Showing questions for topic:
Showing questions tagged:

imap.xxxx the certifate does not come from a safe source

i can not receive mails, since the update to 128.5.2ESR not on imap.strato.com not on imap.gmail.com not on mail.yourhosting.com just since today after the update. sendin… (read more)

i can not receive mails, since the update to 128.5.2ESR not on imap.strato.com not on imap.gmail.com not on mail.yourhosting.com

just since today after the update. sending emails seems to work.

I did NOT change anything in the accounts.

How to solve????

Thank you.

Solved Archived 7 3932

Security certificate exception

Typically if I experience a security certificate exception, thunderbird will popup the certificate exception box, I click to get certificate and am done. Today I cannot … (read more)

Typically if I experience a security certificate exception, thunderbird will popup the certificate exception box, I click to get certificate and am done.

Today I cannot get the certificate popup to appear. which is fine I know where the certificates are managed but I have not a clue how to add a certificate OR what information to enter into the "Add security exception" dialogue box

Any help would be greatly appreciated.

Solved Archived 7 1383

Problème envoi mail Thunderbird and orange.fr

Bonjour Depuis quelques jours je rencontre le message suivant: L’envoi du message a échoué. Une erreur est survenue lors de l’envoi de l’e-mail. Le serveur e-mail a répon… (read more)

Bonjour

Depuis quelques jours je rencontre le message suivant:

L’envoi du message a échoué. Une erreur est survenue lors de l’envoi de l’e-mail. Le serveur e-mail a répondu : 1jHjuyBzCXgNw StartTLS obligatoire. StartTLS mandatory.OFR303_199 [199]. Veuillez vérifier que votre adresse e-mail dans les paramètres du compte est correcte et essayer à nouveau.

Dans les paramètres du compte tout semble OK Merci pour votre aide Cordialement

Solved Archived 8 586

I am using email [edited-for-privacy]@supanet.com

Thunderbird says this "the certificate for imap.supanet.com does not come from a trusted source". however I have used this email for some time and am happy with it . can … (read more)

Thunderbird says this "the certificate for imap.supanet.com does not come from a trusted source". however I have used this email for some time and am happy with it . can I continue with this certificate as I do trust this source

Archived 11 565

SMTP server connection fails

I am using a E-mail server that uses LetsEncrypt certificates. I was using Thunderbird 128 ESR without problems. When the certificate was updated, I was requested to conf… (read more)

I am using a E-mail server that uses LetsEncrypt certificates. I was using Thunderbird 128 ESR without problems. When the certificate was updated, I was requested to confirm - then sending E-mails was possible. Now I have updated to Thunderbird 140 ESR. The E-Mail servers LetsEncrypt certificate was now updated but in Thunderbird I do not get any information about this, nor get I requested to check the new certificate. The SMTP connection just fails. The IMAP access to the E-mail server works fine. (IMAP and SMTP work both fine with K9-Mail on my mobile device)

How can I get Thunderbird to ask me again to check the updated certificate?

Solved Archived 11 488

Ongoing certificate bugs—is there a fix in the pipeline?

Certificate errors have been an ongoing, several-times-a-day frustration for me and other users, with different ISPs, since approximately June 25. Is anyone working on th… (read more)

Certificate errors have been an ongoing, several-times-a-day frustration for me and other users, with different ISPs, since approximately June 25. Is anyone working on this bug? Because it clearly is a bug: Not only I but several other users have reported that Thunderbird worked fine until that date, then stopped working fine. What changed, and can it be put back the way it was, or can we receive some explicit instructions on how to fix it for ourselves? It's making Thunderbird borderline unusable. Every time I try to send a message, I have to confirm a security exception, then send it again. Several times a day, when I try to fetch messages, I have to confirm security exceptions. The confirmations never seem to stick. This is some BS.

Solved Archived 14 447

How to resolve S/MIME certificate issues

I'm trying to send encrypted email to a recipient who I have a certificate for, but Thunderbird states: End-to-end encryption requires resolving certificate issues for ..… (read more)

I'm trying to send encrypted email to a recipient who I have a certificate for, but Thunderbird states:

End-to-end encryption requires resolving certificate issues for ....

