How to Setup MagenQ
Getting Started
- Make sure the card is inserted in your AirID and it is not connected to any other device
- Start MagenQ
- Press Connect to Reader button
- Allow MagenQ to use Bluetooth
- Select your AirID from the list
- You will receive pairing request on your device and on your AirID. Confirm both of them in any order
- Wait until the app connects to readed and fetches your certificate
- Add necessary certificates to ios Keychain
Settings Overview
Connection timeout - Allows you to configure how long reader stays connected to device with card being unused. During this time you do not need to enter PIN assuming you already entered correct PIN once.
Enable notifications - App will send notifications about starting connection to reader, successful connection to reader and disconnect from the reader if this option is enabled.
Advanced notifications - In addition to standard notifications app will also send additional ones when signing or decryption process is initiated. No recomended for everyday use since depending on the app there maybe a large amount of these notifications.
Reset keychain - Deletes all certificates added to device.
Share logs - Uploads logs to developers. Might be needed if bug is discovered. Please read Sharing feedback
Forget saved device - Once you pair with specific AirID MagenQ will connect only to this reader. If you need to change AirID for some reason (for instance yours became non-functional) use this option to forget saved AirID and then pair another one (refer to Getting Started for pairing instructions)
Using MagenQ in different apps
Before trying to use any app listed below make sure your AirID is on, within Bluetooth range and you have correct card inserted. Also note that when you try to use certificates from your card you wiil be asked to permit notifications. This permission is necessary to receive notifications about connection process to reader, successful connection to reader and disconnect from the reader. Permission is asked once and will not be asked ever again.
Connecting to VPN
If you have VPN that requires certificate based authorization you can connect to it using MagenQ.
- Open iOS Settings
- Go to General - VPN & Device Management - VPN - Add VPN configuration
- Fill out Type, Description, Server, Remote ID and Local ID fields
- Change user authentication to Certificate
- Select certificate from your card you want to authorize with
- Save the profile
- Try to enable VPN
- Wait until connection to your AirID is established and PIN is asked
- Enter correct PIN and press OK
- If certificate you selected is suitable for this VPN and you should be successfully connected
Apple Safari
- Open Safari
- Open the website which requires web authentication
- You will see list of identity certificates available on your smart card. Select necessary certificate. Note: List will not appear if there is only one suitable certificate.
- Wait until connection to your AirID is established and PIN is asked.
- Enter correct PIN and press OK
- If certificate you selected is suitable for this website you should successully login
Microsoft Edge
- Open Edge
- Open the website which requires web authentication
- App will ask your permission you access MagenQExt. Allow it.
- You will see list of identity certificates available on your smart card. Select necessary certificate.
- Wait until connection to your AirID is established and PIN is asked
- Enter correct PIN and press OK
- If certificate you selected is suitable for this website you should successully login.
Apple Mail
This instruction assumes you have your mail account added to Apple Mail.
- Open iOS Settings - Apps - Mail
- Open Mail Accounts
- Select your account
- Open Account Settings - Advanced Settings. On the bottom you'll see S/MIME Sign and Encrypt by default options
- If you want to sign your emails with digital signature open Sign menu, enable Sign and select a certificate for Digital Signature.
- If you want to encrypt/decrypt messages open Encrypt by default menu. Select certificate for decryption. Enable Encrypt by default if you want.
Microsoft Outlook
This instruction assumes you have your mail account added to Outlook
- Open Outlook
- Open Settings - Accounts - select your account - S/MIME
- Enable S/MIME
- App will ask your permission you access MagenQExt. Allow it.
- Select your certificate for signing and encryption if you have more than one.
- Optionally enable Signed and/or Encrypted in Always Send As section if you want your mail to be sent signed and/or encrypted by default
Feedback and Bug Reporting
Follow this steps if you want to report a bug or send other feedback.
- Open MagenQ
- Open Settings -> Report a Problem
- Explain what happened and, optionally, specify your email address (then we can follow-up with you to clarify details).
- Send button.
- The app will sends logs securely to developers.

