Key extraction

  If the Email Gateway is operating in FIPS mode, PGP keys will not be extracted as PGP is an unsupported encryption type.

Key extraction works in the following way:

  1. When decrypting an email message on a policy route, the Email Gateway checks it for PGP public keys and subordinate/root CA S/MIME certificates.
  2. If an appropriate key or certificate is detected, it is extracted.
  3. The extracted key or certificate is added to the Email Gateway certificate store.

Extracted keys and certificates can then be used for encryption and signature verification (although S/MIME certificates may have usage restrictions).

Tell me about...

See also...