{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-414-preserve-older-s-mime-decryption-keys-when-importing-replacement-certificates/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-414-preserve-older-s-mime-decryption-keys-when-importing-replacement-certificates/",
        "slug": "dse-20260909-414-preserve-older-s-mime-decryption-keys-when-importing-replacement-certificates",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-414-preserve-older-s-mime-decryption-keys-when-importing-replacement-certificates/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-414-preserve-older-s-mime-decryption-keys-when-importing-replacement-certificates.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-414-preserve-older-s-mime-decryption-keys-when-importing-replacement-certificates/"
        },
        "title": "Preserve older S/MIME decryption keys when importing replacement certificates",
        "summary": "Why can a newly imported S/MIME certificate leave older mail unreadable?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:25:02+00:00",
        "modified_at": "2026-09-10T02:04:57+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 228,
        "potentially_affected": "Use this review for Intune imported-PKCS S/MIME encryption delivery, not merely for a mail-signing certificate. Identify the user's required devices and the older encrypted messages that must remain accessible.",
        "dse_recommendation": "Make historical mail decryption an explicit acceptance test for certificate replacement.",
        "primary_source": {
            "name": "Use imported PFX certificates in Microsoft Intune - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/device-configuration/certificates/imported-pfx-profiles",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>S/MIME mail decryption requires the private key associated with the certificate used to encrypt that message. Microsoft&#8217;s imported-PKCS guidance therefore calls for preserving earlier certificates when older messages must remain readable, while importing a replacement before the current certificate expires. Ordinary SCEP and PKCS profiles issue different certificates per device, so they cannot supply the same encryption certificate across a user&#8217;s devices for this purpose. <a href=\"https://learn.microsoft.com/en-us/intune/device-configuration/certificates/imported-pfx-profiles\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this review for Intune imported-PKCS S/MIME encryption delivery, not merely for a mail-signing certificate. Identify the user&#8217;s required devices and the older encrypted messages that must remain accessible.</p>\n<h2>DSE recommendation</h2>\n<p>Make historical mail decryption an explicit acceptance test for certificate replacement. Ask the mail and PKI owners to map retained encryption certificates to the periods of mail they protect. Keep authorized key custody and device delivery separate from routine certificate cleanup. Do not delete older material solely because the newest certificate imports successfully, and do not copy private keys into ordinary support tickets.</p>\n<h2>Verification</h2>\n<p>With an authorized test account, read representative messages encrypted before and after replacement on each required device. Confirm the intended certificate and private-key availability through protected administrative inspection. Test a replacement device as a separate recovery case. Record results and any missing history before approving retirement of older encryption material.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/device-configuration/certificates/imported-pfx-profiles\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Use imported PFX certificates in Microsoft Intune</a>.</p>",
        "content_text": "Source facts\nS/MIME mail decryption requires the private key associated with the certificate used to encrypt that message. Microsoft’s imported-PKCS guidance therefore calls for preserving earlier certificates when older messages must remain readable, while importing a replacement before the current certificate expires. Ordinary SCEP and PKCS profiles issue different certificates per device, so they cannot supply the same encryption certificate across a user’s devices for this purpose. Microsoft Learn.\nApplicability\nUse this review for Intune imported-PKCS S/MIME encryption delivery, not merely for a mail-signing certificate. Identify the user’s required devices and the older encrypted messages that must remain accessible.\nDSE recommendation\nMake historical mail decryption an explicit acceptance test for certificate replacement. Ask the mail and PKI owners to map retained encryption certificates to the periods of mail they protect. Keep authorized key custody and device delivery separate from routine certificate cleanup. Do not delete older material solely because the newest certificate imports successfully, and do not copy private keys into ordinary support tickets.\nVerification\nWith an authorized test account, read representative messages encrypted before and after replacement on each required device. Confirm the intended certificate and private-key availability through protected administrative inspection. Test a replacement device as a separate recovery case. Record results and any missing history before approving retirement of older encryption material.\nOfficial references\nMicrosoft Learn: Use imported PFX certificates in Microsoft Intune.",
