Signature marked as broken (red cross) after certificate has expired, but decryption still works. Should not signature check work too?
I have installed a valid personal certificate in Thunderbird 45.4.0, and tested that I can send encrypted an signed mails to myself. The received mail looks alright. The content is decrypted, and the icon for the signature is fine.
Then I tested to change the date in the system after the validity time of the certificate. After that, I can still see the encrypted content, but the signature looks broken, i.e. the signature icon has a red cross over it.
I did this test after having found out that one must not delete expired certificates from Thunderbird in order to still be able to decrypt old mails. See http://kb.mozillazine.org/Message_security#Expired_Certificate
In fact, that was a surprise too me. I had thought that it would be possible to use a renewed certificate as long as the same keys are used. I have not found the rationale behind the behavior of Thunderbird regarding this. It would be good to have that explained.
All Replies (4)
This isn't specific to Thunderbird. When you get a new cert, it's not just the same cert/key with a new validity date, it's a new key(pair). If you delete the expired cert from the Thunderbird certificate store, Thunderbird cannot decrypt messages anymore which have been encrypted to the deleted key.
Hi christ1
The test I made involved a single certificate. I did not replace the certificate with a new one.
Also, creating a new certificate does not necessarily require a new pair of keys. You can simply create a new certificate using the same certificate signing request, i.e. the one that was used when creating the old certificate. I think you could even create a new certificate signing request pointing at the same private key as before, and use that csr when creating the new certificate.
Modified
That's all technically possible, but it depends on the CA to accept the same key again or not.
I know nothing about what kind of CA you use to create your certs, and how exactly the result looks like. So I'm not going to guess any further about why you couldn't decrypt older messages anymore with a 'renewed' cert.
In any case, I don't think it's best practice to re-use the same key pair again and again. And I don't really see a benefit in doing so. Why don't you simply issue yourself a cert running long enough, so that it doesn't need to be renewed in the first place?
Hi again, christ1
Our discussion is off topic. It does not explain or solve my issue - the verification of signatures of old emails.
Thanks, anyway!
F.y.i. I have set up my own CA using openssl with mostly a default configuration. I have not investigated how to add any policies to the configuration. I have glanced at the server configuration, but do not see that I can affect it in order to remove the issue.