Open Bug 1909717 Opened 2 years ago Updated 1 year ago

Okta; Sign in with smartcard fails, no prompt to select certificate

Categories

(Thunderbird :: Security, enhancement)

Thunderbird 115
enhancement

Tracking

(Not tracked)

UNCONFIRMED

People

(Reporter: emailthereeves+bugzilla, Unassigned)

Details

Attachments

(1 file)

Steps to reproduce:

Added new account to Thunderbird. Upon authentication to Exchange, I am redirected to Okta. I selected "Sign in with PIV / CAC card."

Actual results:

It immediately errors: "No certificate selected. Choose a certificate and try again."

Expected results:

Prompt to select a certificate from my smartcard. After selecting a certificate, I am prompted for my PIN to complete the authentication.

Component: Untriaged → Security

If I understand correctly, you are using a mail server setup that combines the Microsoft Exchange server technology with the offerings of a company named "Okta" (I have no experience with either of those), and your email account is required to use a smartcard for authentication?

Can you please confirm my understanding?

Flags: needinfo?(emailthereeves+bugzilla)

Your understanding is correct.

Authentication for Microsoft Exchange Online is redirecting to a 3rd party Authentication service called Okta. Our organization is working on rolling Okta out and testing impacts. Most of our users use Outlook so it’s less impactful. But we have about 100 Thunderbird users who will be impacted by this change.

We have users on Windows, MacOs and Linux using Thunderbird.

Comparing different OS and Clients, we’ve found that Outlook on MacOS can do Smartcard but not FIDO2 (Yubikey) with Okta due to the mini-browser not being capable.

With Thunderbird, all OS, FIDO2 (Yubikey) works with Okta but the Smart card option is not working, so it’s the opposite of MacOs/Outlook.

I’m not sure how to determine if the issue is with Thunderbirds inability to prompt to select a certificate or if the issue is with the mini-browser that is presented is unable to prompt to select a certificate.

Any thoughts on how to make that determination?

Flags: needinfo?(emailthereeves+bugzilla)

Another question, you are using the IMAP protocol for accessing the server?
And the authentication is standard "TLS client certificate authentication"?

AFAICT the Thunderbird project currently doesn't test that smartcards work with email servers.

Flags: needinfo?(emailthereeves+bugzilla)

(In reply to Kai Engert (:KaiE:) from comment #3)

Another question, you are using the IMAP protocol for accessing the server?
And the authentication is standard "TLS client certificate authentication"?

AFAICT the Thunderbird project currently doesn't test that smartcards work with email servers.

IMAP with OAuth2.

Flags: needinfo?(emailthereeves+bugzilla)

I have never used OAuth with a certificate and a smartcard.
I don't know how we could even test it, we would probably require an account on a preconfigured server, and would also require appropriately configured smartcards.

Jeremy, given this setup is rather special and not common, and if you are interested to get this fixed, would you able to invest resources to get this analyzed/debugged by an engineer in your local environment?

You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: