The certificates can be used for SSL.
2. S/MIME Applications
To enable S/MIME on mail applications such as Mozilla Thunderbird:
1. In Mozilla Thunderbird, open the Edit menu, and select Account Settings.
2. Select Security on the left.
3. Add a PKCS #11 driver.
a. Click Manage Security Devices to open the Device Manager window.
b. Click the Load button.
c. Enter the module name, such as
token keypk11 driver
.
d. Click Browse, find the Enterprise Security Client PKCS #11 driver, and click OK.
4. If the CA is not yet trusted, download and import the CA certificate.
a. Open the SSL End Entity page on the CA. For example:
https://example.com:9443/ca/ee/ca
b. Click the Retrieval tab, and then click Import CA Certificate Chain.
c. Click Download the CA certificate chain in binary form and then click Submit.
d. Choose a suitable directory to save the certificate chain, and then click OK.
e. In Thunderbird, open the Edit menu, and select Account Settings.
f. Select Security on the left, and click the Manage Certificates button.
g. Click the Authorities tab, and import the CA certificate.
5. Set up the certificate trust relationships.
a. In Thunderbird, open the Edit menu, and select Account Settings.
b. Select Security on the left, and click the Manage Certificates button.
c. In the Authorities tab, select the CA, and click the Edit button.
d. Set the trust settings for identifying websites and mail users.
e. In the Digital Signing section of the Security panel, click Select to choose a certificate to
use for signing messages.
S/MIME Applications
43
Summary of Contents for CERTIFICATE SYSTEM ENTERPRISE - SECURITY GUIDE
Page 2: ...Red Hat Certificate System Enterprise Security Client Guide ...
Page 4: ...Red Hat Certificate System Enterprise Security Client Guide ...
Page 6: ...vi ...
Page 10: ...4 ...
Page 12: ...6 ...
Page 18: ...Figure 3 5 Beginning Installation Chapter 3 Installation 12 ...
Page 26: ...20 ...
Page 59: ...Index 53 ...
Page 60: ...54 ...