<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Outlook S/MIME certificate selection</title><link>http://blogs.technet.com/b/pki/archive/2008/12/17/outlook-s-mime-certificate-selection.aspx</link><description>Consider that you are sending an encrypted eMail to a recipient who has multiple certificates stored in Active Directory. The key question is: Which certificates are selected by Outlook 2003/2007? When sending an encrypted eMail, Outlook actually requires</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Outlook S/MIME certificate selection</title><link>http://blogs.technet.com/b/pki/archive/2008/12/17/outlook-s-mime-certificate-selection.aspx#3459105</link><pubDate>Thu, 13 Oct 2011 15:04:40 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3459105</guid><dc:creator>Markus</dc:creator><description>&lt;p&gt;Is any more insight available, how the &amp;quot;first&amp;quot; is calculated: &amp;nbsp;&amp;quot;If the default certificate is not found, the *first* valid certificate in the store is selected.&amp;quot; How is the list ordered exactly?&lt;/p&gt;
&lt;p&gt;I need to know this, because we need a alerting, if a user has a functioning S/MME certificate. We need a tool that matches the my store of the users with his AD store and shows possible inconsistencies, introduced by migration of old AD with their own PKI in the central company AD one.&lt;/p&gt;
&lt;p&gt;I know how to eliminate invalid certificates (out of life time, no purpose &amp;quot;Secure email&amp;quot;) and I have learned that a certificate from a AD integrated PKI is always higher prioritized than that of a non-AD integrated PKI. I had assumed that &amp;quot;first&amp;quot; means either &amp;quot;the first entry in the multivalued ldap attribute&amp;quot; or &amp;quot;the one with the oldest starting time&amp;quot;. But exact tests are difficult and my results are not consistente yet. If I would knew the *exact* algorithm to choose the certificate for the S/MIME mail, that would help.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3459105" width="1" height="1"&gt;</description></item><item><title>re: Outlook S/MIME certificate selection</title><link>http://blogs.technet.com/b/pki/archive/2008/12/17/outlook-s-mime-certificate-selection.aspx#3450109</link><pubDate>Tue, 30 Aug 2011 20:04:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3450109</guid><dc:creator>Stephen</dc:creator><description>&lt;p&gt;Interesting and informative... However I&amp;#39;m trying to figure out why Outlook 2010 is choosing an expired certificate as the default, over a new valid certificate, from the offline address book. &amp;nbsp;Both certificates are in usercertificate attribute in AD. &amp;nbsp;I can&amp;#39;t figure out if Outlook is blindly selecting the expired certificate without checking its validity period, or if something in the oab is explicitly telling Outlook to use the older certificate as the default. &amp;nbsp;Either way, the behavior is somewhat problematic during the cleanup plus propagation delay for getting expired certificates out of users&amp;#39; oabs.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3450109" width="1" height="1"&gt;</description></item><item><title>re: Outlook S/MIME certificate selection</title><link>http://blogs.technet.com/b/pki/archive/2008/12/17/outlook-s-mime-certificate-selection.aspx#3357178</link><pubDate>Wed, 22 Sep 2010 19:42:53 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3357178</guid><dc:creator>Jack</dc:creator><description>&lt;p&gt;I have some questions.&lt;/p&gt;
&lt;p&gt;S/MIME will use the User Certificate, right?&lt;/p&gt;
&lt;p&gt;Can we push all users certificates on Exchange server GAL (global address list)? If yes, how to push them? &lt;/p&gt;
&lt;p&gt;Then Outlook will look for user certificate in GAL first; If not find, then outlook will search user certificate in Active Directory user object attributes, correct?&lt;/p&gt;
&lt;p&gt;Thanks&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3357178" width="1" height="1"&gt;</description></item><item><title>re: Outlook S/MIME certificate selection</title><link>http://blogs.technet.com/b/pki/archive/2008/12/17/outlook-s-mime-certificate-selection.aspx#3357167</link><pubDate>Wed, 22 Sep 2010 19:12:31 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3357167</guid><dc:creator>Jack W</dc:creator><description>&lt;p&gt;It makes the understanding of S/MIME much easier. Save much time.&lt;/p&gt;
&lt;p&gt;Thank you&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3357167" width="1" height="1"&gt;</description></item></channel></rss>