S/MIME client signing certificate attached as smime.p7s

Sorry, but no.
We wrote the functionality exact this way so every instance owner can decide on who to trust (or not).

This is also described within the documentation:
https://admin-docs.zammad.org/en/latest/system/integrations/smime.html#setup

You can, if you must, trust specific CAs of your choice to allow several S/MIME certificates at once without trusting them one by one. But that’s an administrative choice of yours.