Showing questions for topic:
Showing questions tagged:

Certificate error

When I login, I receive the message, "the certificate for mail.bdmdata.com is not valid" and I cannot send or receive emails. I am using IMAP. I currently have… (read more)

When I login, I receive the message, "the certificate for mail.bdmdata.com is not valid" and I cannot send or receive emails. I am using IMAP. I currently have to use [email removed]@yahoo.com'

Archived 3 100

Smartcards & broken GPG support

Hello, I am writing this message in regards to Thunderbird's GPG support after v68, in the last hope that someone suggests a solution that moves me away from version 68. … (read more)

Hello,

I am writing this message in regards to Thunderbird's GPG support after v68, in the last hope that someone suggests a solution that moves me away from version 68. I consider the current state broken.

My PGP keys reside on a Yubikey, but smartcard usage has been broken after v68, as none of the supposedly correct setups work. It should work pretty much out of the box, but it doesn't. The whole idea of moving away from Enigmail without having a properly, fully implemented support, including for smartcards, or at least for working with GPG, was utterly misguided, IMO, and broke the once nice client.

I enabled gpg usage and fetching in Settings, I imported my pubkeys to Thunderbird's PGP manager, then added my external key (with GPG). Everything looks fine. But when I click an encrypted message, I get "The secret key that is required to decrypt this message is not avaliable". Nah, it's available and it's there! The pinentry isn't appearing at all and this is the result. I believe this is TB's fault, as the pinentry correctly appears with everything else I do, also with TB 68 + Enigmail. The setup is the same. I am using the latest Gpg4win.

Settings:

mail.openpgp.allow_external_gnupg - true mail.openpgp.fetch_pubkeys_from_gnupg - true mail.openpgp.alternative_gpg_path - has no effect whether set or not

gpg-agent.conf:

enable-win32-openssh-support default-cache-ttl-ssh 900 max-cache-ttl-ssh 1800 no-allow-external-cache default-cache-ttl 300 max-cache-ttl 3000 ignore-cache-for-signing allow-loopback-pinentry

gpg.conf:

utf8-strings auto-key-locate local use-agent

FYI, adding "pinentry-program" has no effect on solving the problem, whether set or not.

Your suggestions are welcome!

Solved 1 108

Thumderbird has stopped receiving emails because of error "The certificate for pop3.exemail.com.au is not valid for that server"

My thunderbird account stopped receiving emails yesterday and is giving the message: "Thunderbird The certificate for pop3.exemail.com.au is not valid for that server. So… (read more)

My thunderbird account stopped receiving emails yesterday and is giving the message:

"Thunderbird The certificate for pop3.exemail.com.au is not valid for that server. Someone could be trying to impersonate the server and you should not continue."

Mails are still going to the Webmail account and my husband has an exemail account with the same settings that is working correctly.

Exetel is in the process of selling its email service to a third party but this isn't final until September 8, will moving to the new provider fix this issue or is there something else I should be doing?

Archived 2 138

Thunderbird is showing Certificate for mobile.charter.net:993 does not come from a trusted source.

Email not working on my desktop. Using Edge 11, Settings show certificate for mobile.charter.net:993 does not come from a trusted source. I can not send or receive emai… (read more)

Email not working on my desktop. Using Edge 11, Settings show certificate for mobile.charter.net:993 does not come from a trusted source. I can not send or receive email on my desktop. This started this morning. I have not made any changes to my computer, but did do an Edge update. I can check my email on my cellphone if there is a fix.

Open 4 40

Thunderbird Beta and Release: External GnuPG Keys Not Working with GnuPG 2.5.x

DEUTSCH (English see below(: Hallo zudammen, Konfiguration: - Window11 25H2 (aktuell) - Thunderbird Beta-6 (BuildID=20260213180051) - gpg2.5.17 (Gpg4Win 5.0.1); siehe au… (read more)

DEUTSCH (English see below(:

Hallo zudammen,

Konfiguration: - Window11 25H2 (aktuell) - Thunderbird Beta-6 (BuildID=20260213180051) - gpg2.5.17 (Gpg4Win 5.0.1); siehe auch: <https://www.gpg4win.de/>

Der bisherige und standarmärige Installationspfad von "Gpg4Win": "C:\Progam Diles (x86)\Gpg4Win\" wurde softwareseitig auf: "C:\Progam Diles\Gpg4Win\" geändert!

Bug 1967121 (Closed) => thunderbird148 --- fixed! <https://bugzilla.mozilla.org/show_bug.cgi?id=1967121>

Zur Zeit verfolge ich die Änderungen bezüglich der externen Schlüsselverwaltung in Thunderbird-Beta, da das Arbeiten mit externen Schlüsseln in der esr- und in der relesease-Version von Thunderbird seit der offiziellen Herausgabe von gpg2.5.x absolut nicht mehr möglich ist! Die geheimen Schlüssel für das Entschlüsseln und Signieren werden mit gpg2.5.x nicht mehr gefunden!

