Closed Bug 195939 Opened 23 years ago Closed 7 years ago

S/MIME Eudora messages will not dencrypt

Categories

(MailNews Core :: MIME, defect)

x86
Windows 2000
defect
Not set
normal

Tracking

(Not tracked)

RESOLVED INCOMPLETE

People

(Reporter: jamesrome, Unassigned)

Details

Using build 2003022105. A S/MIME message sent to me had the following in the header (censored to protect the sender): Subject: Entrust test In-reply-to: <3E64B271.5000504@ornl.gov> X-Sender: user@email.cind.ornl.gov To: "James A. Rome" <romeja@ornl.gov> Message-id: <5.1.0.14.2.20030304150653.025f47c8@email.cind.ornl.gov> MIME-version: 1.0 X-Mailer: QUALCOMM Windows Eudora Version 5.1 Content-type: application/x-pkcs7-mime; name=smime.p7m; smime-type=enveloped-data Content-transfer-encoding: base64 References: <3E6431FE.6000504@ornl.gov> <3E63872C.5080106@ornl.gov> <3E5D6D03.700@ornl.gov> <3E63872C.5080106@ornl.gov> <5.1.0.14.2.20030303121320.00acc070@email.cind.ornl.gov> <3E63915C.7050702@ornl.gov> <3E63A673.5070201@ornl.gov> <3E63AA34.6050709@ornl.gov> <3E63AC46.3030307@ornl.gov> <3E63B472.2030703@ornl.gov> <3E63BA3C.9060106@ornl.gov> <3E63BD05.5090408@ornl.gov> <3E63C9D1.1030500@ornl.gov> <3E63CDBD.4090705@ornl.gov> <3E63E008.5020109@ornl.gov> <3E63E86B.7020309@ornl.gov> <3E6431FE.6000504@ornl.gov> Original-recipient: rfc822;romeja@ornl.gov MIIYIAYJKoZIhvcNAQcDoIIYETCCGA0CAQAxggHoMIHUAgEAMD0wNTELMAkGA1UEBhMC VVMxJjAkBgNVBAoTHU9hayBSaWRnZSBOYXRpb25hbCBMYWJvcmF0b3J5AgQ1M91HMA0G CSqGSIb3DQEBAQUABIGAcVM+UIn5t3cd4xyfAQnF4RK17MKYWyqafV+12tVtY0Rtr1fV jaAcnkJKEqHuIucUsuTAcjLFuL7/edozfuxqAOOKXiSztNS5UB6ghIBtWD47K7DzvdFH .... fqC7qGKDjDOo-- Mozilla says the message was not signed, and an unknown problem prevented the message from being decrypted. He used an "Entrusted" version of Eudora to do this. On the other hand, when I send a message to myself via Mozilla, I get: From: "James A. Rome" <jar@ornl.gov> Subject: test To: romeja@ornl.gov Message-id: <3E5D4141.4030607@ornl.gov> MIME-version: 1.0 Content-type: application/x-pkcs7-mime; name=smime.p7m Content-transfer-encoding: base64 Content-disposition: attachment; filename=smime.p7m Content-description: S/MIME Encrypted Message X-Accept-Language: en-us, en User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3b) Gecko/20030221 Original-recipient: rfc822;jar@ornl.gov MIAGCSqGSIb3DQEHA6CAMIACAQAxggJlMIIBDQIBADB2MG4xCzAJBgNVBAYTAlVTMRgwFgYD VQQKEw9VLlMuIEdvdmVybm1lbnQxHTAbBgNVBAsTFERlcGFydG1lbnQgb2YgRW5lcmd5MSYw .... ESr5izSZEssA0UfhA4a2oUOqNCQW2GkECMJGIdzq6umnAAAAAAAAAAAAAA==
I think he used an old certificate of mine to encrypt it. But the error message is confusing (could not decrypt because of unknown problem).
We are investigating S/MIME at Penn State and have experienced the exact same thing. We have had no problems encrypting/decrypting messages sent between Mozilla, Pine (with S/MIME patch), Outlook, and Outlook Express. Messages sent from Eudora (with the WorldSecure S/Mime plugin) that are signed work find in all of these clients, and all of these clients can send encrypted and/or signed mail to Eudora with no problems. The only problem we experienced is that Mozilla (and only Mozilla of the clients we have tested) refuses to decrypt any encrypted mail sent by Eudora. The error we saw was the same as described above.
It actually worked for us finally. The trick is to get the Entrust certificate into Eudora. Our Entrust accounts had to be modified to allow export of .p12 files.
My understanding is that Entrust Certificates are a little "different" than standard x.509 certs. We are using regular, OpenSSL generated x.509 certificates. Oddly, there is no problem with any combination of signing/encrypting on any of the known S/MIME clients that we tested EXCEPT for decrypting email on Mozilla that was sent from Eudora. I'm inclined to think the problem lies with Mozilla (since no other clients had any problem decrypting these messages).
The entrust certs are different because they contain an escrowed encryption key and a non-escrowed signing key. But if you export them as a .pkcs#12 file (which requires special Entrust setup), they seem to be quite standard. Only the signing key is in the certificate.
Product: MailNews → Core
Assignee: ducarroz → nobody
QA Contact: stephend → mime
Product: Core → MailNews Core
Is this still an issue?
Flags: needinfo?(mxe20)
Flags: needinfo?(jamesrome)
Not for me. No one is using s/mime anymore
Flags: needinfo?(jamesrome)

Kaie, what do you make of this?

Flags: needinfo?(mxe20) → needinfo?(kaie)

Based on https://en.wikipedia.org/wiki/Eudora_(email_client) the Eudora software is no longer supported, and since 2013 users have been advised to switch to Thunderbird.

I don't know what had misbehaved, but we'd need example messages and certificates to reproduce and analyze. It seems unrealistic that we get that. I guess the original problem is no longer relevant. Of course, if the problem can still be demonstrated using modern email clients, please provide details.

Status: NEW → RESOLVED
Closed: 7 years ago
Flags: needinfo?(kaie)
Resolution: --- → INCOMPLETE
You need to log in before you can comment on or make changes to this bug.