by using the same way, i mean
UseKeyIdentifier?


Outlook uses the certificates you can see either from IE's ToolsInternet
OptionsContentCertificates or StartRuncertmgr.msc . I think these certs
are physically located in the folder named for your SID under
%AppData%\Microsoft\Crypto\RSA. There is a
HKEY_CURRENT_USER\Software\Microsoft\Office\xx.x\C ommon\Security\DefaultSigningCert
key, but I don't know how that relates.
--
Brian Tillman


  #4  
Old June 21st 07, 05:43 AM posted to microsoft.public.outlook.installation
Brian Tillman
external usenet poster
 
Posts: 17,452
Default certificate renew with S/MIME in Outlook

Allbe Rem''s wrote:

you're right brian, i make a mistake.
I would like to ask if it's possible to decrypt the message with the
renewed certificates with the same key pair as previous.
Because my users didn't saved the previous or old certificates.
I know that it's possible in OWA, but i don't know the configuration
for Outlook client.

Or if you want, we have renew certificate with the same key pair for
our users.


Do you have your own Private Key Infrastructure with your own certificate
issuing system? I don't know all there is to know about digital
certificates, but I don't think that you can generate new certs with the old
key values. Each renewal is a completely new public/private key pair, no
different than issuing a completely new cert, as far as I know. The only
difference in the procedure is that a renewal expects to find a prior cert
in the crypto store.

They have some messages crypted with their previous certificates.
And those previous certificates and private key have been renew.


What's the configuration in Outlook to used renew certificate with
same key pair to decrypt old messages?


Never delete the old keys is all I can recommend.
--
Brian Tillman

 




Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Digital certificate in outlook [email protected] Add-ins for Outlook 0 April 24th 07 02:42 PM
Outlook 2007 and digital certificate Paulo Rebêlo Outlook - General Queries 0 February 14th 07 11:20 PM
What the heck is MIME Version or Mime format? jukeboxjen Outlook Express 4 October 24th 06 07:41 PM
Where's the certificate (RPC over HTTP between Outlook & Exchange) Steve Baker Outlook - General Queries 4 February 27th 06 09:52 AM
Outlook 2003 SP2 - Invalid Certificate Gerald Stanley Outlook - Installation 0 February 21st 06 07:46 PM


All times are GMT +1. The time now is 07:00 AM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.Search Engine Friendly URLs by vBSEO 2.4.0
Copyright ©2004-2025 Outlook Banter.
The comments are property of their posters.