Skip Navigation

Enable PKI digital signatures

OPM
 supports PKI digital signed email messages using one certificate for each account, stored in the 
NDS
 database.
Prerequisites
Before enabling digital signatures, perform the following steps:
  1. Provision a valid PKI X509 certificate issued by one of the Certification Authorities (CA) with a private key. The certificate needs to be in the certificate file format .pfx.
    Protect this file with a password.
  2. Add the root certificate of the issuer (for example, Verisign) to the 
    LocalMachine|Trusted Root Certificate Authorization
     store on each application server.