Open Bug 1170862 Opened 11 years ago Updated 3 years ago

old encryption certificate is used even when new selected

Categories

(Thunderbird :: Security, defect)

31 Branch
defect

Tracking

(Not tracked)

UNCONFIRMED

People

(Reporter: birdfund, Unassigned)

Details

User Agent: Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:41.0) Gecko/20100101 Firefox/41.0 Build ID: 20150602055237 Steps to reproduce: I use S/MIME. I had used a cert for quite a while, it is in the local store. I now want to use a new cert that is on my smart card via pkcs11. I go to account seetings/security and cleared both for sign and encrypt. I then select cert from my smart card. This is reflected accurately in the settings. Actual results: What happened is - even though I changed certs, Thunderbird continues to use the previous cert to decrypt existing messages. It does not ask, but rather does on its own. I even did a reboot to be sure it was not caching the info. Expected results: I have mixed feelings but do believe this to be a security risk. It is understandable that it may be useful, even desirable, to still provide access to the old certficate to decrypt previously recvd. messages. However, this presents a risk as certs that are not on a card will always be freely available with no key request unless removed from the store thus all local messages can always be read. It seems far more secure in this type of situation that Thunderbird request password information securely before trying to use a non-default certificate (I would also like to do this on startup or after set time period for default key but that is a different issue).
Group: core-security
Severity: normal → S3
You need to log in before you can comment on or make changes to this bug.