Policy
Require SuiteB algorithms for S/MIME operations
Microsoft Office 5532.1000
Policy overview
Key metadata and intent for this policy.
This policy setting determines whether Outlook is required to use NSA Suite B algorithms for S/MIME operations. Outlook implements Suite B, a set of cryptographic algorithms for symmetric encryption, hashing, digital signatures, and key exchange announced in 2005 by the National Security Agency (NSA), a division of the United States Department of Defense. The Suite B protocols can be used to meet U.S. government standards for handling both classified and unclassified information. If you enable this policy setting, Outlook uses only Suite B algorithms for S/MIME operations. The Suite B algorithms are as follows: - Symmetric encryption. Advanced Encryption Standard (AES) with key sizes of 128 and 256 bits. - Message digest. Secure Hash Algorithm (SHA-256 and SHA-384). - Key agreement. Elliptic-Curve Menezes-Qu-Vanstone (ECMQV); Elliptic Curve Diffie-Hellman (ECDH). - Digital Signatures. Elliptic-Curve Digital Signature Algorithm (ECDSA). If you disable or do not configure this policy setting, Outlook can use any available algorithm for S/MIME operations, such as encryption, signing, and so on. Note - For more information about Suite B, see "Fact Sheet NSA Suite B Cryptography" http://www.nsa.gov/ia/industry/crypto_suite_b.cfm.
Registry values
How enabled and disabled states update the registry.
| Registry location | Type | Enabled value | Disabled value |
|---|---|---|---|
| HKCU\software\policies\microsoft\office\16.0\outlook\security\suitebmode | REG_DWORD | 1 | 0 |
Policy elements
Inputs and configuration options exposed by this policy.
This policy has no additional user input fields.
Other policies in this category
Explore related policies at the same level.
- UserAlways use TNEF formatting in S/MIME messagesWindows7
- UserCheck for the user's private key when the user sends an encrypted email that includes the user as a recipientWindows7
- UserDo not check e-mail address against address of certificates being usedWindows7
- UserDo not display 'Publish to GAL' buttonWindows7
- UserDo not provide Continue option on Encryption warning dialog boxesWindows7
- UserEnable Cryptography IconsWindows7
- UserEnable Retrieval of Remote Certificate Authority InformationWindows7
- UserEncrypt all e-mail messagesWindows7
- UserEnsure all S/MIME signed messages have a labelWindows7
- UserFortezza certificate policiesWindows7
- UserMessage FormatsWindows7
- UserMessage when Outlook cannot find the digital ID to decode a messageWindows7