Configuring Algorithms for Inbound Emails
The smime_signed_verify algorithm is used to verify and decode signed inbound email messages. If an inbound email message is both signed and encrypted, configure the smime_signandencrypt_decryptandverify algorithm keyset. For encrypted, but unsigned, inbound email messages, configure the smime_encrypted_decrypt algorithm.
These algorithms rely on the OpenSSL configuration. Trusted root certificates configured in OpenSSL are used to verify email signatures. To configure the smime_signed_verify algorithm, add the appropriate root certificate to the OpenSSL configuration. See Understanding the Supported Algorithms and your OpenSSL documentation for instructions.
To configure the smime_encrypted_decrypt algorithm and the smime_signandencrypt_decryptandverify algorithm:
-
Add the email sender's public certificate, the email receiver's public certificate, and the email receiver's private key to the corresponding keyset.
Note:
Ensure that the keyset ID for the certificates is the associated email address. Prefix the greater than (>) sign to the email address for the recipient's private key.
See Security Administration: Understanding PeopleSoft Encryption Technology.
-
Add the email recipient's private key passphrase to the MCF configuration page.
For all private keys entered into the keyset algorithms mentioned in this section, you must enter the passphrases for the recipient’s private keys into the MCF Email Configuration page. To access the configuration page for private key passphrases, select