The Entourage cryptography model uses public key encryption to send and receive digitally signed and encrypted e-mail messages. Encryption makes a message unreadable to anyone other than the intended recipient. To send an encrypted message, the sender must have a copy of the recipient’s digital certificateA file issued and verified by a third-party certificate authority that is used in the process of digitally signing or encrypting messages. A certificate is sometimes called a "digital ID" or "digital certificate.". The message is encrypted specifically for each recipient by using the recipient’s public key; it can be decrypted only by using the associated private key, which is stored on the recipient's computer. Entourage uses the sender’s keys to read and write encrypted messages in the Drafts or Sent Items folders, which allows users to review encrypted messages that they have created. If the sender has no digital certificate, this review is not possible.
A digital signature helps the recipient verify the sender’s identity and the message integrity. Digitally signing a message helps the recipient verify that you are the authentic sender and that the contents of the message were not altered in transit.
TipWe recommend that digital certificates have a key size of 1,024 bits or more. Using a digital certificate of this size makes it extremely difficult to decode an encrypted message or forge a digital signature. For more information about the digital certificate key size, see Entourage Help.
To | The digital certificate requirement is |
|---|---|
Send an encrypted message | The sender must have a copy of each recipient’s digital certificate. The sender does not need to have a digital certificate of his or her own. However, if the sender does not have a digital certificate, he or she will not be able to read the saved message in the Draft or Sent Items folder, and will not be able to receive an encrypted response from a recipient. |
Receive an encrypted message | The recipient must have a digital certificate of his or her own. The sender must have a copy of the recipient's digital certificate in order to encrypt the message. Entourage 2008 can encrypt messages with any of the following encryption algorithmsA method for encrypting a message and its attachment.: AES-256, AES-192, AES-128, and 3DES. Of these four algorithms, 3DES is the most compatible with other S/MIME applications and AES-256 is the most secure. Entourage 2008 supports the following signing algorithmsA method for protecting the integrity of a digital signature. for digital signatures, which are listed from strongest to weakest: SHA-512, SHA-384, SHA-256, and SHA-1. Of these four algorithms, SHA-1 is the most compatible with other S/MIME application, and SHA-512 is the most secure. |
Send a digitally-signed message | The sender must have a digital certificate of his or her own. |
Receive a digitally-signed message | The recipient does not need a digital certificate of his or her own. |



