Where did you install Firefox from? Help Mozilla uncover 3rd party websites that offer problematic Firefox installation by taking part in our campaign. There will be swag, and you'll be featured in our blog if you manage to report at least 10 valid reports!

搜索 | 用户支持

防范以用户支持为名的诈骗。我们绝对不会要求您拨打电话或发送短信,及提供任何个人信息。请使用“举报滥用”选项报告涉及违规的行为。

Learn More

Can't use S/MIME certificate to sign email

  • 5 个回答
  • 1 人有此问题
  • 15 次查看
  • 最后回复者为 Matt

more options

This is happening to a user I support, but I can recreate this issue in the thunderbird 91.4.0 snap package on ubuntu.

Whenever I load my S/MIME certificates (procured from digicert) I get a message when signing an email, not allowing me to sign or encrypt my email:

"Sending of the message failed. You specified that this message should be digitally signed, but the application either failed to find the signing certificate specified in your Mail & Newsgroup Account Settings, or the certificate has expired."

I have tried loading my CA certificates under the authorities tab, where it tells me that the cert is already in the certificate store. I have also checked, and the certificate doesn't expire until May of 2022.

I've tried finding extended debugging parameters, and trying many different things to no avail. I appreciate any suggestions that someone may have.

This is happening to a user I support, but I can recreate this issue in the thunderbird 91.4.0 snap package on ubuntu. Whenever I load my S/MIME certificates (procured from digicert) I get a message when signing an email, not allowing me to sign or encrypt my email: "Sending of the message failed. You specified that this message should be digitally signed, but the application either failed to find the signing certificate specified in your Mail & Newsgroup Account Settings, or the certificate has expired." I have tried loading my CA certificates under the authorities tab, where it tells me that the cert is already in the certificate store. I have also checked, and the certificate doesn't expire until May of 2022. I've tried finding extended debugging parameters, and trying many different things to no avail. I appreciate any suggestions that someone may have.
已附加屏幕截图

所有回复 (5)

more options
I have tried loading my CA certificates under the authorities tab

You need to import your cert (and private key) under the 'Your Certificates' tab in Thunderbird.

more options

I have imported my cert and private key under the 'Your Certificates' tab, and still get the same result.

more options

I have this happen to me periodically. When it does the certificate in account settings has lost it's serial number. Clicking select opens the certificate manager against the correct certificate and I then can sign mail again until the next time.

Bug 1481969 refers

more options

Thanks for your reply!

The certs are selected, and showing their fingerprints. To ensure this wasn't the issue, I have re-selected the certificates only to have the same result (I've attached an image showing the thumbprints next to the name). I've also tried going in to the cert authority area and selecting "This certificate can identify mail users" tick box on the Digicert CA certificates, and that did not work either.

The user, who is also experiencing this issue, his S/MIME certificate is good until May of next year. Since my cert is nearing expiration, I'm going to try renewing early, and see if that fixes the issue on my side to make sure the user and I are experiencing the same issue.

I will update this If anything changes from my testing.

more options

you might also want to disable the option to check certificates using "query OCSP responder servers" before you renew. My guess is that process is returning a not valid result.