#smime — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #smime, aggregated by home.social.
-
AS2 в .NET без отдельного Java-гейтвея: EDI-обмен с партнёрами прямо в маршруте
Если вы поставляете товар в крупную розницу, возите грузы для 3PL-оператора, шлёте платёжные извещения банку или обмениваетесь медицинскими транзакциями X12 — вы почти наверняка обмениваетесь этими документами по AS2 . Заказ (EDI 850), счёт (810), уведомление об отгрузке (856), платёжное авизо (820) уходят партнёру не почтой и не через REST, а как подписанный и зашифрованный S/MIME-конверт поверх HTTP, с подписанной квиткой-распиской в ответ. Так работает регламентированный B2B-документооборот в рознице, логистике, финансах, производстве и здравоохранении уже двадцать лет: Walmart, Amazon и их сети поставщиков, банки с host-to-host каналом, автопром, дистрибьюторы — все требуют AS2. В .NET до сих пор было два пути. Либо коммерческий AS2-шлюз — Cleo, Seeburger, BizTalk — отдельная коробка, отдельная лицензия, отдельная команда сопровождения. Либо Java-сервер с открытым кодом — OpenAS2, Mendelson Community — отдельный JVM-процесс рядом с вашим .NET-бэкендом, со своим inbox-каталогом, откуда документы надо ещё забирать джобой. В обоих случаях AS2 живёт сбоку от вашей интеграции, а не внутри неё. redb.Route.AS2 закрывает этот разрыв: AS2 становится обычным шагом маршрута в вашем .NET-процессе. Приняли конверт от партнёра, расшифровали, проверили подпись, отдали документ в pipeline — провалидировали, трансформировали, положили в Kafka или SQL — и вернули партнёру подписанную расписку. Один процесс, один деплой, одна панель наблюдаемости. Разберём, как это выглядит в коде, где применяется и почему нативный коннектор в ESB выигрывает у отдельного шлюза.
https://habr.com/ru/articles/1069840/
#AS2 #EDI #X12 #EDIFACT #SMIME #MDN #B2B #ESB #NET #redbRoute
-
Kleiner Hinweis an @mailbox_org bzgl. Überweisung von Guthaben:
Gestern nachmittag eine Sofortüberweisung an #posteo vorgenommen.
Heute um kurz vor 09:00 Uhr die Bestätigung erhalten:
»Ihrem Posteo Guthaben wurden soeben 20,00 EUR gutgeschrieben.«
Dieses Guthaben reicht dann für über 15 Monate eMail / Kalender sowie ein S/MIME-Zertifikat.
-
Kleiner Hinweis an @mailbox_org bzgl. Überweisung von Guthaben:
Gestern nachmittag eine Sofortüberweisung an #posteo vorgenommen.
Heute um kurz vor 09:00 Uhr die Bestätigung erhalten:
»Ihrem Posteo Guthaben wurden soeben 20,00 EUR gutgeschrieben.«
Dieses Guthaben reicht dann für über 15 Monate eMail / Kalender sowie ein S/MIME-Zertifikat.
-
Ihr habt einen E-Mail-Account bei #posteo_de ? Ihr nutzt #smime ?
Dann prüft doch bitte, wie lange euer Zertifikat gültig ist!
Mein Zertifikat läuft im Laufe der kommenden Woche aus; deswegen habe ich es heute erneuert.
-
Ihr habt einen E-Mail-Account bei #posteo_de ? Ihr nutzt #smime ?
Dann prüft doch bitte, wie lange euer Zertifikat gültig ist!
Mein Zertifikat läuft im Laufe der kommenden Woche aus; deswegen habe ich es heute erneuert.
-
I have been using SMIME certificates from Comodo SSL Store and from SwissSign. With both, I run into the situation that the certificate got invalidated during the lifetime of 3 years (Comodo) or 2 years (SwissSign).
Where do you have your SMIME certificates from?
Did your certificate ever got invalidated?
Do you use an automated process to request the certificates? -
Bei S/MIME ist das Zertifikat der Schlüssel zur sicheren E-Mail.
S/MIME ist ein bewährter und weit verbreiteter Standard für E-Mail-Verschlüsselung und digitale Signaturen. Um S/MIME zu nutzen, benötigen Nutzende ein Zertifikat von einer sogenannten Certificate Authority.
- Was enthalten diese Zertifikate?
- Welche Arten gibt es?
- Wo sind sie erhältlich?
- Welche Zertifikate unterstützt mailbox?Erfahren Sie mehr dazu in unserem Blog: https://mailbox.org/de/blog/smime-e-mails-sicher-verschluesseln-und-signieren/
-
Bei S/MIME ist das Zertifikat der Schlüssel zur sicheren E-Mail.
S/MIME ist ein bewährter und weit verbreiteter Standard für E-Mail-Verschlüsselung und digitale Signaturen. Um S/MIME zu nutzen, benötigen Nutzende ein Zertifikat von einer sogenannten Certificate Authority.
- Was enthalten diese Zertifikate?
- Welche Arten gibt es?
- Wo sind sie erhältlich?
- Welche Zertifikate unterstützt mailbox?Erfahren Sie mehr dazu in unserem Blog: https://mailbox.org/de/blog/smime-e-mails-sicher-verschluesseln-und-signieren/
-
Gerne würde ich mehr #Verschlüsselung bei #Email nutzen können. Du?
Nutzt Du Verschlüsselung?#DSGVO #Datenschutz #PGP #SMIME #Thunderbird #Tuta #Tutanota #Proton #Mailbox #Posteo #Mozilla #Firefox #FirefoxThunderbird
-
Gerne würde ich mehr #Verschlüsselung bei #Email nutzen können. Du?
Nutzt Du Verschlüsselung?#DSGVO #Datenschutz #PGP #SMIME #Thunderbird #Tuta #Tutanota #Proton #Mailbox #Posteo #Mozilla #Firefox #FirefoxThunderbird
-
Ihre Konkurrenz liest mit? Nicht mit S/MIME.
Die Ende-zu-Ende-Verschlüsselung mit S/MIME macht E-Mails für ungebetene Mitleser zum unknackbaren Datensalat.
Erfahren Sie, wie S/MIME-Verschlüsselung im Detail funktioniert und wie Sie S/MIME bei mailbox nutzen können: https://mailbox.org/de/blog/smime-e-mails-sicher-verschluesseln-und-signieren/
-
Ihre Konkurrenz liest mit? Nicht mit S/MIME.
Die Ende-zu-Ende-Verschlüsselung mit S/MIME macht E-Mails für ungebetene Mitleser zum unknackbaren Datensalat.
Erfahren Sie, wie S/MIME-Verschlüsselung im Detail funktioniert und wie Sie S/MIME bei mailbox nutzen können: https://mailbox.org/de/blog/smime-e-mails-sicher-verschluesseln-und-signieren/
-
Ist diese E-Mail wirklich von Ihrer Chefin?
S/MIME-Signaturen schaffen Klarheit: Sie beweisen zweifelsfrei, wer der Absender ist und ob die Nachricht manipuliert wurde. Das macht Phishing-Angreifern den Alltag schwer.
Erfahren Sie in unserem Blog, wie die Signatur mit S/MIME im Detail funktioniert: https://mailbox.org/de/blog/smime-e-mails-sicher-verschluesseln-und-signieren/
-
Ist diese E-Mail wirklich von Ihrer Chefin?
S/MIME-Signaturen schaffen Klarheit: Sie beweisen zweifelsfrei, wer der Absender ist und ob die Nachricht manipuliert wurde. Das macht Phishing-Angreifern den Alltag schwer.
Erfahren Sie in unserem Blog, wie die Signatur mit S/MIME im Detail funktioniert: https://mailbox.org/de/blog/smime-e-mails-sicher-verschluesseln-und-signieren/
-
@ueckueck @datenpunks
Sehr gut. Eine CC-Lizenz oder ähnliches wäre wünschenswert, für den Fall dass ich dazu etwas in meine #PGP oder #SMIME Workshops einbauen könnte 😜 -
@ueckueck @datenpunks
Sehr gut. Eine CC-Lizenz oder ähnliches wäre wünschenswert, für den Fall dass ich dazu etwas in meine #PGP oder #SMIME Workshops einbauen könnte 😜 -
What is S/MIME and how does it contribute to email security?
The email correspondence of more than 4.5 billion users worldwide is exposed to attacks every day. This makes reliable encryption and digital signature solutions all the more important.
Find out how you can protect your email communication with S/MIME, ensure the authenticity of your correspondence and use S/MIME with mailbox: https://mailbox.org/en/blog/smime-encrypt-and-sign-emails-securely/
-
What is S/MIME and how does it contribute to email security?
The email correspondence of more than 4.5 billion users worldwide is exposed to attacks every day. This makes reliable encryption and digital signature solutions all the more important.
