Find the encryption certificate for a recipient mailbox.
Find the signing certificate + private key for a signer mailbox.
The trust anchors used for certificate-chain validation.
Import a single certificate into the store.
Import the certificates (and CRLs) contained in the DER/PKCS#7 data.
Register a certificate as a trusted root/anchor.
Register a signer/decryptor: a private key with its certificate chain (leaf-first).
Signing key entries whose certificate can sign.
All registered private-key entries (decryption candidates).
A simple, always-available in-memory certificate / private-key store.