In der Schlüsselverwaltung von TB-Beta befinden sich meine öffentlichen Schlüssel und alle öffentlichen Schlüssel meiner Kommunikationspartner. Extern sind meine geheimen Schlüssel gelagert. Folgende Präferenz wurde aufgrund von gpg2.5.x hinzugefügt:

https://assets-prod.sumo.prod.webservices.mozgcp.net/media/uploads/images/2026-02-26-10-04-58-df59be.png

Allerdings erscheint nach all diesen Maßnahmen die Fehlermeldung: "The secret key that's required to decrypt this message is not availlable."

https://assets-prod.sumo.prod.webservices.mozgcp.net/media/uploads/images/2026-02-26-10-05-45-d8280e.png

Mit Herausgabe von Thunderbird/148.0 (release) sind dort die gleichen Probleme mit der externen Schlüsselverwaltung zu bepbachten!

Mit Versionen gpg < 2.5 funktioniert unter Windows alles problemlos!

UNTER LINUX haben hier Änderungen an der Präferenz: "mail.openpgp.load_untested_gpgme_version" nachweislich keinerlei Auswirkungen!

Was übersehe ich?

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

ENGLISH:

Hello,

Configuration: - Window11 25H2 (current status) - Thunderbird Beta-6 (BuildID=20260213180051) - gpg2.5.17 (Gpg4Win 5.0.1); see also: <https://www.gpg4win.de/>

The previous and default installation path of "Gpg4Win": "C:\Program Files (x86)\Gpg4Win\" has been changed by the software to: "C:\Program Files\Gpg4Win\"!

Bug 1967121 (Closed) => thunderbird148 --- fixed! <https://bugzilla.mozilla.org/show_bug.cgi?id=1967121>

At the moment, I’m following the changes regarding external key management in Thunderbird Beta, because working with external keys in the ESR and release versions of Thunderbird has become absolutely impossible since the official release of gpg 2.5.x! The secret keys required for decryption and signing are no longer found when using gpg 2.5.x!

In Thunderbird Beta’s key manager, my public keys and all public keys of my communication partners are present. My secret keys are stored externally. The following preference was added because of gpg 2.5.x:

https://assets-prod.sumo.prod.webservices.mozgcp.net/media/uploads/images/2026-02-26-10-04-58-df59be.png

However, even after all these measures, the following error message appears: **"The secret key that's required to decrypt this message is not available."**

https://assets-prod.sumo.prod.webservices.mozgcp.net/media/uploads/images/2026-02-26-10-05-45-d8280e.png

With the release of Thunderbird 148.0 (release), the same problems with external key management can be observed there as well!

With gpg versions **older than 2.5**, everything works flawlessly under Windows!

    • UNDER LINUX**, changes to the preference

"mail.openpgp.load_untested_gpgme_version" have demonstrably no effect at all!

What am I missing?

Open 6 187

Thunderbird will not accept my mail server's certificate.

I am unable to download email for my Bell email accounts. For one of the two Bell accounts all messages disappeared. I get an error message saying saying the server's c… (read more)

I am unable to download email for my Bell email accounts. For one of the two Bell accounts all messages disappeared. I get an error message saying saying the server's certificate is invalid.

Open 1 50

Receiving message saying pop.starpower.net is not valid for that server.

Receiving the above message when trying to get emails. Am able to receive emails on cell phone which is not with Thunderbird email. Made no changes to Thunderbird. Starte… (read more)

Receiving the above message when trying to get emails. Am able to receive emails on cell phone which is not with Thunderbird email. Made no changes to Thunderbird. Started about 2 days ago. Spoke with our email provider and they say it is specific to our Thunderbird email.

Entire message reads - " The certificate for pop.starpower.net is not valid for that server. Someone could be trying to impersonate the server and you should not continue "

                                                                                                          Thanks,
                                                                                                       Mike Worden
Archived 1 275

Сброс сертификатов \ Reset certificates

Здравствуйте, мы пользуемся программой Kaspersky Security Center, у нас возникла проблема. После изменения политики, постоянно меняется самоподписные сертификаты почты (… (read more)

Здравствуйте, мы пользуемся программой Kaspersky Security Center, у нас возникла проблема. После изменения политики, постоянно меняется самоподписные сертификаты почты (Thunderbird) и каждый раз приходится подтверждать их заново. Просьба оказать помощь в решение данной проблемы.

________________________________________________________________ Hello, we are using the Kaspersky Security Center program, and we have a problem. After changing the policy, the self-signed mail certificates (Thunderbird) are constantly changing, and we have to re-verify them every time. Please help us resolve this issue.

Solved Archived 3 119

TLS Certificate as Authentication for SMTP

OS: GNU/Linux Thunderbird Desktop Is it possible to set up a TLS client certificate for authentication with SMTP, as it is with IMAP? It works fine on the K-9 Android cl… (read more)

OS: GNU/Linux Thunderbird Desktop

Is it possible to set up a TLS client certificate for authentication with SMTP, as it is with IMAP?

It works fine on the K-9 Android client for both IMAP and SMTP.

Is there a reason why this hasn't yet been added as an authentication method for SMTP?

Thank you!

Best Regards

Open 90

S/MIME encryption cannot find recipient's address despite valid cert in CertMgr/certutil

Hi, I have successfully added my personal certificate in my account's E2EE and I can ever since digitally sign messages. Yay! After importing a multiple valid certificate… (read more)

Hi,

I have successfully added my personal certificate in my account's E2EE and I can ever since digitally sign messages. Yay! After importing a multiple valid certificates for recipients, I tried to send encrypted emails to some of these (one recipient per email draft). All of them highlight the recipient's address in yellow with a yellow status bar: "End-to-end encryption requires resolving certificate issues for [recipient address]"

Clicking on the button "S/MIME" -> "View Certificates Of Recipients", a window comes up showing the address with the status "Not found". When I open "Settings -> Privacy & Security -> Certificate Manager", I see the certificates present with valid dates. Using certutil to investigate cert9.db in Thunderbird's profile folder, I also see the certificates being in there, but what struck me was the trust status: [...] Fingerprint (SHA-256):

       7B:DF:9F:28:F2:B4:42:5E:37:06:EE:B8:D6:22:0C:70:12:05:F8:33:26:10:5A:1C:03:21:65:2A:C0:C3:3F:5E
   Fingerprint (SHA1):
       56:43:79:93:41:E0:8B:16:0A:FC:64:3E:74:B6:6F:F8:4E:67:93:D4
   Mozilla-CA-Policy: false (attribute missing)
   Certificate Trust Flags:
       SSL Flags:
       Email Flags:
       Object Signing Flags:

I changed the Trust flags (first for emails, then for SSL email) by running certutil -M -n <recipient's email addresss> -t ",P," -d <certdir>

This lead to

Fingerprint (SHA-256):
       7B:DF:9F:28:F2:B4:42:5E:37:06:EE:B8:D6:22:0C:70:12:05:F8:33:26:10:5A:1C:03:21:65:2A:C0:C3:3F:5E
   Fingerprint (SHA1):
       56:43:79:93:41:E0:8B:16:0A:FC:64:3E:74:B6:6F:F8:4E:67:93:D4
   Mozilla-CA-Policy: false (attribute missing)
   Certificate Trust Flags:
       SSL Flags:
       Email Flags:
           Terminal Record
           Trusted
       Object Signing Flags:

Whils I am not sure if this makes any difference to my beforementioned problem, I realize "Mozilla-CA-Policy: false (attribute missing)". How can I address this missing attribute and what can I do to get my emails encrypted, please?

Open 10

Thunderbird 115.18.0 Linux - Cannot decrypt PGP encrypted message

I received a PGP-encrypted e-mail which is just showing the encrypted text in mail preview and also in a separate mail window; it is not getting auto-decrypted, even thou… (read more)

I received a PGP-encrypted e-mail which is just showing the encrypted text in mail preview and also in a separate mail window; it is not getting auto-decrypted, even though the correct key is present in the OpenPGP key management. I have this same behavior on two different setups on Linux Mint 21.1 Vera. Once I reply to the e-mail, the original message gets decrypted in the reply message, but not in the original.

I've got another setup on MacOS, same Thunderbird version, which also does not auto-decrypt the message, but in message preview provides a button "Decrypt" which does the job. But this button is missing in the Linux configs.

All setups have the correct PGP Key configured.

Any hint to resolve the issue is highly appreciated. Thanks for your time.

Archived 7 286

I can't click the green lock icon in the URL bar of the web browser that launches within Thunderbird.

When adding a new email account, the built-in web browser launches and displays the OAuth screen. To verify the security of the destination site, I want to click the gree… (read more)

When adding a new email account, the built-in web browser launches and displays the OAuth screen. To verify the security of the destination site, I want to click the green lock icon in the URL bar to check the details, but I can’t click it.

Does a green lock icon mean a secure connection has been established?

Solved 6 70

problem with certicate

I receive a lot of Thunderbird messages with this text (in French) : "Le certificat pour imap.gmail.com ne provient pas d’une source sûre." What I have to do please Thnx … (read more)

I receive a lot of Thunderbird messages with this text (in French) :

"Le certificat pour imap.gmail.com ne provient pas d’une source sûre."

What I have to do please Thnx

Solved 1 130

www.mozilla.org uses an invalid security certificate

Hi, With new version 1.143 all accounts are gone, need to re-create my existing mails accoutns (outlook, yahoo, gmail) but all fail on error message "www.mozilla.org uses… (read more)

Hi, With new version 1.143 all accounts are gone, need to re-create my existing mails accoutns (outlook, yahoo, gmail) but all fail on error message "www.mozilla.org uses an invalid security certificate" How to resolve ? Grtz, Jane

Open 1 120