With the Digital ID management solution, you can issue and manage the lifecycle of certificates and distribute them to multiple devices, using the Smart ID Identity Manager. Some tasks are available via self-service, for example to request S/MIME certificates. For more information on the available use cases, self-service tasks, approval steps, and so on, see Digital ID.
Certificates can be issued from a trusted root, for example D-Trust or QuoVadis, or from Nexus' Corporate PKI solution. See also Integrate Identity Manager with certificate authority (CA).
With Nexus' Corporate PKI, key archiving and recovery is provided. If the encryption key for S/MIME is lost, it can be recovered and any loss of encrypted data can be avoided.
Digital ID - How it works
Use S/MIME certificates on desktop
When a smart card or virtual smart card is provisioned, the S/MIME certificates are ready to use in Outlook on your desktop. Your IT department need to configure the options to encrypt or digitally sign email messages in Outlook.
Smart cards
S/MIME certificates can be issued on smart cards for signing and encrypting emails on your desktop. For more information on lifecycle management, available use cases and workflows in Smart ID, see Smart card management.
Most common card types are supported, see also Personal Desktop Client requirements and interoperability.
Virtual smart cards
S/MIME certificates can be issued on virtual smart cards for signing and encrypting emails on your desktop. For more information on lifecycle management, available use cases and workflows in Smart ID, see Virtual smart card management.
Use S/MIME certificates on mobile device
Virtual smart cards can also be used for signing and encrypting emails on Android and iOS mobile devices. This works with all email apps with S/MIME functionality and access to a corresponding key chain, for example Apple mail.
Single user
For a single user to sign or encrypt with S/MIME certificates, they must first be installed in the system keychain. See Install digital certificates using Smart ID Mobile App.
Mobile device management
If a mobile device management (MDM) system is used within an organization, the IT department can set up email encryption for all users. This can be integrated with for example the MobileIron email client.
For more information on lifecycle management, available use cases and workflows in Smart ID, see Mobile virtual smart card management.