S/MIME Installation in Mozilla Thunderbird

Introduction

Installing an S/MIME certificate in Thunderbird provides you with a secure and trustworthy method for encrypting and signing your emails. By using this certificate, you not only increase the security of your communications but also actively protect your personal and business information from unauthorized access.

Prerequisites

  • S/MIME certificate (can be purchased through our Customer Center)
  • Mozilla Thunderbird



Exporting the S/MIME Certificate as a PFX File

To install it in Thunderbird, we need the S/MIME certificate as a .pfx file. The certificate can be exported directly as a .pfx file via our Customer Center.


To do this, navigate to the Certificate Manager and select the desired S/MIME certificate (email certificate). Under the "Settings" section, you can export the certificate as a PFX file.


Next, choose a password for the .pfx file; your email client will prompt you for this password later when importing the file.


If you forget your password, you can re-export the certificate from the Customer Center and set a new password for the .pfx file.



Installing the S/MIME Certificate

Once the certificate has been exported as a .pfx file, you can add the S/MIME certificate to Thunderbird.


To do this, open Thunderbird and navigate to the account settings for the email account where you want to store the S/MIME certificate. Here, you can select end-to-end encryption in your email account settings, where you’ll find the S/MIME section.


Click the “Manage S/MIME Certificates” button to open Thunderbird’s certificate manager and import the certificate you downloaded earlier.


During import, you must enter the password that was assigned during export. The S/MIME certificate will then appear in Thunderbird’s certificate manager.


Click the OK button to exit the Certificate Manager.


The certificate is automatically assigned to the corresponding mailbox if the certificate’s email address matches that of the mailbox. If this is not the case, you can select the previously imported certificate by clicking the Select… button.



S/MIME Settings

Additional settings can then be configured later via the S/MIME settings.


Setting Description
Encrypt new messages By default, new messages are not automatically encrypted, as the recipient must possess the certificate to decrypt the message.
Digitally sign unencrypted messages To have new messages automatically signed, you must enable this setting