Page Options
 
orangeDivider

How Do I...

Configure Outlook 2007 to Use PKI?
You can configure Outlook 2007 to use PKI in order to send secure, digitally encrypted email. After downloading your PKI certificate, do the following:

Choose Tools in the Outlook menu bar
Choose TrustCenter
Choose the Email Security Option



Click the Settings... button and you should get this popup screen:


First give your setting a name, you should be able to choose yourself:



Within the 'Certficates and Algorithms' section, click the Choose... button and you will be presented by a listing of your personal certificates:



You can view each certificate by first selecting a certificate and then clicking the View Certificate… button. You should then see a screen that displays information about the certificate:



When you find the certificate you want to use, select it and click OK:



The certificate will now be added to both the 'Signing Certificate' and 'Encryption Certificate' boxes for this security setting.



Click OK to save this Security Setting.

Digitally signing your e-mail messages with Microsoft Outlook 2007

When you open a new email message window, in the Options section you will see two Mail Security icons. The top icon is the signing icon and selecting this will sign your email with the chosen certificate. The lower icon is the encrypting icon and selecting it will encrypt your email. NOTE: Both the sender and recipient of the email need to have encryption setup before it is possible to successfully send/receive encrypted email messages from each other.




Your digital signature enables the recipient of your message to verify that you actually sent the message and that it was not altered along the route. Signing your email will also give your recipient your public key. This will allow your recipient to send you encrypted emails in the future.

Signing a message does not affect the contents of the message in any way or protect the message from being intercepted and read by someone other than the intended recipient.

To ensure that only the recipient can read a message, you must also encrypt the message. If the recipient of your signed message uses an S/MIME–enabled e-mail package, he can still read your message. In that case, your digital signature shows up as an attachment.

The signed icon shows that the received message was signed:


An untrusted signature icon shows that the received message was signed by a certificate which was issued by a CA which you do not trust yet (because you have not installed its root certificate or it has been revoked). This icon looks like:



You can sign your messages each time you want to sign or you can configure your security settings (as described previously) to sign using a specific certificate.