Find out how you can protect your email communication with S/MIME, ensure the authenticity of your correspondence and use S/MIME with mailbox: https://mailbox.org/en/blog/smime-encrypt-and-sign-emails-securely/
-
Surprise, the local part of email addresses, i.e. the part in front of the @-character, is per RFC case-sensitive. Do not mess with the local part.
Relevant when sending out challenge mails, account validation mails, password reset mails, issuing S/MIME certificates, etc.
Luckily a lot of the internet infra just ignores the case, but Apple Mail does not.
-
Surprise, the local part of email addresses, i.e. the part in front of the @-character, is per RFC case-sensitive. Do not mess with the local part.
Relevant when sending out challenge mails, account validation mails, password reset mails, issuing S/MIME certificates, etc.
Luckily a lot of the internet infra just ignores the case, but Apple Mail does not.
-
Was ist S/MIME und wie trägt es zur E-Mail-Sicherheit bei?
Die E-Mail-Korrespondenz von mittlerweile über 4,5 Milliarden Nutzern weltweit ist täglich Angriffen ausgesetzt. Umso wichtiger sind verlässliche Lösungen zur Verschlüsselung und digitalen Signatur.
Erfahren Sie, wie Sie mit S/MIME Ihre E-Mail-Kommunikation schützen, die Authentizität Ihrer Korrespondenz gewährleisten und S/MIME bei mailbox einsetzen: https://mailbox.org/de/blog/smime-e-mails-sicher-verschluesseln-und-signieren/
-
Was ist S/MIME und wie trägt es zur E-Mail-Sicherheit bei?
Die E-Mail-Korrespondenz von mittlerweile über 4,5 Milliarden Nutzern weltweit ist täglich Angriffen ausgesetzt. Umso wichtiger sind verlässliche Lösungen zur Verschlüsselung und digitalen Signatur.
Erfahren Sie, wie Sie mit S/MIME Ihre E-Mail-Kommunikation schützen, die Authentizität Ihrer Korrespondenz gewährleisten und S/MIME bei mailbox einsetzen: https://mailbox.org/de/blog/smime-e-mails-sicher-verschluesseln-und-signieren/
-
The S/MIME certificate of my "private" e-mail address will expire next month, and I wonder what recommendable S/MIME providers are out there. So far, I found:
- WISeID: https://wiseid.com/pricing/
- Actalis (https://www.actalis.com/s-mime-certificates) whose root cert I find at
/usr/share/ca-certificates/mozilla/Actalis_Authentication_Root_CA.crt. So, I suppose they stopped trying get their root cert installed into the trust store via separate ways?!? - Certum (https://shop.certum.eu/ssl.html) which I used so far.
If nothing else pops up, I'll opt for Certum due to the company being in the EU.
btw, I use OpenPGP for the "community" e-mail address (https://duxsco.de/my_openpgp_public_key/). So, let's not get into S/MIME vs OpenPGP discussions 😉
-
Mein bisheriger Fortschritt beim #diday #didit #dutgemacht ... ein Prozess über Jahre und nicht von heute auf morgen. Aber Schritt für Schritt:
Weg von #Meta zu #Mastodon bei @digitalcourage
#Email bei #Posteo (mit #Thunderbird #PGP und #SMIME - leider kaum Behörden mit Verschlüsselung)
#Alias bei #unboxAT
#Cloud eine managed #Nextcloud
#Passwortmanager ist @keepassxc
Wo es geht #2FA mit #enteauth
#Foto geht zu @ente
Ein #ThinkPad T480 gebraucht gekauft und gleich #Linux mint drauf gemacht (aussehen wie macOS)
#Firefox nach der Anleitung von @kuketzblog
#WhatsApp gelöscht stattdessen @signalapp mit @mollyim und @threemaapp mit #ThreemaLibre
Vom #iPhone11Pro zum #fairphone5 und dort selbst #eOS @e_mydata drauf installiert.
Daheim ein #raspberrypi mit #AdGuardHome
Verschlüsselung per @cryptomatorProjekte:
#yunohost
AdGuardHome per #VPNZuhause noch einen iMac 27“ 5K (2017) mit macOS. Dort wird irgendwann auch Linux drauf kommen.
Bin selbst kein ITler... darum gerne offen für Tipps.
