Generate S/MIME or PGP private key

  If Secure Email Gateway is operating in FIPS mode, you will be unable to create PGP keys. PGP encryption uses algorithms that are not supported.

You can use the Gateway to generate private S/MIMEClosed Secure Multipurpose Internet Mail Extensions (S/MIME) is a specification for secure email messages that uses the X.509 format for digital certificates and uses various encryption algorithms such as 3DES. and PGP keys. These keys can be used for signing and encryption in mail encryption endpoints.

  You can only self-sign generated S/MIME keys using a generated signing certificateClosed The certificate of the certificate authority that signed the key certificate. It contains the certificate authority's own public key. Also known as "root certificate".. You cannot self-sign generated PGP keys.

Create and self-sign a private S/MIME key

  1. Navigate to System > Encryption > Certificate Store.
  2. In the task panel, click Generate certificateClosed A digital means of proving your identity. When you send a digitally-signed message, you are sending your certificate and public key. Certificates are issued by a certification authority and can expire or be revoked./key. The Generate New Certificate or Key dialog is displayed.
  3. From the Type drop-down menu, select S/MIME.
  4. From the Sign With drop-down menu, select a signing certificate that you have created yourself.
  5. Specify the remaining fields as required.

      Enter only ASCII printable characters in the fields. When you mouse over, some of the fields display a tooltip.
  6. Click Generate.
  7. Apply the configuration.

Create an S/MIME key using a Trust Center

If you have not already configured authentication with the Trust Center, you need to do this on the Trust Center Configuration page before you can continue.

 

As described in the Required information when configuring the Trust Center section, information you need to provide may vary, depending on the product type you have with SwissSign.

  1. Navigate to System > Encryption > Certificate Store.
  2. In the task panel, click Generate certificate/key. The Generate New Certificate or Key dialog is displayed.
  3. From the Type drop-down menu, select Trust Center.
  4. Specify the following fields.

    Name

    Email

    Given Name

    Surname

    Pseudonym

    Company

    Department

    State

    Country

      Enter only ASCII printable characters in the fields. When you mouse over, some of the fields display a tooltip.
  5. Specify the Validity Period (1, 2 or 3 years) from the drop-down menu.

  6. Specify the Key Strength (2048, 3072 or 4096) from the drop-down menu.

  7. Enter a password in the Password and Confirm fields.
  8. Click Generate.
  9. Apply the configuration.

Create a PGP private key

  1. Navigate to System > Encryption > Certificate Store.
  2. In the task panel, click Generate certificate/key. The Generate New Certificate or Key dialog is displayed.
  3. From the Type drop-down menu, select PGP.
  4. Specify the remaining fields as required.

      Enter only ASCII printable characters in the fields. When you mouse over, some of the fields display a tooltip.
  5. Click Generate.
  6. Apply the configuration.
 

If you change any configuration or policy settings, you must Apply Configuration for the new settings to take effect. You can do this either from the Changes Made panel, or System > ConfigurationApply Configuration. See Apply new configuration for more information.

If you use Peer Gateways (i.e. when multiple Gateways are peered), any configuration changes from a local Gateway can then be applied to all the peers at the same time. See Configure Peer Gateways for more information.

See also...