Closed Bug 152865 Opened 22 years ago Closed 19 years ago

Signed messages should validate against reply to address in addition to from address

Categories

(MailNews Core :: Security: S/MIME, defect, P3)

1.0 Branch
x86
Windows 2000
defect

Tracking

(Not tracked)

RESOLVED WORKSFORME

People

(Reporter: hauser, Unassigned)

Details

Attachments

(1 file)

In my mail account security settings, "Digitally sign messages (by default)" is
set. 

When I forward messages out of my sent folder, the outer message arrives with an
invalid signature while the signater of the forwarded inner message seems to be o.k.

Looking at my sent folder, all sent messages appear to have a broken signature
(irrespective of whether forwarded or new) - this at least since I also
installed enigmail.

Any hints what is wrong?
S/MIME
Assignee: mstoltz → ssaux
Component: Security: General → S/MIME
Priority: -- → P3
Product: MailNews → PSM
QA Contact: junruh → carosendahl
Version: other → 2.3
oops, my buildID is 2002053012
.
Status: UNCONFIRMED → RESOLVED
Closed: 22 years ago
Resolution: --- → INVALID
.
Status: RESOLVED → VERIFIED
Why do you change the status, I still can reproduce the bug?
Status: VERIFIED → UNCONFIRMED
Resolution: INVALID → ---
I can not reproduce it on the latest builds.  You indicated that you were using
a build from 5/30.

I am using a build from 6/19.

Chances are the broken signature is due to the fact that either you are not
logged in to the security module, or the certificate used to sign the messages
does not match the certificate currently configured for use with the mail client.

Using existing and new profiles with certs from our intranet CA, I can forward
messages from my sent folder to both myself and several test accoutns without
problem.

Have you tried with a new profile to see if the problem persists. I need more
information to reproduce this.  Otherwise I will mark it as WFM.
http://bugzilla.mozilla.org/show_bug.cgi?id=50823 with multiple addresses may be
part of the reason, but this still doesn't explain why first and inner messages
arrive with correct signatures in my MS OUTLOOK 2000 while forwarded/outer
don't. Will let you know whether a newer build changes the picture.
can somebody reproduce this with a recent mozilla verson like 1.1beta?
We have complketely changed the way signatures are validated now.  Only the
outermost message is displayed.

Another bug related to opening attachments in separate windows, once fixed will
allow the user to view the individual signature attributes for each attachment.

Closing as fixed.
Status: UNCONFIRMED → RESOLVED
Closed: 22 years ago22 years ago
Resolution: --- → FIXED
verified
Status: RESOLVED → VERIFIED
Good progress, with build 2002080811, outer and inner message signatures arrive
ok in Outlook when sent from mozilla.

However, in my sent folder, the signatures still appear to be broken even if I
just sent a message before and therefore am logged into the security model (your
comment #6). Also, I would hope that at least when clicking on it, Mozilla would
prompt for a security module login and not just display the signatures as
invalid if loging in would remedy this.

Thirdly, what is the other bug you are referring to in comment #9, this prevents
me from looking at the signatures of inner messages in the sent box and I would
like to get on the cc of that bug.
Status: VERIFIED → UNCONFIRMED
Resolution: FIXED → ---
Bug 143565 is tracking all of the issues with opening attachments.

I cannot reproduce the problem with the sent folder.  What is the error message
you are getting for the invalid signature?
Thanks,  I'd like you to try something (just a wild shot)

Under preferences->Mail&Newsgroups->Composition, check the 'quoted-printable'
option and send a message.  

See if you still get the same error message.
Result (Build20020819):
In MS-Outlook, everything arrives fine.
In Mozilla:
1) All signed messages in the sent folder show a broken key, irrespective of
whether nested/forwarded or not
2) In a forwarded message, if I try to open the attached original message, still
the HTML browser opens instead of a message window, thus it is impossible to see
whether it has a proper signature or not.
Changed summary to detail underlying problem.

Netscape currently only validates the message against the email address in the
from header.  We need to validate against the reply to header as well.
Status: UNCONFIRMED → NEW
Ever confirmed: true
Summary: Digital Signature is not valid when forwarding mail → Signed messages should validate against reply to address in addition to from address
Keywords: nsbeta1
Build2003010808

1) Improvement: The signature Icon is no longer broken, but only with a question
mark (further thoughts on this in
http://bugzilla.mozilla.org/show_bug.cgi?id=188320)

2) Unfortunately, as per Carl's comment in
http://bugzilla.mozilla.org/show_bug.cgi?id=143565#c4, there is no progress on
displaying inner messages yet - they still come as html with URI
mailbox:///C|/Documents%20and%20Settings/rhauser/Application%20Data/Mozilla/Profiles/default/otk490k7.slt/Mail/mail.ifi.unizh.ch/Sent?number=4169274&part=1.1.2&type=message/rfc822&filename=%5BFwd%3A%20%5BFwd%3A%20%5BFwd%3A%2008%20sigtest2%5D%5D%5D
Mass reassign ssaux bugs to nobody
Assignee: ssaux → nobody
Product: PSM → Core
The question mark is an intended behaviour, you will learn about it when you click it.

WRT inner messages, when I open attached  messages in a separate window, I get correct signature information.

Can you confirm this is now WORKSFORME?
Status: NEW → RESOLVED
Closed: 22 years ago19 years ago
Resolution: --- → WORKSFORME
Version: psm2.3 → 1.0 Branch
Product: Core → MailNews Core
QA Contact: carosendahl → s.mime
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: