Thunderbird does not recognize a signed SSL certificate
Dear support,
I experience a very strange problem that I don't quite understand.
I run an ISP server serving HTTPS and IMAP with TLS/SSL encryption. Both services use the same SSL certificate issued by GeoTrust/RapidSSL for server edward.ennabe.de
When I open a https connection to the server, Firefox correctly resolves the certificate chain and uses the Equifax root CA (which is correct). However, when I try to connect to a mailbox via Thunderbird, all I get in the Certificate Hierarchy is my server edward.ennabe.de. I don't think that this is "works as designed", or is it?
Is something wrong with my Thunderbird or my Dovecot configuration? What really strange is that firefox recognizes it properly.
Thank you in advance
Kind Regards
ZeroEnna
Выбранное решение
In Thunderbird click the 'Details' tab in the Certificate Viewer window. Do you see all CA certificates listed in the 'Certificate Hierarchy' field also installed in your Thunderbird certificate store? When checking that look for the 'Authorities' tab. If there are any certs listed in the chain missing in the Thunderbird certificate store (for whatever reason), you can try to export them in Firefox, and import them into Thunderbird.
Прочитайте этот ответ в контексте 👍 0Все ответы (7)
What is the exact error message you get with Thunderbird? Do you get a prompt to create an exception ('I understand the risks')?
For https://edward.ennabe.de I do get: The certificate is only valid for the following names: www.foto-treff-bielefeld.de, foto-treff-bielefeld.de (Error code: ssl_error_bad_cert_domain)
I'd expect something similar for Thunderbird.
Hello,
yeah..uhm...sorry for this confusion. The Cert is valid for https://edward.ennabe.de:8080 (my ISPConfig Backend)
I get the message
"Certificate is not trusted because it hasn't been verified by a recognized authority using a secure signature."
Whch is very strange because I use the very same certificate for both HTTPS and Mailing.
I found this article in the mozillazine:
But I don't quite understand How I should tell any Issuer to not use MD5 hashes.
By the way, I tried the same with a new certificate signed by COMODO...same problem.
I don't understand what you're trying to say with 'Issuer to not use MD5 hashes'.
Can you create a screenshot of the error you get in Thunderbird, and also possibly one with the cert details? See attached instructions.
Here are the screens :) Two from Thunderbird (english language pack, but this error is language independent in Thunderbird), and two other from Firefox, where it's working properly.
Kind Regards
Изменено
Выбранное решение
In Thunderbird click the 'Details' tab in the Certificate Viewer window. Do you see all CA certificates listed in the 'Certificate Hierarchy' field also installed in your Thunderbird certificate store? When checking that look for the 'Authorities' tab. If there are any certs listed in the chain missing in the Thunderbird certificate store (for whatever reason), you can try to export them in Firefox, and import them into Thunderbird.
Hello,
your suggestion was quite helpful in many ways. I just checked the certificate chain, and it turned out to be broken. Some intermediate certs were missing. I fixed that and now it works like a charm.
Thank you very much!