Understanding S/MIME Email Encryption (Part II)
February 24, 2025

Click here to read PDF edition (digital signature and timestamp with global trust and global legal effect, all rights reserved, plagiarism is prohibited!
Please indicate when reprinting: Reprinted from ZoTrus CEO Blog)

This article continues the previous part "Understanding S/MIME Email Encryption (Part I)" and continues to explain S/MIME email encryption. In the previous part, the article focuses on the technical principles of S/MIME and two core products - S/MIME certificates and S/MIME clients. After reading the detailed introduction in the previous part, you may ask the following question: Why has such a good email encryption technology based on international standards not been widely used 27 years since the international standards were formed? This is a good question. This part will explain this problem, explain the difficulties encountered in implementing S/MIME email encryption, and briefly explain how ZoTrus Technology solves these problems.

1. Why has S/MIME technology not been widely used?

To successfully use S/MIME technology to implement email encryption, users must purchase and apply for an S/MIME certificate from a CA. This is not just a matter of cost; there is also a certificate application process. Users must manually apply for a certificate according to the CA's process and complete email validation after receiving the email verification code. For email certificates that need to be bound to personal or corporate identities, users also need to submit relevant identity validation proof documents and wait for the CA to complete identity validation. Once the CA issues an email certificate, users need to configure the email certificate to an email client that supports S/MIME technology. The configuration methods of each email client are different, and the configuration process is very cumbersome. This is the first difficulty – S/MIME certificate application and configuration.

The second difficulty is key management. After users apply for email certificates from CA, they must manage the private and public keys of the certificates themselves and import these certificates into all email clients for use. If the certificate expires, a new certificate must be re-applied for. However, in order to decrypt previously encrypted emails, the expired certificate with private key must be kept available at any time for decrypting previously encrypted emails. These certificate management tasks are also very cumbersome, especially the private key protection password set when backing up the certificate must be remembered. Once forgotten, the certificate cannot be imported to decrypt encrypted emails.

The two difficulties are often stumped at the first step, where it is impossible to configure the email certificate to be used in the email client. The second difficulty is not just managing one certificate. Multiple mailboxes require multiple certificates, and all email certificates over the years must be managed. This management process is more complicated than managing SSL certificates. Once an SSL certificate expires, it is useless and does not need to be managed anymore. The two difficulties are huge obstacles to the popularization of S/MIME email encryption, making it impossible for S/MIME technology to be popularized.

2. How does ZoTrus Technology solve the application difficulties of S/MIME encryption?

To solve the two difficulties faced by S/MIME email encryption, we must learn from the popularization of HTTPS encryption and implement automatic certificate management like SSL certificate, including automatic email certificate application, automatic mailbox control validation, automatic certificate configuration for use, and automatic private key management. These automations are more difficult than automatic SSL/TLS certificate management, because they involve automatic certificate management for every email user, while SSL certificates only need to be implemented on each website, not on every website visitor.

ZoTrus Technology proposes corresponding automatic solutions to the two difficulties of S/MIME email encryption. This solution must be the integration of the email client and the CA system, and it must completely solve the current situation where the email client only uses certificates and the CA system only issues certificates. In fact, this integration capability is the advantage of ZoTrus Technology. The author (the company founder) has been engaged in CA business for 18 years and email client development for 4 years and knows the integration of the two.

In order to solve the first certificate application and configuration difficulty, ZoTrus Technology draws on the international standard for automatic management of SSL certificate (ACME) and the RFC8823 standard for automatic management of email certificates to achieve automatic issuance and configuration of dual-algorithm (RSA/SM2) S/MIME email certificates. Users only need to set up their mailboxes to send and receive emails normally. When user click the “Apply for certificate” in ZTmail App, ZTmail will automatically connect to ZoTrus Cloud CA System to automatically apply for dual-algorithm email certificates and configure the issued email certificates for email encryption and digital signature. Users do not need to purchase and apply for email certificates from CA, do not need to manually complete email control validation, and do not need to tediously configure email certificates. Everything is done automatically.

In order to solve the first certificate application and configuration difficulty, ZoTrus Technology draws on the international standard for automatic management of SSL certificate (ACME) and the RFC8823 standard and China GM/T standard’for automatic management of email certificates to achieve automatic issuance and configuration of dual-algorithm (RSA/SM2) S/MIME email certificates. Users only need to set up their mailboxes to send and receive emails normally. When user click the “Apply for certificate” in ZTmail App, ZTmail will automatically connect to ZoTrus Cloud CA System to automatically apply for dual-algorithm email certificates and configure the issued email certificates for email encryption and digital signature. Users do not need to purchase and apply for email certificates from CA, do not need to manually complete email control validation, and do not need to tediously configure email certificates. Everything is done automatically.

In order to solve the second difficulty of key management, ZoTrus Technology's innovative solution is to use the user's own mailbox to back up and save the user's private key and certificate. As long as the user's mailbox is there, the private key is there, and ZTmail can automatically obtain the private key to decrypt all encrypted emails, regardless of whether they are encrypted with an expired certificate or an unexpired certificate, and regardless of which device they are on. It can automatically obtain the key that the user has used to automatically decrypt all encrypted emails, and users don't have to worry about key management issues at all.

ZoTrus Technology uses an innovative client-to-cloud solution to achieve email certificate automation, and key management automation. The automations ensure that users can realize email encryption and decryption, email digital signature and signature verification without feeling, and realize S/MIME encryption and digital signature automatically. And this automation service is completely free, including free configuration of email certificates, free implementation of email encryption and digital signature.

3. What other enhancements have been made to ZoTrus email encryption automation service?

ZoTrus Technology not only realizes S/MIME certificate automation, but also brings innovations in email management. It is the integration of an AI assistant, where users can choose their own AI model and use their own model API key for smart email management. It can help draft, reply, polish, and translate emails when sending, and summarize, extract schedules, and detect fraud when receiving, greatly boosting email management efficiency and improving email management quality.

4. S/MIME technology can only be widely used if it is automated

Through the detailed explanation in the first half of this article, you can understand the history of S/MIME technology, the implementation principles of S/MIME encryption and digital signatures and understand S/MIME certificates and S/MIME clients. The second half of this article explains in detail why S/MIME technology is difficult to implement and how ZoTrus Technology innovatively solves this difficulty.

Just as the popularization of HTTPS encryption that everyone is familiar with benefits from the automatic management of SSL certificates, the only way to popularize S/MIME encryption is to use the automatic management of S/MIME certificates. Only by realizing the automatic management of S/MIME certificates can we truly take the first step in the implementation of S/MIME technology. ZoTrus Technology has not only taken this step, but also realized the second step of automatically managing keys on its own, and innovatively added the AI assistant . The automations perfectly realize the implementation of S/MIME standard technology, removing all technical barriers for the popularization of S/MIME technology to ensure global email security, allowing the ancient email to serve all mankind more securely.