-
Mein bisheriger Fortschritt beim #diday #didit #dutgemacht ... ein Prozess über Jahre und nicht von heute auf morgen. Aber Schritt für Schritt:
Weg von #Meta zu #Mastodon bei @digitalcourage
#Email bei #Posteo (mit #Thunderbird #PGP und #SMIME - leider kaum Behörden mit Verschlüsselung)
#Alias bei #unboxAT
#Cloud eine managed #Nextcloud
#Passwortmanager ist @keepassxc
Wo es geht #2FA mit #enteauth
#Foto geht zu @ente
Ein #ThinkPad T480 gebraucht gekauft und gleich #Linux mint drauf gemacht (aussehen wie macOS)
#Firefox nach der Anleitung von @kuketzblog
#WhatsApp gelöscht stattdessen @signalapp mit @mollyim und @threemaapp mit #ThreemaLibre
Vom #iPhone11Pro zum #fairphone5 und dort selbst #eOS @e_mydata drauf installiert.
Daheim ein #raspberrypi mit #AdGuardHome
Verschlüsselung per @cryptomatorProjekte:
#yunohost
AdGuardHome per #VPNZuhause noch einen iMac 27“ 5K (2017) mit macOS. Dort wird irgendwann auch Linux drauf kommen.
Bin selbst kein ITler... darum gerne offen für Tipps.
-
Selbst ist der #Nerd: Nachdem zuerst die web gui bei @mailbox_org meinen neuen p12 #sMime Schlüssel nicht importieren wollte. Einfach lokal via #OpenSSL in Private Key und Zertifikate zerlegt, wieder zu einem neuen p12 File vereint und hochgeladen. Siehe da: Funktioniert! 🤓 Der Fehler mag beim Aussteller oder beim Importieren liegen, wer weiß. Hauptsache gelöst.
-
Selbst ist der #Nerd: Nachdem zuerst die web gui bei @mailbox_org meinen neuen p12 #sMime Schlüssel nicht importieren wollte. Einfach lokal via #OpenSSL in Private Key und Zertifikate zerlegt, wieder zu einem neuen p12 File vereint und hochgeladen. Siehe da: Funktioniert! 🤓 Der Fehler mag beim Aussteller oder beim Importieren liegen, wer weiß. Hauptsache gelöst.
-
Mich würde interessieren, welcher Anteil der Fediverse Nutzer ihre e-Mails mit OpenPGP oder S/MIME signieren oder verschlüsseln.
Bitte gerne teilen/boosten.
---------------
I'd be interested to know what percentage of Fediverse users sign or encrypt their e-Mails with OpenPGP or S/MIME.
Please share/boost.
-
Mich würde interessieren, welcher Anteil der Fediverse Nutzer ihre e-Mails mit OpenPGP oder S/MIME signieren oder verschlüsseln.
Bitte gerne teilen/boosten.
---------------
I'd be interested to know what percentage of Fediverse users sign or encrypt their e-Mails with OpenPGP or S/MIME.
Please share/boost.
-
@Hopfi
Ja der Funktionsumfang kann einen anfangs erschlagen, aber man arbeitet sich rasch ein. Nur manchmal muss man für die "Feinabstimmung" in den Einstellungen suchen.Das für mich Wichtigste an dieser App ist, dass sowohl #SMIME als auch #PGP unterstützt wird.
Support gibt es u.a. per e-Mail und der Entwickler ist wirklich bemüht alle Fragen so gut als möglich zu beantworten
-
Thunderbird 144 arrives with Flatpak update and a flood of crucial fixes
https://web.brid.gy/r/https://nerds.xyz/2025/10/thunderbird-144/
-
Für den Fall das jemand nach einem kostenlosen #smime #zertifikat sucht um seine E-Mails zu signieren oder zu verschlüsseln.
Bei #actalis actalis.com kann man sich kostenlose eins für ein Postfach für 1 Jahr anfordern und herunterladen.
-
Not promoting Google here because they long ago jumped the shark, but E2E encryption is nice.
-
Not promoting Google here because they long ago jumped the shark, but E2E encryption is nice.
-
Nutzt hier irgendwer verschlüsselte Mails via PGP oder S/MIME? Privat oder für die Arbeit?
-
Nutzt hier irgendwer verschlüsselte Mails via PGP oder S/MIME? Privat oder für die Arbeit?
-
RIP #Volksverschlüsselung, du wirst nicht vermisst werden! https://www.heise.de/news/Bald-ist-Schluss-Volksverschluesselung-wird-eingestellt-10637044.html
Warum wählen eigentlich Projekte, die verschlüsselte Kommunikation massentauglich machen wollen, regelmäßig so beknackte Nerd-Namen und -Akronyme? 🙄 Siehe auch p≡p.
