SmartMobile - Android Email encryption and decryption
SmartMobile - Android Email encryption and decryption
Central security policies require the ability to encrypt and decrypt emails for secure transfer of confidential information.
The setup of email encryption / S/MIME is mandatory for every device within Smart Mobile!
On Android devices, this will be realized with the TouchDown application.
This user guide should help you to configure your Android device to use this functionality and to import your PKI certificate in a secure way on your device.
(4a) PKI Self Service Client (a) (4b) PKI Self Service Client (b)
Wait until your current key inventory has been retrieved Click "Cancel" and do not click "Continue" here to proceed!
(5) Choose scenario „Recover my certificates“ (6) First, data is retrieved again.
From the list provided, choose your current encryption key and "continue"
(7) Enter your PIN and wait until data is prepared (8) Your PKI encryption key will be sent to you via encrypted email
(9) You will receive three encrypted emails from the Siemens Trustcenter (a) (10) You will receive three encrypted emails from the Siemens Trustcenter (b + c)
a.) One which contains the encryption key (the certificate in format P12). b.) A second email containing the certificate password (Transport PIN).
- Subject is "Siemens PKI: Your PKI key / Ihr PKI-Schluessel (Encryption, Serial Number 123456789)" - Subject is "Siemens PKI: Transport PIN (Encryption, Serial Number 123456789)"
- Please open this encrypted Trustcenter email with Outlook on your PC and forward the email - Please do NOT forward or save this email unencrypted!
unencrypted to yourself - You will need to enter it on your device later
c.) Third email with subject "Siemens PKI: Recovery of your PKI key / Wiederbereitstellung Ihres PKI-
Schluessels" is for information and can be ignored
2. Import the certificate on your Android device
(11) Open the forwarded, unencrypted "Trustcenter email" (12) Open the encrypted "Trustcenter email" containing (13) Install the certificate
containing your encryption key your certificate password (transport PIN) with Outlook on
On the mobile device please click the certificate symbol on
(certificate) using TouchDown your PC.
the right.
Start TouchDown, go to the mail screen, and open the email. You will need this password in step (13).
Click on the paper clip to see and download the attachment (.p12 Note: For security reasons it's prohibited to forward the
file). second "Trustcenter email" containing the certificate
password (transport PIN)!
(16) Compose a new email (17) Insert a recipient (18) Select email Options
Press email symbol to compose a new email. Insert a new recipient and select the elliptical symbol to get Select "Security"
further options.
(19) Select "Encrypt Message" (20) Insert your certificate PIN (21) In case of an encryption warning
And "Apply". From step (14) If the encryption key from your recipient is not cached on your
device you will receive a warning. Please don't send the
Please note: Signing outbound emails from the mobile device is
email unencrypted.
NOT supported
Using "GAL" TouchDown will download the certificate from the
Exchange Server and send the email encrypted.
Hint:
If you have done all steps above for the first time during the initial setup of your device please go back to the Android user manual for TouchDown 9.x proceeding with the Siemens specific configuration.