Closed Bug 2057324 Opened 2 months ago Closed 1 month ago

Failure to find a certificate on use closes the email composition window without allowing a save to Drafts, thus losing any information entered

Categories

(MailNews Core :: Security: S/MIME, defect)

Thunderbird 150
defect

Tracking

(Not tracked)

RESOLVED DUPLICATE of bug 2054196

People

(Reporter: jgrant, Unassigned)

References

Details

(Keywords: dataloss, regression, regressionwindow-wanted)

User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:153.0) Gecko/20100101 Firefox/153.0

Steps to reproduce:

Roughly 2 updates prior to 152.0.1 the Thunderbird user interface started closing the email composition window when it fails to find a valid certificate, leading to the loss of all information in the draft. Prior to this, the window would stay open and one could attempt to resolve the missing certificate issue or save it as a draft. This new behavior requires saving a draft manually prior to clicking Send as you will lose the email if there is a certificate issue. If additional smartcards (without email certs) are present, Thunderbird requires their authentication as well. See following test scenarios and results.

Actual results:

Case 1: Closed TB, removed smartcard, opened TB (previously configured for default digital signature under End-To-End Encryption settings). Send message error popup (no valid sig or cert). Immediately closes Write window upon acknowledging popup.
Case 2: Inserted smartcard, compose new email, asked for PIN to smartcard, sent message normally.
Case 3: Remove smartcard, uncheck “Sign unencrypted messages”. Compose new email, message sent successfully.
Case 4: Insert Yubikey, compose new email (no default signature). Upon entry of To:, requires Yubikey authentication (PIN) even though it does not contain any email certs. Sent successfully.
Case 5: Close and restart TB, Yubikey still inserted, ECA smartcard not inserted, no default signature. Compose new email, enter To: email, requires Yubikey authentication. Sent successfully.
Case 6: Repeat Case 1 with Yubikey inserted at restart. Compose new email, enter To: email, requires Yubikey authentication. Enter message, Send fail (no valid sig or cert), immediately closes Write window upon acknowledging popup. Msg box disappears. Compose another new email, enter info (no call for authentication), Send fail (no valid sig or cert), immediately closes Write window upon acknowledging popup.. Insert ECA smartcard (with email certs), Compose another new email, enter To: info, requests authentication, sent successfully.

Expected results:

The desired (and previous) behavior would be to leave the composition window open upon failure to find the certificate specified for the email signature, or at a minimum save as a draft prior to closing. Also desired would not requiring authentication of smartcards which do not contain email certificates. We use Yubikey as multifactor authentication, so any Yubikeys which are present must also be authenticated (I sometimes have 2 plus the ECA). This is likely a separate issue as when present each smartcard shows up as security devices in the Device Manager list. Multiple authentications has been present for a long time, I just deal with it although TB does not identify which smartcard I am authenticating so it is common to enter the PIN for the wrong smartcard.

Does this reproduce with v153?

Flags: needinfo?(jgrant)
Version: Thunderbird 152 → Thunderbird 150

Yes, I just updated to v 153.0, and on creating an email, with the default to include a signature, no smartcard inserted (no availble certs for the signature), the S/MIME button was present. I entered an email address and subject, tried to send, received the send message error that no cert could be found, and the composition immediately window closed. After inserting ECA, repeated message composition and send, also failed to send and closed composition window immediately. On second attempt with ECA still inserted, as soon as I entered a To: email address, TB asked me to authenticate the smartcard. Completed filling out composition subject and body, and the message sent normally. This mirrors my previous long term (well over a year) experience where the first attempt with a smartcard present would fail, but a subsequent attempt succeeds.

Flags: needinfo?(jgrant)
Keywords: dataloss
Duplicate of this bug: 2061624
Duplicate of this bug: 2061976
Status: UNCONFIRMED → RESOLVED
Closed: 1 month ago
Duplicate of bug: 2054196
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.