That's rather unhelpful - what issues exactly? I've imported the CA certs into the system and they are shown in TB. openssl verify on the cert returns OK. I'm at a loss as to what might be the issue.

Archived 2 419

Senders’ certificates no longer imported?

Hello! I just observed a new issue with S/MIME. When trying to send an encrypted mail to somebody new, I get an error “End-to-end encryption requires resolving certificat… (read more)

Hello!

I just observed a new issue with S/MIME. When trying to send an encrypted mail to somebody new, I get an error “End-to-end encryption requires resolving certificate issues with somebody@example.com”.

The message is not very helpful, and doesn’t propose any solution. So a web search gave me this article: Prerequisite for sending an encrypted email message. It states:

> If Thunderbird considers the email's signature and the sender's certificate valid, it will automatically be imported and available when you attempt to encrypt an email to that correspondent using the S/MIME technology.

When I open the sender’s mail, the signature is confirmed as valid by Thunderbird.

Ignoring the warning message and trying to send the encrypted mail results in the following error in the log: `mailnews.send: NS_ERROR_ILLEGAL_VALUE: Component returned failure code: 0x80070057 (NS_ERROR_ILLEGAL_VALUE) [nsIMsgComposeSecure.beginCryptoEncapsulation]`

So, I verified in my list of certificates for people, and that new person didn’t figure in the list. Other people did, the last one from 6 June.

Is it possible there’s a bug causing TB to not import the certificate when I open the mail? What would a workaround be? Is there a way to import a sender’s certificate manually from their signed mail?

Archived 6 419

Having trouble with digital signature/encryption settings on Ubuntu 20

I regularly send/receive encrypted email on Windows with Outlook but seeing as most of my work is done on my Ubuntu partition, I was interested in a Linux solution. I was… (read more)

I regularly send/receive encrypted email on Windows with Outlook but seeing as most of my work is done on my Ubuntu partition, I was interested in a Linux solution. I was able to connect to my exchange server using owl automagically and see my email, no problem. I had some experience getting smart-card readers working on Ubuntu so I already had some things in place using the OpenSC Security Device. TB was able to talk to my card reader, grab the certificates, and I was able to set my S/MIME digital signing and encryption certificates. It definitely works, I can decrypt messages that I had already received in the way I expect, it checks if I have a card inserted, asks for me PIN, and the message decrypts correctly as I would expect. The issue is that if I try to send a signed email to myself, I get the error, "Sending of the message failed. You specified that this message should be digitally signed, but the application either failed to find the signing certificate specified in your Mail & Newsgroup Account Settings, or the certificate has expired." A similar message is sent if I try to encrypt (but not sign) a message to myself but for the encryption certificate.

I don't understand this message, as TB can definitely see my card, ask my card for my private key, and use it to decrypt messages, so I believe my E2E settings are correct. Neither certificate is expired, both expire sometime in 2027. I even added my companies root certificate to my Certificate Authorities in TB, so I don't believe it's an issue with my certificate being deemed invalid, and the error message certainly doesn't suggest as much. I've also tried both of my card-readers in case something was only looking at the first one, but both can be signed into correctly but neither let me send signed/encrypted email. The only clues I can see are the console error in my terminal when the message fails to send...

console.error: mailnews.send: "Sending failed; , exitCode=2147500037, originalMsgURI="

Also when I open a remote debugging session, this is the error shown...

mailnews.send: NS_ERROR_FAILURE: Component returned failure code: 0x80004005 (NS_ERROR_FAILURE) [nsIMsgComposeSecure.beginCryptoEncapsulation]

   _startCryptoEncapsulation resource:///modules/MimeMessage.jsm:510
   _writePart resource:///modules/MimeMessage.jsm:558

Does anyone know what I might be doing wrong and nudge me in the correct direction?

Solved Archived 1 417

Why does thunderbird not Confirm Security Exception anymore

My e-mail provider has done the annual update of security and provided a new e-mail cert; however, Thunderbird no longer successfully updates it. Thunderbid gets to the p… (read more)

My e-mail provider has done the annual update of security and provided a new e-mail cert; however, Thunderbird no longer successfully updates it.

Thunderbid gets to the point of confirming the security exception; however, does not proceed.

