We are using Sectigo Certificates, we have uploaded the CA to the Virtual Cert Collection. Without a CA **see my point below though** uploaded we got the message in the Certificate "Verification" "Chain Building Error" but now with the CA it reads "Untrusted". The client can open encrypted/signed emails and see the content but when we attempt to sign a new email it says "Certificate Invalid" and when we try and reply to an encrypted email we get "Something went wrong. Please try again or contact support."
** Sectigo does have an intermediate cert in the chain, we did try building an SST with just specifying the CA Root but just got "Chain Building Error" when we specified the Intermediate in the sst it went to "untrusted".
**edit** Just took time for something to take affect, certificate verifies now, I'll leave this up in case anyone has a similar issue. Now we have a different issue.
When composing or sending an encrypted message (to somone we have or have not previously emailed) we get the error. "No valid Recipients" - "This encrypted draft contains no valid recipients. The Encryption Certificates are missing and/or could not be fetched".
Outlook on the desktop can exchange encrypted emails with no issue.