Honor the Dead by Helping the Living

Veterans of Foreign Wars
Post & Auxiliary 12093
'John Lukac'

Installing an Email Certificate in Thunderbird

EMAIL SECURITY

Post Officers and Committee Chairs are given Post e-maIL addresses for OFFICIAL USE. Plain e-mail is naked. Think of a postcard pinned up to the bulletin board at the local market. NO SECURITY. To deal with this issue, people should use email certificates to at least "sign" their email so that the recipient knows it is legitimate and unchanged. Certificates also allow encryption for protecting private information. Here is how to get and install a certificate using Firefox and Thunderbird:

Obviously, your e-mail address is not postmaster so change that to your address when following these instructions. The setup process is actually easy but writing it all down makes it look daunting. Be dauntless as you were when in uniform!

It is assumed you already have Thunderbird installed on your computer. If you have not already installed Thunderbird, go to THUNDERBIRDHow to Install and Setup Thunderbird.

  1. Using your web browser (Firefox) go to Comodo Free Email Certificate
  2. On the left you should see a "Sign Up Now" button. Click on the "Sign Up Now" button.
  3. You now must fill in the few pieces of information needed.
  4. For First Name, use your position (i.e. Postmaster).
  5. For Last Name, use "VFW Post 12093".
  6. For the E-mail Address, use your official Post email (i.e. "postmaster@vfwpost12093.org").
  7. Leave country "United States" and Key Size "High Grade".
  8. Choose a revocation password. I encourage you to use the password for your email account.
  9. Choose whether to opt in for Comodo's advertising.
  10. Click on "Accept" for the license terms.
  11. Click on "Next" which will generate the encryption key pairs and the certificate.

You will be quickly taken to a screen congratulating you on creating a certificate and telling you instructions have been emailed to the address you entered.

  1. Start Thunderbird and go to the email address for which you created the certificate.
  2. If you chose to opt in to the Comodo mailings, there will be an email with a link for you to click on to confirm the email address.
  3. You should also have an email from Certificate Customer Services entitled "Your certificate is ready for collection!" Open that email.
  4. In the email, there will be a button labelled "Click & Install Comodo Email Certificate". Click on that button.
  5. This will take you back to your browser window saying you are attempting to retrieve the certificate. You should get a pop up window telling you the certificate was successfully installed.

The certificate is installed in Firefox. We need to copy it to Thunderbird.

  1. In Firefox at the upper right, you should have a set of 3 horizontal lines. Left mouse click on those lines.
  2. You should get a pop up window. Click on "preferences".
  3. On the left, you should have several options. Click on "Advanced".
  4. Across the top you have several options, click on "Certificates".
  5. Click on the "View Certificates" button at the bottom left of the verbiage.
  6. At the top of the pop up screen, ensure you are on "Your Certificates".
  7. In the body of the window, you should see a list of certificates (perhaps only one). Find the one that shows E= and the email address for which you just created the certificate.
  8. Highlight that certificate and then click on the "Back up..." button at the bottom of the list.
  9. Chose the location and name of the back up file you will create. I use the year and the email address without any punctuation or the @ symbol (i.e. "2017postmastervfwpost12093com")
  10. The system adds the correct extension after the dot and then asks you to enter twice a "backup password". I use the same password I set for revocation; the email password.
  11. This creates a backup where you specified with the name you specified.

Now we install the certificate into thunderbird.

  1. Open Thunderbird.
  2. You should see a pane on the left with a list of your e-mail account configurations. Right mouse click the account to secure (i.e. "postmaster@vfwpost12093.org").
  3. Left mouse click on "Settings". This should let you configure the account.
  4. Left mouse click on "Security" under the email address on the left.
  5. On the right, click on "Manage Certificates".
  6. You should get a very similar pop up window to the one we saw in Firfox. Ensure you are on the "Your Certificates" tab.
  7. Click on "Import..." at the bottom.
  8. Go to the location of your back up file and select it. (i.e. "2017postmastervfwpost12093com")
  9. Click "Open".
  10. You will be asked for the password you created when you backed up the file. (i.e. Email password) Enter it and click on "OK".

Now that you have the certificate in Thunderbird you want to tell Thunderbird how to use it.

  1. On the same security page above the "Manage Certificates", you have two fields. One for Digital Signing and one for Encryption. We want to set up both.
  2. Under Digital Signing, click on the "select" button.
  3. A pop up window will appear. At the top is a pull down with all your certificates. In the field below is the details including the email address. It should already have found the certificate we just imported.
  4. Click "OK".
  5. A pop up should appear asking if you want to use the same certificate if someone sends you an encrypted message. Click on "Yes".
  6. Both the Digital Signing and Encryption fields should now have your certificate listed.
  7. You will want to click on the "Digitally sign messages (by default)" check box under the Digital Signing Certificate field.
  8. You will want to select the "Never (do not use encryption)" radio button under the Encryption certificate field.
  9. These last two options will cause you to digitally sign anything you send unless you override it for a specific message in the creation window and not encrypt unless you overrride that similarly.
  10. All done. You can close any open windows.
  11. June 1, 2017 by "Good Time"