S/MIME with Intune
Deploy user certificates to your MDM-managed iOS and Android devices transparently.
Unmanaged Devices
Push user certificates and private keys to your unmanaged devices simply by secure e-mail.
Secure Key Transfer
Push private keys securely from your TOPKI key archive or a Microsoft CA database.
"Secardeo certPush completes the end-to-end security vision by enabling e-mail encryption and digital signature through key distribution also for mobile devices."
A user wants to read his encrypted e-mails on all his devices. For this, all devices must provide the same private key. In an enterprise PKI the private decryption key resides in a central key archive from where it can be recovered by authorized Key Recovery Agents. Also separate private signature keys can be handled accordingly. Standard S/MIME certificates typically use one multipurpose key for encyrption and digital signature.
Secardeo certPush is a service for the automated recovery and distribution of X.509 user certificates and private keys from such a central key archive. With it the private keys of S/MIME certificates can be pushed to all managed or unmanaged devices of a user. By this, the user can decrypt, encrypt or sign his e-mails using e-mail apps on mobile devices like iOS or Android or even on MDM-managed Windows or Mac systems.
Secardeo certPush is an integral part of the Secardeo TOPKI platform. It can also be used as an extension for a Microsoft CA. With certPush, X.509 user certificates and PKI private keys can be simply recovered using standard Microsoft key recovery mechanisms based on Key Recovery Agents (KRA). Recovered keys can then securely be distributed to all devices of a user in a protected PFX (.P12) container.
Certificate distribution can be done automatically via secure e-mail, e.g. for unmanaged devices, or via an MDM system for managed devices.
certPush Mail distributes the private key in a PKCS#12 encrypted container as a .pfx attachment to the certificate owner. The password to decrypt and import the key on the device is transferred end-to-end encrypted.
certPush MDM uploads a user’s certificate and private key to his configured profile on Mobile Device Management (MDM) system. This is done over a secure channel via the MDM API. The PKCS#12 container and password can then be pushed to the mobile device or even MDM-managed Windows PCs or Macs in a mail or exchange profile.
certPush KRS is a Key Recovery Service that provides recovered private keys to authorized applications like certLife based on a strong authentication. By this, a user may import his certificates and keys to his device via a web based self-service.
The user certificates or S/MIME certificates may stem from an internal Microsoft CA or a public CA like SwissSign or Digicert using certEP or certLife.
certPush supports the recovery of single private keys and batch recoveries of private keys of multiple users. Secardeo certPush can either recover only the current certificate and private key of a user or the whole key history into a .P12 container.
© 2024 Secardeo GmbH.
All rights reserved.