Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

Learn More
Open

In the Thunderbird Certificate Manager, where does TB store the reference to deleted smartcard certificates?

BarnRat1

I have a smartcard with email signature and encryption S/MIME certificates. I recently updated the signature and encryption certificates on my card and was having issues getting TB to read the encryption certificate. Both the signature and the encryption certificates check out fine with the certificate issuer (IdentTrust), can be read by Windows, Edge, and Firefox Certificate Managers, and works fine for authentication to websites. I am wondering if I accidentally deleted the encryption certificate in the TB Certificate Manager, as the signature certificate (having same issue date and email address) is visible but the encryption certificate is not found. To see if I could restore access I have tried replacing existing profile files having dates prior to the new certificates for:

cert9.db
content-prefs.sqlite 
key4.db
permissions.sqlite
pkcs11.txt
prefs.js
SiteSecurityServiceState.bin

This restored my settings for my previous (now expired) certificates but still does not allow me to view the encryption certificate in Certificate Manager. I also tried removing the logins.json and logins-backup.json files which had no effect on ability to view the encryption certificate, and tried adding the certificate ID .

I'm hoping someone could explain what the TB Certificate Manager does when when accessing and deleting a certificate from a smartcard (it can't electronically delete it without the middleware - in this case ActivClient, and the missing certificate still remains as other apps can still access the certificate in question). I surmise that the name must be stored somewhere, and hopefully by editing the appropriate preference setting I can restore access.

I have a smartcard with email signature and encryption S/MIME certificates. I recently updated the signature and encryption certificates on my card and was having issues getting TB to read the encryption certificate. Both the signature and the encryption certificates check out fine with the certificate issuer (IdentTrust), can be read by Windows, Edge, and Firefox Certificate Managers, and works fine for authentication to websites. I am wondering if I accidentally deleted the encryption certificate in the TB Certificate Manager, as the signature certificate (having same issue date and email address) is visible but the encryption certificate is not found. To see if I could restore access I have tried replacing existing profile files having dates prior to the new certificates for: cert9.db content-prefs.sqlite key4.db permissions.sqlite pkcs11.txt prefs.js SiteSecurityServiceState.bin This restored my settings for my previous (now expired) certificates but still does not allow me to view the encryption certificate in Certificate Manager. I also tried removing the logins.json and logins-backup.json files which had no effect on ability to view the encryption certificate, and tried adding the certificate ID . I'm hoping someone could explain what the TB Certificate Manager does when when accessing and deleting a certificate from a smartcard (it can't electronically delete it without the middleware - in this case ActivClient, and the missing certificate still remains as other apps can still access the certificate in question). I surmise that the name must be stored somewhere, and hopefully by editing the appropriate preference setting I can restore access.

You must log in to your account to reply to posts. Please start a new question, if you do not have an account yet.