Initial situation:
Apple Mail clients on iOS cannot receive S/MIME-encrypted emails with the increased, recommended security setting RSA-OAEP.
In SEPPmail Secure E-Mail Gateway as well as in seppmail.cloud there is a corresponding configuration option for RSA-OAEP for each domain.
•In SEPPmail Secure E-Mail Gateway the option RSA-OAEP for S/MIME encryption is deactivated by default.
•In seppmail.cloud the option Avoid RSA-OAEP for S/MIME encryption is deactivated by default, so RSA-OAEP is active.
Background:
To our best of knowledge, Apple Mail does not support RSAES-OAEP as a padding method for asymmetric key transport.
Alternative:
We recommend using an encryption gateway solution such as SEPPmail. This largely eliminates dependencies on the respective mail client and key management. In addition, S/MIME certificates within the framework of an MPKI via SwissSign are significantly more cost-effective than those from GlobalSign.
A solution such as SEPPmail Secure E-Mail Gateway or seppmail.cloud decrypts inbound emails at the gateway and delivers a decrypted, signature-verified email to the user. This makes it possible to read the email on any device.