Importing a pfx file into Outlook
An Outlook recipient receives the following message1 containing the attached password encrypted pfx:
1. Double-click the attached pfx file
Alternatively, you can save the pfx file and open it with Explorer by double-clicking it. A warning will be shown asking whether you want to open the pfx file.
2. Click the "Open" button
The "certificate import wizard" will be started. The import wizard will be used to import the password protected certificate and private key.
Click the Next button until you come to password page
Enter the password for the pfx file. Optionally, check "Mark this key as exportable".
3. Click the Next button
Click Next on all the next pages until you reach the "Completing the Certificate Import Wizard" page (leave the settings at their default values).
4. Click "Finish"
The certificate and private key will now be imported.
The pfx file not only contains the end-user certificate and private key but also the root and intermediate certificate. The import wizard will also try to import the root and intermediate certificate. Windows asks for permission when importing a root certificate.
5. Click "Yes"
6. Finished.
Now that you have installed a certificate and private key, you are able to decrypt encrypted email.
[The following steps are only required if you want to send encrypted email]
We will explain how to receive and send encrypted email.
Receiving signed and encrypted email
A signed and encrypted message looks as follows:
The 'padlock'
shows that the message was encrypted and the 'ribbon'
shows that the message was signed.
The signed and encrypted message contains the public certificate of the sender. To make it possible to securely reply to the message, the public certificate should be associated with the sender.
1. Select the senders email address, right-click and select "Add to Outlook Contacts"
Save the newly added Outlook contact. If the contact is already stored in your contacts lists, you will receive a "Duplicate Contact Detected" warning.
2. Click "Update"
Note: You will only need to associate the certificate with the sender contact the first time you receive a signed and encrypted email.
Sending signed and encrypted email
Sending a signed and encrypted email is similar to sending a normal email. To sign and encrypt the message, the sign and encrypt options should be selected.
If your Outlook toolbar does not contain the sign and encrypt buttons, you can enable sign and encrypt by opening the "message options" and select the "Security Settings..."
Importing a certificate for a contact
If you received a certificate (.cer or .p7b file) for an external user you can add the certificate to an Outlook contact.1. Open the contact and select the certificates2