Page Options
 
orangeDivider

How Do I...

Configure Thunderbird to Use PKI (on Mac)?

PKI can be used with Thunderbird to send secure, digitally encrypted email. Thunderbird (and other Mozilla family products) don't use the Macintosh Keychain. The PKI digital certificate is imported directly into the application.

Using PKI with Thunderbird


Open Thunderbird. Click on Tools | Account Settings:




Click on Security | View Certificates under your email account.



Go to the Your Certificates tab and click the Import button.



Browse to the location where your digital certificate is stored and click Open to import the certificate.




If the certificate has imported correctly you will see the certificate listed on the Your Certificates tab. Click OK to close this window.



You should return to the security options. Click the Select button within the 'Digital Signing' section.




In the drop-down menu for the list of digital certificates you have available, select the digital certificate you would like to use and click OK:



The window below appears next. Click OK.




The Digital Signing area in the Security window should now display the name of the digital certificate being used. In order for the certifcate to be active, check the box Digitally sign messages (by default). Please note that under Encryption, the selection is set to Never (do not use encryption). Click OK to complete the digital signature configuration.


Thunderbird is now ready to send secure email. When you create an email message, you should have a drop-down menu under 'Security' where you can select to 'Encrypt This Message' and/or 'Digitally Sign This Message'.




Your digital signature enables the recipient of your message to verify that you actually sent the message and that it was not altered along the route. Signing a message does not affect the contents of the message in any way or protect the message from being intercepted and read by someone other than the intended recipient.

To ensure that only the recipient can read a message, you must also encrypt the message. NOTE: Both the sender and recipient of the email need to have encryption setup before it is possible to successfully send/receive encrypted email messages from each other.