Managing several Sophos firewalls both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.
Signed and encrypted mails are different. And for decrypting encrypted messages you need to use your own private key.
Wenn diese Option aktiviert ist, liest das E-Mail-Verschlüsselungssystem automatisch S/MIME-Zertifikate aus eingehendem E-Mail-Verkehr aus, vorausgesetzt die Zertifikate wurden von einer gültigen S/MIME-Zulassungsstelle signiert.
Wenn diese Option gewählt ist, werden die an eingehende E-Mails angehängten S/MIME-Zertifikate automatisch extrahiert. Voraussetzung hierfür ist, dass dieses Zertifikat von einer vertrauenswürdigen Zertifizierungsstelle (CA) signiert wurde, das heißt, von einer CA, die auf dem Gerät vorhanden ist und deshalb unter Mail Security > Verschlüsselung > S/MIME-CAs angezeigt wird. Zudem muss die Zeit- und Datumsanzeige von Astaro Security Gateway innerhalb der Gültigkeitsdauer des Zertifikats liegen, da die automatische Extraktion der Zertifikate sonst nicht funktioniert. Erfolgreich extrahierte Zertifikate werden auf der Registerkarte Mail Security > Verschlüsselung > S/MIME-Zertifikate angezeigt. Beachten Sie, dass dieser Prozess ca. fünf bis zehn Minuten dauern kann. Klicken Sie auf Übernehmen, um Ihre Einstellungen zu speichern.
When this option is enabled, the email encryption system automatically reads S/MIME certificates from incoming mail traffic, provided the certificates were signed by a valid S/MIME certificate authority.
When this option is selected, S/MIME certificates attached to incoming mails are automatically extracted. Necessary condition for this is that this certificate was signed by a trustworthy certificate authority (CA), that is by a CA that is present on the device and therefore is displayed under Mail Security > Encryption > S/MIME CAs. Additionally, the time and date display of Astaro Security Gateway must lie within the validity interval of the certificate because otherwise the automatic extraction of certificates does not work. Successfully extracted certificates are displyaed on the Mail Security > Encryption > S/MIME certificates tab. Note that this process may take about five to ten minutes. Click apply to save your settings.
Bumping this thread: Meanwhile we have UTM 9.413-4 and the problem is still there, even after so many years.
I just tested the situation once more with an incoming mail,
I also tested with another incoming mail,
Neither of these mails triggered the automatic S/MIME certificate extraction. My list under "S/MIME certificates" is still empty.
I do not find any interesting lines in the smtp.log, either (or would I have to look elsewhere?)
It would be really great if this problem could be resolved, finally.
P.S.: I noticed some strangeness, but don't know if that is in any way related to the bug: The format how fingerprints are displayed differ between global and local CAs in that local CA fingerprints are displayed (via the info icon) as pure hex digit sequence (e.g., "Fingerprint: DA1D80BCF06499E616B8C51226A1C62D7ADAD751") whereas global CA fingerprints are grouped by colons (e.g., "Fingerprint: B5:61:EB:EA:A4:DE:E4:25:4B:69:1A:98:A5:57:47:C2:34:C7:D9:71").