Tuesday, November 13, 2007

Exchange 2003 contacts and certificates

In Exchange you can add externals recipients as contacts. So I tried to add certificates to the contacts, just my Outlook was not able to get them and so I couldn't send a encrypted email.
The standard with S/MIME is first to exchange signed messages between both parties and then they can start to encrypt. Well, that's nice for your home computer, but not the right thing for a huge company were everyone is working on other things instead on PKI stuff ;-).

So I added the user certificates to the contact object with an LDAP browser (e.g. ldp). Make sure that you are uploading DER encoded files and that you have a valid email encryption certificate (Enhanced Key Usage: Secure Email). After that it is working in Outlook and Outlook Web Access.
 

No comments: