Windows 10 reached EOS (end of support) on October 14, 2025. For more information, see this article.

Sykje yn Support

Mij stipescams. Wy sille jo nea freegje in telefoannûmer te beljen, der in sms nei ta te stjoeren of persoanlike gegevens te dielen. Meld fertochte aktiviteit mei de opsje ‘Misbrûk melde’.

Mear ynfo

Dizze konversaasje is argivearre. Stel in nije fraach as jo help nedich hawwe.

Senders’ certificates no longer imported?

  • 6 antwurd
  • 0 hawwe dit probleem
  • 182 werjeftes
  • Lêste antwurd fan christ1

Hello!

I just observed a new issue with S/MIME. When trying to send an encrypted mail to somebody new, I get an error “End-to-end encryption requires resolving certificate issues with somebody@example.com”.

The message is not very helpful, and doesn’t propose any solution. So a web search gave me this article: Prerequisite for sending an encrypted email message. It states:

> If Thunderbird considers the email's signature and the sender's certificate valid, it will automatically be imported and available when you attempt to encrypt an email to that correspondent using the S/MIME technology.

When I open the sender’s mail, the signature is confirmed as valid by Thunderbird.

Ignoring the warning message and trying to send the encrypted mail results in the following error in the log: `mailnews.send: NS_ERROR_ILLEGAL_VALUE: Component returned failure code: 0x80070057 (NS_ERROR_ILLEGAL_VALUE) [nsIMsgComposeSecure.beginCryptoEncapsulation]`

So, I verified in my list of certificates for people, and that new person didn’t figure in the list. Other people did, the last one from 6 June.

Is it possible there’s a bug causing TB to not import the certificate when I open the mail? What would a workaround be? Is there a way to import a sender’s certificate manually from their signed mail?

Hello! I just observed a new issue with S/MIME. When trying to send an encrypted mail to somebody new, I get an error “End-to-end encryption requires resolving certificate issues with somebody@example.com”. The message is not very helpful, and doesn’t propose any solution. So a web search gave me this article: [[Prerequisite for sending an encrypted email message]]. It states: > If Thunderbird considers the email's signature and the sender's certificate valid, it will automatically be imported and available when you attempt to encrypt an email to that correspondent using the S/MIME technology. When I open the sender’s mail, the signature is confirmed as valid by Thunderbird. Ignoring the warning message and trying to send the encrypted mail results in the following error in the log: `mailnews.send: NS_ERROR_ILLEGAL_VALUE: Component returned failure code: 0x80070057 (NS_ERROR_ILLEGAL_VALUE) [nsIMsgComposeSecure.beginCryptoEncapsulation]` So, I verified in my list of certificates for people, and that new person didn’t figure in the list. Other people did, the last one from 6 June. Is it possible there’s a bug causing TB to not import the certificate when I open the mail? What would a workaround be? Is there a way to import a sender’s certificate manually from their signed mail?

Alle antwurden (6)

Btw I’m on Thundebird 128.12 on Linux.

You posted: "When trying to send an encrypted mail to somebody new, I get an error “End-to-end encryption requires resolving certificate issues with somebody@example.com”.

The message is not very helpful, and doesn’t propose any solution. So a web search gave me this article: Prerequisite for sending an encrypted email message. It states:

> If Thunderbird considers the email's signature and the sender's certificate valid, it will automatically be imported and available when you attempt to encrypt an email to that correspondent using the S/MIME technology.

When I open the sender’s mail, the signature is confirmed as valid by Thunderbird."

Didn't you say in the beginning that you had an error message?

Thunderbird is an email client that queries CRLs (the whole procedure seems to be undergoing changes). What more do you think tbird can do about someone elses ctfs?

Hi, thanks for your answer.

Yes, that’s exactly the point.

The nuance is that I get an error when trying to *send* (i.e. encrypt) the mail—not when reading it or verifying the certificate and the signature.

I’d expect tbird to import the certificate once I open the sender’s mail, which it doesn’t seem to do.

Maybe the changes broke it?

Is there any manual way to import that certificate?

Is there anything related in the error console (CTRL-Shift-J) when you attempt to send an encrypted message?

Is this always happening or just for one particular recipient?

Hi and thanks for helping.

Yes, there’s an error in the console when trying to send the message encrypted:

`mailnews.send: NS_ERROR_ILLEGAL_VALUE: Component returned failure code: 0x80070057 (NS_ERROR_ILLEGAL_VALUE) [nsIMsgComposeSecure.beginCryptoEncapsulation]`

It’s hard to tell if it’s always happening, since I don’t receive S/MIME-signed mails from unknown senders every day. If you could send one to test, that’d be great! You can send to smime@ux-t.dev

So, I verified in my list of certificates for people, and that new person didn’t figure in the list. Other people did, the last one from 6 June.

When the cert from the new contact wasn't imported into your Thunderbird's certificate store I'd suspect a problem with that cert. Due to the lack of a valid cert you do get the error message when attempting to send an encrypted message to that recipient.

Is there any manual way to import that certificate?

Ask the owner of the problematic cert to send it as an email attachment. You can then try to import it into Thunderbird. At the top right of the Thunderbird window, click the menu button ≡ > Settings - Privacy & Security - Certificates - Manage Certificates

In the Certificate Manager select the 'People' tab, and click Import

If you could send one to test, that’d be great!

I don't want to do that.

Bewurke troch christ1 op