Creating user certificate capable of signing emails (S/MIME) with IdM's CA

Solution Verified - Updated -

Issue

S/MIME stands for Secure/Multipurpose Internet Mail Extension. S/MIME certificates are commonly used as email signing certificates or personal authentication certificates.

In order to create user certificate with ability to sign emails, we need to add S/MIME attributes to usual user certificate. Certificate has to have E-mail Protection extended key usage, provided by exKeyUsageOID 1.3.6.1.5.5.7.3.4.

Environment

IPA 4+ with embedded CA
RHEL 7.9+

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content