Too bad it still takes so long to get SMIME going on each device. Compared to just a wireless activation that is. Since SMIME CALs are free now, we had a request to setup S/MIME on all devices (6200). When I showed them how much time it would take per each one, they changed it to VIPs and others only on specific request.
re: #1 above - With v4.5 and later of the device software we no longer have to install the SSP, but you still need to use app loader to check the box for S/MIME support. It would be nice if web desktop manager did the cert synch too.