This is using ThunderBird 140.4.0esr (64-bit) from Ubuntu Snap, on Ubuntu LTS 24.04.3.

Solved Archived 2 399

does not accept self-signed smtp certificates

With the latest updates, the client no longer accepts the self-signed smtp certificate as exceptions. The server is old and there is no way to upgrade to a newer one. It … (read more)

With the latest updates, the client no longer accepts the self-signed smtp certificate as exceptions. The server is old and there is no way to upgrade to a newer one. It is also not possible to connect a third-party certification authority

Solved Archived 5 397

"Reply with Template" always uses encryption, resulting in corrupted e-mail reply

When my message filter uses the "Reply with Template" action, the reply e-mail is always PGP encrypted, even when I do not have any public key for the recipient e-mail ad… (read more)

When my message filter uses the "Reply with Template" action, the reply e-mail is always PGP encrypted, even when I do not have any public key for the recipient e-mail address. As a result, the reply e-mail is always corrupted.

I am using Thunderbird 140.7.1esr on Windows 10.

I have attached a screenshot of what the reply e-mail always looks like.

In the Template that I am using, the "encrypt" button is not selected, and in the OpenPGP menu of the Template, the "Encrypt" menu item does not have a checkmark next to it.

Does anyone know how I can get Thunderbird to send reply e-mails without using encryption?

Archived 9 370

Thunderbird stopped sending e-mails: error message - you are about to override how T-Bird identifies this site. This site attempts to identify itself with invalid information. Confirm security exception...

E-mail stopped working. T-bird doesn't respond to "send e-mail" to address book. Something to do with an invalid information and encryption. T-Bird worked fine yeste… (read more)

E-mail stopped working. T-bird doesn't respond to "send e-mail" to address book. Something to do with an invalid information and encryption. T-Bird worked fine yesterday. This is a very recent development. Help. Thank you.

Archived 1 360

Email sync issue with invalid certificate message

Hello. I have added a new account to Thunderbird, and it is not syncing to show new messages. I am getting a pop-up from Tbird saying "The certificate for mail.newcreat… (read more)

Hello.

I have added a new account to Thunderbird, and it is not syncing to show new messages. I am getting a pop-up from Tbird saying "The certificate for mail.newcreationloughborough.uk is not valid for that server ..." etc. I have gone through the procedure titled 'Troubleshooting email client warnings about invalid server certificates' to add Norton's certificate to my email app (as directed by the 'resolve' link in the 'Resolve email sync issues caused by certificate warnings' from the Norton EE Cyber Security add-on), and it tells me that the certificate is already installed.

What can I do next to get it to sync?

Archived 7 339

Thunderbird, smtp server certificate

Hello, My SMTP server uses Let's Encrypt certificate. The website with the same domain has no certificate. Thunderbird refuses to connect to my SMTP server. Test connecti… (read more)

Hello, My SMTP server uses Let's Encrypt certificate. The website with the same domain has no certificate. Thunderbird refuses to connect to my SMTP server. Test connection to the server (STARTTLS) in account settings sais "The secure connection to the server failed" (or similar. I see bg localization). Another server with Let's Encrypt certificate. Test pases. Clicking View certificate shows webserver cert (from DigiCert Inc).

I can't send emails! :)

Regards! Valentin

Archived 8 329

PKCS # 12 operation failed for unknown reason when importing an S/MIME client certificate

I successfully imported the self-signed CA certificate into thunderbird. Then I tried to import the p12 S/MIME client certificate and this error message popped up (cf. sc… (read more)

I successfully imported the self-signed CA certificate into thunderbird. Then I tried to import the p12 S/MIME client certificate and this error message popped up (cf. screenshot below).

