Mail encryption using S/MIME seems to be broken in Outlook 2016

Anonymous
2017-06-02T12:33:59+00:00

Hi there,

I'm using a Win10 x64 system with Office 2016 Business, version 1704 (last update).

Today I discovered that I'm no longer able to sent S/MIME encrypted e-mails. I do not get any error message and on first sight it looks as the encrypted mail is sent without any problems, but...

  1. No warning/error when sending a mail with enabled encryption
  2. If the recipient is using outlook 2016 as well as myself, he gets a plain, empty message
  3. If the recipient is using another mail program (e.g. K9 mail for android), the mail program initially shows that the mail is encrypted, but it is not and can be opened without any decryption.
  4. Receiving encrypted e-mails sent from other outlook 2016 users shows me a plain empty message
  5. Receiving encrypted e-mails from other mail programs are displayed OK, showing that they are encrypted
  6. Using Outlook 2016 in safe mode, sending and encryption is OK - The reason why this worked was, that in safe mode mails are formatted in html, where in normal mode, I have set up outlook to send mails as plain text, see "Update 2" below

It seems, as the encryption functionality in Outlook 2016 is no longer working...Signing messages is OK

It is not a certificate problem, as everything works OK when sending mails in safe-mode. However, I tried it anyway, deleting the public certificate in the recipients contact information and reinstalling it. No success.

I already tried the online repair function - no success.

It seems as if this error occurred first time after the last Win10 Update (2017-05 Update für Windows 10 Version 1607 for x64-based systems (KB3150513))

I find it critical, if a security feature like mail encryption is not working properly, even worse, it seems as mails marked for encryption are sent unencrypted and are only not displayed if the recipient is using outlook as well. Other mail clients show the mail content unencrypted!!!

[Update: I just got the information, that it is not limited to Outlook 2016 - same behavior with Outlook 2010]

[Update 2: I just discovered, that this behavior is limited to sending encrypted e-mails in plain text format. Sending encrypted e-mails as html, the encryption works as designed]

Regards

R. Schröppel

***Post moved by moderator to the appropriate category***

Outlook | Windows | Classic Outlook for Windows | For home

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
{count} votes
Answer accepted by question author
  1. Anonymous
    2017-10-14T16:39:31+00:00

    Huh... lots of emails, i think. We use encripted email then sending a sensitive information in the organisation, and to contractors, and shifting from Outlook 2010/2013 to 2016. Luckly, most users nether change the default html format to the plain text, but some advanced do.

    Btw, new security update, kb4011162, as they say ("Publicly Disclosed = no", really?) should fix this bug now. Have you tryed it?

    0 comments No comments

10 additional answers

Sort by: Most helpful
  1. Anonymous
    2017-06-11T09:57:33+00:00

    Not solved yet....

    Plain-text problem encrypting e-mail with S/MIME still exists and has been confirmed by a good friend of mine.

    0 comments No comments
  2. Anonymous
    2017-07-14T14:31:40+00:00

    exactly the same problem here.

    0 comments No comments
  3. Anonymous
    2017-08-01T14:10:29+00:00

    Interestingly i sent the last successful encrypted mail on 5th Juli 2017. However my certificate ran out shortly after that and i was renewing it today after vacation. Exact same issue as stated by the OP. So i either didn't have that suspected update around that time or there is somethings to differentiate?

    Changing to HTML is a workaround as described by the OP. I guess not many face this issue as most people don't tamper with these settings.

    Hope MS fixes this soon

    0 comments No comments
  4. Anonymous
    2017-08-01T19:00:03+00:00

    I is really interesting to see, that hardly anybody seems to have the problem or, which may be worse, nobody seems to care about that.

    Being a professional in information security I considered this issue to be a quite serious one, because Outlook does not return an error while sending an e-mail marked "encrypted" but sends the mail unencrypted.

    The receipient may not be able to read the wrongly marked e-mail, however it is no problem for somebody with little knowledge to save the e-mail, open it with notepad and then be able to read the cleartext e-mail.

    I consider this a serious security flaw.

    Regards

    1 person found this answer helpful.
    0 comments No comments