a) Failure to read a smartcard S/MIME encryption certificate but able to read signature certificate in End-To-End Encryption Settings
Categories
(MailNews Core :: Security: S/MIME, defect)
Tracking
(Not tracked)
People
(Reporter: jgrant, Unassigned)
References
(Blocks 1 open bug)
Details
(Keywords: regression, regressionwindow-wanted)
Steps to reproduce:
See also https://thunderbird.topicbox.com/groups/e2ee/T5f95e4df5f4ee5c7 for screen shots associated with the lists of available certificates in and external to Thunderbird.
• Smartcard with ECA S/MIME certs previously worked with no issues. Updated certs (expiration 2029) were added to the smartcard due to pending expiration of previous certs. After addition of new certs to smartcard, the Thunderbird Select window and Manage S/MIME Certificates window see the new signature cert, but do not see the new encryption cert. Several older certs (expired of both types) are present as well. Tried deleting an older cert, it did not make any difference in the ability to see or select the encryption cert.
• Windows certmgr, Windows Internet Properties/Content/Certificates, Firefox certificate manager all show both new certs, Edge imported only the signature cert. Thunderbird will allow me to select my old encryption cert, with that selected I have been able to send both signed and encrypted emails. The new encryption certificate does not show up in the list of available certs.
• Note that with no encryption certificate selected, the S/MIME button disappears from the Write window, although the Encrypt button is still present and can be selected, which generates a warning popup at the bottom of the Write window that states “You are not set up to send end-to-end encrypted messages from <email address>”. The Encrypt button is greyed out when no signature certificate is selected. It seems that this behavior is backwards in that the Encrypt button should disappear when no encryption certificate is selected and the S/MIME button presence should depend on a signature certificate being selected. The actual presence of the smartcard does not seem to affect this behavior, it is just the selection of certificates.
• The new certs check out fine via the IdenTrust website and function for secure website access once the corresponding account has been updated, however I believe the latter only utilizes the signature cert.
Actual results:
Thunderbird cannot see (and consequently select) the new encryption cert, while all other apps see the new encryption cert. All apps see the signature cert including Thunderbird.
Expected results:
Should see the encryption cert in the drop down list in the Thunderbird Certificate Manager and allow its selection.
Comment 1•2 months ago
|
||
Did this start happening at the same time as Bug 2057324 - Failure to find a certificate on use closes the email composition window ?
Unknown, I did not attempt to update my certificates until 7/12-7/13. Prior to then I was using certificates which had been uploaded in 2023.
Updated•2 months ago
|
My previous ECA S/MIME encryption certificate has now expired. Thunderbird still fails to see (and thus select) the new one, although it finds the signature certificate fine. So I can send signed emails, but cannot send or receive encrypted ones. As before, Firefox sees both certificates in the Certificate Manager, while Thunderbird only sees the signature certificate. Is there any remedy for this?
Comment 4•1 month ago
|
||
Are you talking about os managed certificates? Perhaps in the past you had imported the ones you needed?
You can't use those for S/MIME. https://searchfox.org/comm-central/rev/6e35986c2b3a1402d7a94d3d82b6e432a8ec5698/mail/app/profile/all-thunderbird.js#279
These are not OS managed certs. The certs are from an External Certification Authority (ECA), in this case IdenTrust, and are installed on a smart card (Giesecke & Devrient) which requires PIN authentication. Thunderbird recognizes the ActivClient Security Module which acts as the middleware for reading the smart card, and again, Thunderbird was able to read and test the signature certification associated with my email, but the accompanying encryption certification for the same email could not be read (a d Windows OS and Firefox see both certs). Emails successfully send with the signature, but I cannot encrypt/decrypt content. For over a decade this process has worked fine when updating my certs every 3 years.
It is possible that the desired encryption certificate was deleted within Thunderbird Certificate Manager which is why it doesn't appear. I had definitely deleted an older certificate and it no longer shows up in the Certificate Manager in Thunderbird, although it (and the desired encryption certificate) are still present on the smart card and can be accessed by ActivClient, Windows, and Firefox Certificate Manager. Is there any way to "undelete" what is available according to Thunderbird Certificate Manager? I'm wondering if the deleted certificates are recorded somewhere to prevent them from showing up in Certificate Manager. I have tried making a new profile but that did not let me see missing certificates.
New update: I completely uninstalled Thunderbird, moved my profiles and deleted the AppData Thunderbird folders, rebooted, reinstalled Thunderbird, rebooted, created a new account, and Thunderbird could read the signature cert on my smartcard, but not the encryption cert. I then installed Outlook, created an email account, configured that for use with my smartcard, and successfully sent and received signed and encrypted emails. So the certs are indeed present on the smartcard, but for some reason Thunderbird Certificate Manager won't read it. The error I receive when trying to add a personal certificate for encryption is: "Certficate Manager can't locate a valid certificate that other people can use to send you encrypted email messages to the address <jgrant@batt-tech.com>." Is it possible the "<" and ">" carrot symbols are included in testing for an address match? Anything else I should try before giving up on Thunderbird? I have to be able to send and receive encrypted email...
Comment 8•21 days ago
|
||
You may want to try to get a log for CMS
See https://wiki.mozilla.org/MailNews:Logging
Though perhaps this is PKCS11. See https://firefox-source-docs.mozilla.org/security/nss/legacy_extracts/pkcs11log.html - would likely require a special build to debug
Description
•