How can I implement my e-mail certificate (S/MIME) in Mozilla Thunderbird and sign/encrypt my e-mails?



For the implementation, please ensure that you have the certificate in PKCS12 format (.pfx). If you need to convert the certificate, you can use our certificate converter for this. You can find further helpful information on converting your certificate in our FAQ article "How can I create a PFX file?".

To import your certificate into Mozilla Thunderbird

1

Open your Thunderbird and click on Tools > Settings.

2
  1. Click on Advanced and select View certificates.


    In the new version of Thunderbird, select Advanced from the left menu and then switch to the tab Certificates. Now click on Manage Certificates.
  2. In the window that appears, please make sure that you are in the Your Certificates tab.
  3. Click on Import and select previously saved certificate file.
  4. Enter the specified password and the certificate will appear in the certificate manager

3

Click on OK to complete the import.


Signing and encryption of messages

  • Signing an email ensures that the recipient knows that the email came from you and informs them that it was not modified during transmission.
  • Encrypting an email ensures that only the recipient can read the content and attachments of the email.


To encrypt e-mails, you must first have the recipient's e-mail certificate in your certificate store. To obtain the recipient's certificate, first ask the recipient to send you a signed e-mail. When you receive the signed e-mail, his certificate is automatically imported into your certificate store and you can then send an encrypted e-mail to that person.

Assignment of the certificate

1

Open your Thunderbird and click Tools > Account Settings.

2

Now switch to Security (new: S/MIME Security) for the corresponding mail address in the left menu. There you have the possibility to store the certificate for signing and/or encryption. To do so, click on Select and enter the path to the certificate file.



3

Click OK to save the settings.


Signing and encrypting certain messages

1

To encrypt/sign a specific e-mail before sending, first open a new message and write down your text so far.

2

Before sending the messages, select Security and click Digitally sign this message and/or Encrypt this message to enable signing and/or encryption of the message.


To confirm the authenticity of a message, it is sufficient to sign the message. Encryption is only required if you want to transmit data confidentially, for example.


3

As soon as you click on Send, Outlook will convert the message according to your specifications and send it to the recipient.


Default signing and/or encryption of all messages

1

Open your Thunderbird and click Tools > Account Settings.

2

Now switch to Security (new: S/MIME Security) for the corresponding mail address in the left menu. Activate the corresponding checkbox to enable digital signature and/or encryption by default.


To confirm the authenticity of a message it is sufficient to sign the message. Encryption is only required if you want to transmit data confidentially, for example.



3

Click OK to save the settings.


Was this article helpful?

No Yes