We help IT Professionals succeed at work.

sending encrypted emails

kjman
kjman asked
on
Medium Priority
441 Views
Last Modified: 2010-03-05
Hi all

I have isntalled and configured my own CA on my windows 2003 server and domain. I am also running exchange 2003. I can send encrypted and digitally signed emails to anyone in my own domain, I can also send digitally signed emails to all other recipietns outside my domain, but i cannot encrypt these  emails. When i digitally sign an email, and send it to someone@domainame.com, the recipient adds me (the sender) as one of there contacts. Once they do this my certificate is in the Trusted Root Certificate authorites for the CA and my personal cert is in the trusted People on the recipients local machine. This all looks good to me. Do I also need to publish my companys public CA as well?

Thanks for any help.

skip
Comment
Watch Question

You cannot send an encrypted email to an external user if you use your own CA to encrypt the email.  You must use a 3rd party CA such as Verisign.

To Encrypt an email, you download the end-user's public key and then the end-user uses their private key to decrypt it.
Likewise, to Digitally Sign an email, you use your private key and then the end user uses your public key to verify that you were the one who sent the email.

Realizing that 1) your CA is not visible to external users, and 2) your CA is not trusted by external users, you can see the problem here.

Thanks,

David
BembiCEO
CERTIFIED EXPERT

Commented:
For decrypting emails, you need a private key as well as a public key. If you send encrypted emails to recipients outside your scope of you public key, the recipient needs access to your public key. This is usually done by a provider, you stores a public key for all receipients outside your domain. That means, you have to buy a public key from one of the providers (like verisign etc.). Another option is, if this is only for point to point encryption, that your public key is also hosted and pouplated on a CA on the other side of your communication (receipient system).

Author

Commented:
Ok so this wont work because the recipient has no way of trusting my companys CA, or is because the recipient has no way of getting to my companys public CA?

If it is the latter can i publish my companys CA? i.e https:\\domainame.com\certsrv would this allow the recipient to download my companys public certificate?

Thansk again
Skip
CEO
CERTIFIED EXPERT
Commented:
Unlock this solution and get a sample of our free trial.
(No credit card required)
UNLOCK SOLUTION
Unlock the solution to this question.
Thanks for using Experts Exchange.

Please provide your email to receive a sample view!

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.