However, I checked the client certificate and it seems fine:

  1. openssl pkcs12 -in smime-client-certificate.p12 -info -noout

Enter Import Password: MAC: sha256, Iteration 2048 MAC length: 32, salt length: 8 PKCS7 Encrypted data: PBES2, PBKDF2, AES-256-CBC, Iteration 2048, PRF hmacWithSHA256 Certificate bag PKCS7 Data Shrouded Keybag: PBES2, PBKDF2, AES-256-CBC, Iteration 2048, PRF hmacWithSHA256

  1. pk12util -l smime-client-certificate.p12

Enter password for PKCS12 file: Certificate(has private key):

   Data:
       Version: 3 (0x2)
       Serial Number: 1 (0x1)
       Signature Algorithm: PKCS #1 SHA-256 With RSA Encryption
       Issuer: "..."
       Validity:
           Not Before: Thu Feb 19 13:32:18 2026
           Not After : Sun Feb 17 13:32:18 2036
       Subject: "E=user@example.com,CN=user@example.com,
           O=example.com,ST=...,C=..."
       Subject Public Key Info:
           Public Key Algorithm: X9.62 elliptic edwards curve public key
       unknown SPKI algorithm type
       Raw:
           69:58:ee:5d:45:3f:10:d9:bb:8c:a3:b6:a5:c6:16:a6:
           53:78:65:77:73:5d:e0:6f:60:df:2c:32:f3:c2:e2:58
       Signed Extensions:
           Name: Certificate Basic Constraints
           Data: Is not a CA.
           Name: Certificate Key Usage
           Usages: Digital Signature
                   Non-Repudiation
                   Key Encipherment
           Name: Extended Key Usage
               E-Mail Protection Certificate
           Name: Certificate Subject Key ID
           Data:
               99:8a:6d:e4:ec:3a:25:5d:ad:26:a0:36:e1:da:a2:ea:
               bc:88:79:50
           Name: Certificate Authority Key Identifier
           Key ID:
               f5:6c:37:9a:37:d1:81:43:d3:54:3f:b9:33:23:85:c1:
               7e:17:73:88
           Name: Certificate Subject Alt Name
           RFC822 Name: "user@example.com"
   Signature Algorithm: PKCS #1 SHA-256 With RSA Encryption
   Signature:
       44:3a:5e:d7:44:51:f1:3c:a3:80:d8:54:f4:9c:d8:0b:
       ...
   Fingerprint (SHA-256):
       88:95:7A:DF:A5:7C:D1:E8:A5:55:A8:18:BD:BD:7D:92:1F:7D:6E:17:26:68:39:84:26:F3:F6:F3:4A:5C:56:90
   Fingerprint (SHA1):
       72:83:D0:13:C9:C9:AD:46:CA:C3:73:66:9E:79:5B:5C:3B:2E:81:47

Key(shrouded):

   Encryption algorithm: PKCS #5 Password Based Encryption v2 
       Encryption:
           KDF: PKCS #5 Password Based Key Derive Function v2 
               Parameters:
                   Salt:
                       dc:f9:bf:4a:80:e1:7c:4a:b4:f5:52:6b:9b:d5:75:ad
                   Iteration Count: 2048 (0x800)
                   KDF algorithm: HMAC SHA-256
           Cipher: AES-256-CBC
               Args:
                   04:10:0d:a4:96:03:00:2a:d5:a6:fe:d3:6c:a5:d0:12:
                   67:b3

What is going on and how to troubleshoot this issue as there is no logging about this matter into /var/log/syslog?

Environment: - Ubuntu 25.10 - thunderbird 2:1snap1-0ubuntu3

Archived 3 320

Thunderbird Can't Receive Mail with Connection Security set to SSL/TLS

I have spent some time digging through your messages about how to fix this issue. I get the general "where to" enable SSL/TLS but no trouble shooting to this specific lev… (read more)

I have spent some time digging through your messages about how to fix this issue. I get the general "where to" enable SSL/TLS but no trouble shooting to this specific level.

Spectrum (charter) Internet on May-30-25 a pop up "Add Security Exception" on wife's account (Image #1 below). We have same Internet provider and same server config's (except email name & password or course).

 This Security Exception has happened before, as well as on my account in the past. 

Although, I never got the Exception this time. We did "Confirm Security Exception" 2x on her account and she is up and running again. No issues.

  However, I can't receive e-mails with the Account Settings / Server Settings / Security Settings

"Connection Security" set to SSL/TLS" it must be set to "None" When set to SSL/TLS and I push the "Get Mail" button, the server isn't even banged as there's no msg in lower left frame of TB. I have gmail account and it does bang that one like it should. If set to "None" I get the msg in lower left TB frame showing connection to Charter server and I receive any outstanding e-mails. But I don't want to continue without a password.

