Nov 28, 2022
GlobalSign supports the RSASSA-PSS signing algorithm for all S/MIME Certificates issued via Enterprise PKI (effective October 29, 2018).
Please review the steps below to configure your Enterprise PKI Profile to use the RSASSA-PSS algorithm.
New customers:
Contact a Sales Representative to setup an Enterprise PKI account.
Existing customers:
Log in to your GlobalSign Certificate Center (GCC) account.
Select the Enterprise PKI tab as shown below.
On the left menu, under My Profiles, press the Profile Configuration option.
Select the correct Profile that you'd like to configure and then click the Next button.
On the Profile Configuration window, select the Signature Algorithm: RSASSA-PSS (sha256) as shown below.
Click the Next button to complete the process.
You will be redirected to the window confirming the process is successful. Once this has been configured, you can issue Certificates that will include RSASSA-PSS as the signing algorithm.
Follow the normal issuance process either using the GCC (GlobalSign Certificate Center) or the EPKI API. Please take note of the Profile ID that you configured to use the RSASSA-PSS algorithm. You will need to select and/or specify this Profile ID when issuing certificates.
Note: This algorithm should be tested for compatibility with Mail Clients as RSASSA-PSS may not be supported.
Check your certificate installation for SSL issues and vulnerabilities.