#1158 addresses a similar issue in even more limited ways - some enterprises have a way of converting s/mime certs to openpgp public keys, when are missing self-signatures
The above is easier, but it would be better to instead have a way to support s/mime certs natively