-
RIP #Volksverschlüsselung, du wirst nicht vermisst werden! https://www.heise.de/news/Bald-ist-Schluss-Volksverschluesselung-wird-eingestellt-10637044.html
Warum wählen eigentlich Projekte, die verschlüsselte Kommunikation massentauglich machen wollen, regelmäßig so beknackte Nerd-Namen und -Akronyme? 🙄 Siehe auch p≡p.
-
TIL (Today I learned) about RFC9495 https://datatracker.ietf.org/doc/rfc9495/ that extends RFC8659 by adding a new CAA property in DNS called "issuemail" that defines wich CA(s) (Certification Authorities) are allowed to create S/MIME eMail certificates for a domain. And if you don't use S/MIME, you should set it to ";" which means that no CA is allowed to do that.
So I added
CAA 0 issuemail ";"
to the dns of my domains until my CA (Certificate Authority) can produce S/MIME certificates.
-
TIL (Today I learned) about RFC9495 https://datatracker.ietf.org/doc/rfc9495/ that extends RFC8659 by adding a new CAA property in DNS called "issuemail" that defines wich CA(s) (Certification Authorities) are allowed to create S/MIME eMail certificates for a domain. And if you don't use S/MIME, you should set it to ";" which means that no CA is allowed to do that.
So I added
CAA 0 issuemail ";"
to the dns of my domains until my CA (Certificate Authority) can produce S/MIME certificates.
-
Happily sending around signed and encrypted emails that use S/MIME certificates that I created myself on my own CA. And as my mail server (that I also run myself) has DKIM, DMARC, SPF set up correctly, that also works. Nice!
-
Happily sending around signed and encrypted emails that use S/MIME certificates that I created myself on my own CA. And as my mail server (that I also run myself) has DKIM, DMARC, SPF set up correctly, that also works. Nice!
-
So now that I have my own s/mime certificate generated and installed, here's the SHA256 fingerprint:
19dae1a388af5c91e3dc53d89e3efdaef3f24878b9d37f809463ee801f3eae25
Should you get an email from me, it will be signed and with this fingerprint you can verify that indeed it was me who sent it.
I know almost no one will ever actually do this verification, but it is reassuring to me that you can :)
-
So now that I have my own s/mime certificate generated and installed, here's the SHA256 fingerprint:
19dae1a388af5c91e3dc53d89e3efdaef3f24878b9d37f809463ee801f3eae25
Should you get an email from me, it will be signed and with this fingerprint you can verify that indeed it was me who sent it.
I know almost no one will ever actually do this verification, but it is reassuring to me that you can :)
-
I have brain dumped the process at https://codeberg.org/jwildeboer/gists/src/branch/main/2025/20250803SmimeCertStepCA.md and will work on an extended version as blog post in the next few days. Big shoutout to @ben again for getting the process up and running in the first place!
If you want to get a signed email from me to see what happens in your mail client, DM me an email address and I will send a s/mime signed email to you :)
6/6
-
I have brain dumped the process at https://codeberg.org/jwildeboer/gists/src/branch/main/2025/20250803SmimeCertStepCA.md and will work on an extended version as blog post in the next few days. Big shoutout to @ben again for getting the process up and running in the first place!
If you want to get a signed email from me to see what happens in your mail client, DM me an email address and I will send a s/mime signed email to you :)
6/6
-
If I understand the whole s/mime stuff correctly, I can send you a signed email and your mail client should be able to extract my public key from that. You reply with a signed mail, I can extract your public key. Now we can send encrypted emails :) Your mail client/operating system won't trust my certificate as it is signed by my CA (Certificate Authority), but it should still work.
5/6
-
If I understand the whole s/mime stuff correctly, I can send you a signed email and your mail client should be able to extract my public key from that. You reply with a signed mail, I can extract your public key. Now we can send encrypted emails :) Your mail client/operating system won't trust my certificate as it is signed by my CA (Certificate Authority), but it should still work.
5/6
-
After some help from @ben and some swearing about PKCS12 (add a password when you package the .p12 file so that Android and iOS will be able to import it) and Keychain on MacOS, it’s working. S/mime signed and encrypted mails with certificates from my own CA.
4/6
-
If you want to play with free S/MIME certs for e-mail signing and encryption, https://acme.castle.cloud does that letsencrypt style with ACME and certbot :) Made and operated by the Centre Tecnològic de Telecomunicacions de Catalunya (CTTC). A non-profit research institution based in Castelldefels (Barcelona).
3/6