Sending encrypted to internet address

I have a requirement to send an encrypted signed email to a non-Lotus address. Does this mean I need to buy one from some trusted authority i.e. Thawte? Or can one be generated with Domino Administrator? I know it must have an email address attached to it, and I have read in help files, but there is so much and scattered and no single article to say where the certificate comes from or how it is generated.

Thank you,

Durwin

Subject: I think the recipient has to be in your NAB

With a valid public key to use for their encryption

Subject: I think your right, but…

Where does the internet certificate come from?

Subject: Sending encrypted mail uses the recipient’s certificate…

… and the public key within that certificate. The most common way of acquiring the S/MIME cert for somebody outside of your organization is to exchange signed S/MIME mail with them and use “add sender to address book” action on the signed message that you receive from them. You should then be able to use that cert in your local address book for sending encrypted S/MIME messages to that person.