        "content_markdown": "## Source facts\n\nS/MIME mail decryption requires the private key associated with the certificate used to encrypt that message. Microsoft’s imported-PKCS guidance therefore calls for preserving earlier certificates when older messages must remain readable, while importing a replacement before the current certificate expires. Ordinary SCEP and PKCS profiles issue different certificates per device, so they cannot supply the same encryption certificate across a user’s devices for this purpose. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-configuration/certificates/imported-pfx-profiles).\n\n## Applicability\n\nUse this review for Intune imported-PKCS S/MIME encryption delivery, not merely for a mail-signing certificate. Identify the user’s required devices and the older encrypted messages that must remain accessible.\n\n## DSE recommendation\n\nMake historical mail decryption an explicit acceptance test for certificate replacement. Ask the mail and PKI owners to map retained encryption certificates to the periods of mail they protect. Keep authorized key custody and device delivery separate from routine certificate cleanup. Do not delete older material solely because the newest certificate imports successfully, and do not copy private keys into ordinary support tickets.\n\n## Verification\n\nWith an authorized test account, read representative messages encrypted before and after replacement on each required device. Confirm the intended certificate and private-key availability through protected administrative inspection. Test a replacement device as a separate recovery case. Record results and any missing history before approving retirement of older encryption material.\n\n## Official references\n\n[Microsoft Learn: Use imported PFX certificates in Microsoft Intune](https://learn.microsoft.com/en-us/intune/device-configuration/certificates/imported-pfx-profiles)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-414-preserve-older-s-mime-decryption-keys-when-importing-replacement-certificates/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-414-preserve-older-s-mime-decryption-keys-when-importing-replacement-certificates/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-414-preserve-older-s-mime-decryption-keys-when-importing-replacement-certificates/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Preserve older S/MIME decryption keys when importing replacement certificates",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-414-preserve-older-s-mime-decryption-keys-when-importing-replacement-certificates/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-414-preserve-older-s-mime-decryption-keys-when-importing-replacement-certificates/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-414-preserve-older-s-mime-decryption-keys-when-importing-replacement-certificates/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-414-preserve-older-s-mime-decryption-keys-when-importing-replacement-certificates/",
                "headline": "Preserve older S/MIME decryption keys when importing replacement certificates",
                "description": "Why can a newly imported S/MIME certificate leave older mail unreadable?",
                "abstract": "Why can a newly imported S/MIME certificate leave older mail unreadable?",
                "articleBody": "Source facts\nS/MIME mail decryption requires the private key associated with the certificate used to encrypt that message. Microsoft’s imported-PKCS guidance therefore calls for preserving earlier certificates when older messages must remain readable, while importing a replacement before the current certificate expires. Ordinary SCEP and PKCS profiles issue different certificates per device, so they cannot supply the same encryption certificate across a user’s devices for this purpose. Microsoft Learn.\nApplicability\nUse this review for Intune imported-PKCS S/MIME encryption delivery, not merely for a mail-signing certificate. Identify the user’s required devices and the older encrypted messages that must remain accessible.\nDSE recommendation\nMake historical mail decryption an explicit acceptance test for certificate replacement. Ask the mail and PKI owners to map retained encryption certificates to the periods of mail they protect. Keep authorized key custody and device delivery separate from routine certificate cleanup. Do not delete older material solely because the newest certificate imports successfully, and do not copy private keys into ordinary support tickets.\nVerification\nWith an authorized test account, read representative messages encrypted before and after replacement on each required device. Confirm the intended certificate and private-key availability through protected administrative inspection. Test a replacement device as a separate recovery case. Record results and any missing history before approving retirement of older encryption material.\nOfficial references\nMicrosoft Learn: Use imported PFX certificates in Microsoft Intune.",
                "datePublished": "2026-09-10T00:25:02+00:00",
                "dateModified": "2026-09-10T02:04:57+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-414-preserve-older-s-mime-decryption-keys-when-importing-replacement-certificates/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-414-preserve-older-s-mime-decryption-keys-when-importing-replacement-certificates/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Preserve older S/MIME decryption keys when importing replacement certificates"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 228,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Use imported PFX certificates in Microsoft Intune - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/device-configuration/certificates/imported-pfx-profiles"
                }
            }
        ]
    }
}