Search in this section
New Baseline Requirements
In order to standardize the issuing and administration of S/MIME certificates, the CA/B Forum has defined new requirements, taking effect at the beginning of September 2023.
- As a result, the authentication (so-called "vetting") may change or, in the case of existing certificates, may have to be carried out again. In the case of
a person representing an organization, it may be necessary to make a video call in the future. - Some S/MIME products will not be carried over to the new standards by the respective CAs and will be deprecated. Consequently, the following S/MIME products are currently no
longer available at InterNetX: GlobalSign PersonalSign Class 2 and Sectigo Pro S/MIME Certificate - In the future, S/MIME certificates will be categorized into one of the following types: Mailbox-validated, Organization-validated, Sponsor-validated, Individual-validated
- Additionally, a profile is assigned as well. This profile determines the maximum validity period: legacy (3 years), multipurpose or strict (2 years)
- S/MIME certificates issued according to the "old" standards remain valid and can be used until the respective expiration date. A renew or a reissue might not be longer possible. Please see below for details.
Why S/MIME?
The S/MIME (Secure/Multipurpose Internet Mail Extensions) technology secures your email correspondence through encryption and signing.
The asymmetrical encryption protects S/MIME emails against unwanted access, i.e. the reading and modification of the email content by third parties.
The digital signature confirms the authorship of the email and notifies the recipient of any unauthorized changes, making it an effective means of detecting phishing emails.
S/MIME certificates are cost-effective because an unlimited number of emails and documents can be sent pre-encrypted and signed within an email address. They are easy to integrate and use.
Mode of Operation
Digital certificates digitally bind a cryptographic key to a user's identity, providing proof of the origin and integrity of the transmitted message.
Once the certificate is installed, the user can easily sign or encrypt selected emails with one click, or automatically sign and encrypt all emails with the digital certificate via the corresponding configuration.
S/MIME is supported by most mail clients (e.g. Microsoft Outlook, Thunderbird, Apple Mail, Lotus Notes and Mulberry Mail).
Overview of the available S/MIME Certificates
The S/MIME certificates are issued via a digital ID for persons and departments of a company.
GlobalSign
Note for PersonalSign Class 2 Pro and PersonalSign Class 2 Department:
→ Certificates issued BEFORE August 16, 2023 can no longer be renewed. These must be reordered according to the new requirements (CREATE)
→ A reissue is generally no longer possible
Certificate Name | Digital ID for Use | Type | Profile | Digital ID proves Right of Ownership | Verification (Vetting) |
---|---|---|---|---|---|
PersonalSign Class 1 | For general or personal use | Mailbox-validated | Legacy | Email address | By email |
| EOL announced by supplier for August 2023. | -- | -- | -- | In order to continue signing and encrypting emails digitally, other equally secure S/MIME certificates for your personal use are available in our portfolio. |
PersonalSign Class 2 | For a person who represents a company | Sponsor-validated | Legacy | Email address | Execution in two steps (please in this order): 1.) Person: video call with GlobalSign Vetting Team → Via a call to the personnel department with a number from the phone book → Company Register is checked |
PersonalSign Class 2 Department | For a department | Organization-validated | Legacy | Email address Assurance of the existence of the organization | By email Company Register is checked |
DigiCert
Certificate Name | Digital ID for Use | Type | Profile | Digital ID proves Right of Ownership | Verification (Vetting) |
---|---|---|---|---|---|
S/MIME Class 1 | For general or personal use | Mailbox-validated | Legacy | Email address | By email Note that the link in the email is only valid for a maximum of 24h. To resend the email, please contact your support. |
S/MIME Premium (Class 2) | For a person who represents a company | Sponsor-validated | Legacy | Email address | By email. Via a call to the personnel department with a number from the phone book Company Register is checked |
Digital Signature Plus | For a person who represents a company | Sponsor-validated | Legacy | Email address Identity assurance of the person Assurance of the existence of the organization | By email. Via a call to the personnel department with a number from the phone book Company Register is checked |
Digital Signature Plus
With the Digital Signature Plus certificate, it is possible to digitally sign documents using e. g. Microsoft Office (without Access), Adobe PDF, OpenOffice, LibreOffice, etc.
However, the following applies to Adobe PDF: It is possible to digitally sign documents, but these are not fully trusted, as the Digital Signature Plus is not listed in Adobe's Authorised Trust List (AATL).
→ For this use case, we offer the GlobalSign - Document Signing certificate.
Sectigo
Certificate Name | Digital ID for Use | Type | Profile | Digital ID proves Right of Ownership | Verification (Vetting) |
---|---|---|---|---|---|
Sectigo - Personal S/MIME | For general or personal use | Mailbox-validated | Multipurpose | Email address | By email Note that the link in the email is only valid for a maximum of 24h. |
Sectigo - Pro S/MIME Currently not available | For a person who represents a company | -- | -- | Email address | By email Via a call to the personnel department with a number from the phone book Company Register is checked |
Sectigo - Enterprise S/MIME | For a person who represents an entire company | Organization-validated | Multipurpose | Email address Identity assurance of the person Assurance of the existence of the organization | By email |
More detailed information on the individual certificates can be found in our knowledge base.