S/MIME X.509 certificate validation fails
Categories
(Thunderbird :: Security, defect)
Tracking
(Not tracked)
People
(Reporter: rufus.buschart, Unassigned)
Details
Attachments
(6 files)
User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.80 Safari/537.36 Edg/98.0.1108.43
Steps to reproduce:
In Thunderbird on OS X I open an email with an S/MIME signature that was created with the private key of a publicly trusted end-entity-certificate.
Actual results:
The S/MIME signature is displayed as "invalid". See attached screenshot.
Expected results:
The signature should be displayed as "valid", like it is on Outlookk for Windows or within GMail. See attached screenshot.
Ideally Thunderbird would display a message, why it considers a certificate as "invalid".
Reporter | ||
Comment 1•3 years ago
|
||
Reporter | ||
Comment 2•3 years ago
|
||
Reporter | ||
Comment 3•3 years ago
|
||
Reporter | ||
Comment 4•3 years ago
|
||
I have been able to reproduce this behavior also on an out-of-the-box Windows with Thunderbird.
Reporter | ||
Comment 5•3 years ago
|
||
One additional update: if the S/MIME signature contains a full certificate chain, the signature is validated correctly, but if Thunderbird has to download the intermediate and issuing CAs from the AIPs it fails.
Reporter | ||
Comment 6•3 years ago
|
||
Reporter | ||
Comment 7•3 years ago
|
||
Reporter | ||
Comment 8•3 years ago
|
||
Is there someone who could have a look in this issue?
Description
•