ابحث في الدعم

Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

Learn More

S/MIME siganture / certificate validation

  • 2 (ردّان اثنان)
  • 0 have this problem
  • آخر ردّ كتبه Marcin

more options

Dear Support Team,

I'd like to understand the design of S/MIME signature / certificate validation in Thunderbird. Lets's assume the scenarion that a message with valid signature has been received but the certificate expires very soon (next couple of days).

In my opinion, the behaviour of Thunderbird might be a bit missleading. As enclosed, S/MIME information says that certificate is untrusted, which is not really accurate. The certificate was trusted when the message has been received but now expired.

I assume that Thunderbird validates certificate only against current date. But we have the message original date in the headers. Validation process could be configurable, like in popular pdf readers (which date to use for validation), or even better it could execute 2 validations in case current date validation has not been scuccessfull and S/MIME information could cover this scenario that the signature has been valid while message been created / recived but the certificate expired. It would definitely reflect real scenario in more accurate manner.

I'd appreciate if you could let me know if there is a configuration possibility which I'm not aware of. In case it is not available, can you please advise how I could submit a proposal of functionality enhancement? In case, there are rules comming from RFC standards restricting the validation of signature in a way that has been described, I'd also appreciate this feedback.

In spite of the above remarks, I think that you did a vary good job with S/MIME functionality in thunderbird. It is far more user friendly and well presented to a user than in other email clients.


Best regards, Marcin

Dear Support Team, I'd like to understand the design of S/MIME signature / certificate validation in Thunderbird. Lets's assume the scenarion that a message with valid signature has been received but the certificate expires very soon (next couple of days). In my opinion, the behaviour of Thunderbird might be a bit missleading. As enclosed, S/MIME information says that certificate is untrusted, which is not really accurate. The certificate was trusted when the message has been received but now expired. I assume that Thunderbird validates certificate only against current date. But we have the message original date in the headers. Validation process could be configurable, like in popular pdf readers (which date to use for validation), or even better it could execute 2 validations in case current date validation has not been scuccessfull and S/MIME information could cover this scenario that the signature has been valid while message been created / recived but the certificate expired. It would definitely reflect real scenario in more accurate manner. I'd appreciate if you could let me know if there is a configuration possibility which I'm not aware of. In case it is not available, can you please advise how I could submit a proposal of functionality enhancement? In case, there are rules comming from RFC standards restricting the validation of signature in a way that has been described, I'd also appreciate this feedback. In spite of the above remarks, I think that you did a vary good job with S/MIME functionality in thunderbird. It is far more user friendly and well presented to a user than in other email clients. Best regards, Marcin
Attached screenshots

All Replies (2)

more options
As enclosed, S/MIME information says that certificate is untrusted, which is not really accurate.

This has got nothing to do with cert validity. Thunderbird is verifying the entire certificate chain. If that fails you get the 'untrusted certificate' error. It does fail because you either didn't import an intermediate and/or root CA cert, or a cert you imported is not trusted for email.

Helpful?

more options

That is the whole point of my support request that the information presented to the user is not acurate :) This example is based on my own S/MIME certificate which validation path ends up in trusted root certificate (comertial one).

If I open a message which I have sent a year ago it shows the information I have enclosed. At the time of message creation, siganture validation information was positive. Now, it says that certificate is not trusted, which is misleading (certificate just expired).

Helpful?

اطرح سؤالا

You must log in to your account to reply to posts. Please start a new question, if you do not have an account yet.