Avantec AG
Root
SEPPmail Certificates – 5 Tips – Tec-Bite IT-Security Blog
- 07 August 2026
- 100%
- Permanent position
- Root
About the job
The days are getting shorter and the temperatures are increasingly adapting to wintertime. The sun has let us down a bit, but we make the best of it. When it gets dark earlier, you can use the time to read a little, for example a new blog article from us. Today's entry revolves around SEPPmail, but actually more about the S/MIME certificates. With SEPPmail and an MPKI, you have the luxury of no longer having to worry about issuing user certificates yourself and can confidently leave this to the MPKI. However, it can happen that you suddenly lose track of your S/MIME certificates and receive a hefty bill at the end of the year. To prevent this, I would like to give a few tips on management on the SEPPmail appliance and how to generally manage all certificates a little better.
Tipp #1 – Overview under Home
On the "Home" page of the SEPPmail appliance, you can see directly under the "License" section how many licenses are available on SEPPmail and how many are already in use. This gives you a first rough indication of the certificates used. Furthermore, the number of users who have not sent any emails for three months is also displayed here and can possibly be set to inactive. This also frees up a license.
Tipp #2 – Information about the individual user
Under the "Users" menu item, all users created on SEPPmail are displayed. Here you can also see when a user last sent an email. All users who no longer need or are allowed to encrypt should be set to "inactive". WARNING: If these users continue to send emails to addresses that have certificates, an error message will occur. Therefore, only users who have not sent emails for a long time should be set to "inactive". By selecting the two options "May not encrypt mails" and "May not sign mails", the user becomes inactive and no longer requires a license on SEPPmail. Under the individual user, it is also visible how many S/MIME certificates have been issued for them and whether a certificate is still valid. This is a practical option to check whether a user has one or more certificates.
Tipp #3 – SEPPmail status report
If I am registered as an administrator of SEPPmail and have a valid email address stored, I receive a daily SEPPmail Daily Report. This contains a CSV as an attachment, which provides detailed information about the certificates and the last dispatch for each user. From this user report, it is also possible to see which users currently use a SEPPmail user license and which do not. I have marked the most important attributes in red in the table.
Tipp #4 – Certificate checks
The last tip consists of three parts and shows how certificates can be automatically checked using certificate checks. The recommended settings for the individual checks are shown in the following sections.
Own user certificates
To ensure that your own users do not sign or encrypt with revoked certificates, we recommend regularly checking these as well. This can be easily set up under "Users -> Advanced Settings -> Automatically check revocation status every day".
Learned user certificates
SEPPmail can automatically learn and save certificates from external senders. However, these certificates must also be checked so that revoked certificates are no longer used. This check can be performed under "X.509 Certificates -> Advanced Settings -> Automatically check revocation status every day". There are further options here, and we also recommend activating the check for duplicate certificates.
Learned or existing root certificates
The last setting or check verifies the root certificates. The options for this can be found under "X.509 Root Certificates -> Advanced Settings". It is recommended to activate the two checks for expiration and revocation here. Root certificates are rarely revoked and usually have a longer validity period than other certificates, but you should react quickly (or have this done automatically) so that all other certificates "under" this root certificate are no longer used.
Tipp #5 – MPKI portal
To be absolutely sure that you have not created too many certificates, I also recommend occasionally visiting the MPKI portal. There is usually a search or management option with the providers to display your own user certificates. This way, you can also double-check whether issuing and revoking through SEPPmail is still functional.
Summary
Thanks to the built-in options of SEPPmail, you get a good overview of the certificates and can also have them managed automatically. This saves time and effort and, above all, contributes to your own protection by ensuring that only valid certificates are used for communication.
Link
www.avantec.ch/loesungen/seppmail/
The article "5 Tips for the Year-End Clean-Up with Certificates on SEPPmail" first appeared on Tec-Bite.