Google S/MIME Setup
1
Enable the Google Admin SDK API
- Go to the Google Admin SDK API in Google Console.
- Click the Enable button and wait for it to finish.
- It will redirect you to the SDK API management page.
2
Enable the Gmail SDK API
- Go to the Gmail SDK API in Google Console.
- Click the Enable button and wait for it to finish.
- It will redirect you to the SDK API management page.
3
Enable S/MIME for Gmail
- Go to Gmail User Settings in Google Admin.
- Click the section at the bottom for “S/MIME”.
- Check Enable S/MIME encryption for sending and receiving emails.
- Check Allow users to upload their own certificates.
- ClickSave.
4
Enable Client-Side Encryption for Gmail (if using CSE with S/MIME)
- Go to Client-Side Encryption in Google Admin.
- In the “Assignment” section, under “Encryption status by app”, click Edit for Gmail.
- Select On and click Save.
Ordering Certificates for Users
- Select S/MIME (/flow/smime) in the Qanapi App.
- Click the Manage link on the Provider.
- Select the non-active users you wish to enable by clicking the checkbox next to each one.
- Click the Enable button.
- Certificates will be ordered for each selected user, and the status will change to Pending Order.
- Once the order has processed in the background, the status will change to Pending Approval and the user will receive an email to verify their email address.
- Users will follow the link in the email and click the Approve button.
- The status will change to Pending Upload, and the app will attempt to upload the certificate (or CSE Identity) to Gmail. This may take up to 5 minutes.
- After a successful upload, the status will change to Active.
You may view a user’s Gmail certificate information by clicking the “Certificate Info” button next to a user on
the Qanapi S/MIME management page
Cancelling Certificates for Users
- Select S/MIME (/flow/smime) in the Qanapi App.
- Click the Manage link on the Provider.
- Select the active users you wish to disable by clicking the checkbox next to each one.
- Click the Disable button.
- Users will have their status updated to Pending Cancellation.
- The certificate (or CSE Identity) will be removed from Gmail and the status will update to Cancelled.
Sending a signed email
- In Gmail, open a new draft email by clicking the “Compose” button.
- Click the lock icon () in the top right of the email.
- Under “Digital Signature”, click the “Sign Message” option.
- Draft the email and click “Send”.
- Once sent, the email should have a certificate icon () under the sender’s name.
Encrypting emails
To send encrypted emails with another email address, both senders must first send signed emails to exchange public certificates.- In Gmail, draft and send a signed email to the desired recipient.
- The recipient must do the same, replying to the first email with their own signed email.
- Begin a reply to this email and click the lock icon () in the top right of the email.
- Under the “Additional encryption” section, click the “Turn on” link. A verification dialog may open a warning about the loss of any existing body to the email.
- Draft the email and click “Send”. This may take a few seconds as Gmail encrypts the email.
- Once sent, the email should have a green lock icon () or blue shield icon () under the sender’s name.
A green lock icon denotes Hosted S/MIME, where Gmail uses certificates uploaded from Qanapi.
A blue shield icon denotes CSE-wrapped S/MIME, where Gmail uses Qanapi’s Client-Side Encryption
A blue shield icon denotes CSE-wrapped S/MIME, where Gmail uses Qanapi’s Client-Side Encryption
Troubleshooting
Error on Upload: Feature Not Enabled
Error on Upload: Feature Not Enabled
The most likely cause is that the user was created recently. Google needs time to replicate its changes. This can
take several minutes to several hours.
Error on Upload: KACLS URI Mismatch
Error on Upload: KACLS URI Mismatch
This happens when using Google’s Client-Side Encryption where the Key
Service is set to a different URI than the Provider Configuration.
Unable to decrypt an email sent by someone else
Unable to decrypt an email sent by someone else
The most likely cause is failure to exchange signatures before sending encrypted emails. The signature exchange
allows Gmail to capture the sender’s public encryption keys in order to properly encrypt emails.