 Under [Settings/ Privacy & security / Manage Certificates]

hers (Image #2 below) looks different than mine (Image #3 below). She has the 2 confirmed Security Exceptions, but also has a "View" and "Export" button that are bolded when the specific line item is highlighted. I do not have a View or Export button shown. How do I enable the SSL/TLS with password and actually receive emails?

 I am using TB 128.11.0esr (64-bit)

thx in advance Gene

Solved Archived 9 318

Thunderbird says certificate expired, letsencrypt certbot says its good, different dates shown

I'm using Thunderbird 140.5.0esr. I have a remote email server on a small "linode" and recently had to restore it from a backup. When opening Thunderbird, I get the mess… (read more)

I'm using Thunderbird 140.5.0esr. I have a remote email server on a small "linode" and recently had to restore it from a backup.

When opening Thunderbird, I get the message "The certificate for adonax.com expired on 10/29/2025." I've been getting emails up to and including yesterday.

I ran the renewal program (sudo certbot renew) from the command line of my remote server, and was told the certificate did not need renewing. The "expiry date" is shown to be 2026, March 20 when having certbot display the certificate information.

So, there is some sort of disconnect happening in the communications between Thunderbird and the locations of the certificates on my server. I'm hoping for some advice as to how to trace the path. One possibility is that there is a location on my server that is used to connect to the certs and this is holding stale information due to the recent restore done for the remote server. Another is that maybe there is cached information or something else blocking the request from Thunderbird.

From Thunderbird, I am presented with a form "Add Security Exception". This indicates that thunderbird is contacting the location adonax.com:993. I checked the port from the server using UFW and it is open to all. The Thunderbird form however hangs when I hit the "Get Certificate" button, and clicking the "Confirm Security Exception" appears to do nothing. The button "View..." opens a tab with the expired certificate. All the information on the certificate that is displayed by Thunderbird looks good, matches what I have in terms of URLs, but the dates are wrong.

Is there perhaps something blocking thunderbird from using port 993? Is there a way to test that? If 993 is working, I will try to research what is going on there at the Ubuntu end. I tried putting adonax.com:993 in Chrome and got an ERR_UNSAFE_PORT, for what that is worth.

Solved Archived 2 298

Thunderbird no longer able to display S/MIME encrypted messages sent from Outlook App (Android and iOS)

From Microsoft: "Recent Outlook Mobile updates introduced a stricter and more standards-aligned S/MIME message structure. The messages themselves are valid, but some thir… (read more)

From Microsoft: "Recent Outlook Mobile updates introduced a stricter and more standards-aligned S/MIME message structure. The messages themselves are valid, but some third‑party mail clients such as Thunderbird do not fully support the way Outlook mobile structures the encryption. As a result, these clients may display a blank message body even though the encrypted content is present.

As a workaround, if you need to send encrypted mail to recipients who use third‑party clients, use Outlook desktop or Outlook on the web instead of Outlook mobile. These versions generate encrypted messages in a format that is more widely supported. "

I couldn't find this reported anywhere in these forums. Is there a solution being worked on to address this issue? Or has anyone found a workaround? We are stuck with using the Outlook app until the Thunderbird app supports S/MIME.

Archived 1 298

Sending of S/MIME message failed.

Hi All. New to Thunderbird but liking what I see. Am trying to install a new certificate but keep seeing the same error message when I attempt to send an email: Sending o… (read more)

Hi All. New to Thunderbird but liking what I see. Am trying to install a new certificate but keep seeing the same error message when I attempt to send an email:

Sending of the message failed. You specified that this message should be digitally signed, but the application either failed to find the signing certificate specified in your Mail & Newsgroup Account Settings, or the certificate has expired.

So here is what we know:

The certificate seems to work (I've sent test emails to a couple of test email accounts) when I use it in Outlook safe mode. Can't get it to work in normal Outlook mode because of add-ins, hence my switch to Thunderbird. They seem to appear fine in the S/MIME section for digital signing and encryption and I can even see the certificate when I go into Manage S/MIME Certificates.

Has anyone come across this before / got any ideas about how to resolve this? Thanks!!

Archived 5 290