Required Certificate Authority
Jump to overview

Policy overview

Key metadata and intent for this policy.

User
Category
Microsoft Outlook 2016 > Security > Cryptography
Supported on
Windows7

This policy setting enables you to designate a required certificate authority for Outlook to use for encryption and digital signatures. If you enable this policy setting, you can specify a required certificate authority by entering an X.509 distinguished name in the text field that is provided. The name must conform to the X.509 certificate format exactly. For example: CN=WoodgroveBankCA, DC=WoodgroveBank, DC=com If you disable or do not configure this policy setting, Outlook trusts any certificate authorities that are represented by certificates in the Trusted Root Certification Authorities store on users' computers.

Internal name
L_RequiredCertificateAuthority
Policy ID
db6a2bb5f210
Elements
1

Registry values

How enabled and disabled states update the registry.

No explicit registry values are set for enabled or disabled states.

Policy elements

Inputs and configuration options exposed by this policy.

ScopeElementTypeRegistry mappingConstraints & behaviorCopy
User
X.509 issue DN that restricts choice of certifying authorities:
ID L_X509issueDNthatrestrictschoiceofcertifyingauthorities
text
Path
software\policies\microsoft\office\16.0\outlook\security
Value name
requiredca
Type
REG_SZ
None
X.509 issue DN that restricts choice of certifying authorities:
User · Type text
Registry mapping
Path
software\policies\microsoft\office\16.0\outlook\security
Value name
requiredca
Type
REG_SZ
DetailsNone