We're calling on all EU-based Mozillians with iOS or iPadOS devices to help us monitor Apple’s new browser choice screens. Join the effort to hold Big Tech to account!

Шукати в статтях підтримки

Остерігайтеся нападів зловмисників. Mozilla ніколи не просить вас зателефонувати, надіслати номер телефону у повідомленні або поділитися з кимось особистими даними. Будь ласка, повідомте про підозрілі дії за допомогою меню “Повідомити про зловживання”

Докладніше

Ця тема перенесена в архів. Якщо вам потрібна допомога, запитайте.

verify sha256 signed S/MIME Mail from IBM Notes

  • 3 відповіді
  • 1 має цю проблему
  • 2 перегляди
  • Остання відповідь від christ1

more options

Hello, we are using IBM Notes9 to write S/MIME mails signed with a sha256 certificate. Our CA is the DFN Verein. When the received mail is opend with Thunderbird (newest Version), the virification says that the mail was changed and the signature is not valid. Apple mail or outlook saying the signature is ok.

When i write a signed S/MIME mail with a sha1 certificate from Notes all is fine in Thunderbird.

Maybe someone can help us.

Regards Holger

Hello, we are using IBM Notes9 to write S/MIME mails signed with a sha256 certificate. Our CA is the DFN Verein. When the received mail is opend with Thunderbird (newest Version), the virification says that the mail was changed and the signature is not valid. Apple mail or outlook saying the signature is ok. When i write a signed S/MIME mail with a sha1 certificate from Notes all is fine in Thunderbird. Maybe someone can help us. Regards Holger

Усі відповіді (3)

more options

Did you import the DFN CA cert into Thunderbird?

more options

Yes. And here is the chain: https://pki.pca.dfn.de/uni-kassel-ca/pub/cacert/chain.txt

If i send a mail from a Thunderbird or Outlook-Client using this certifikate, the signature is displayed as true in thunderbird. Only sending by IBM Notes to Thunderbird the signature appears as not valid. But sending from Notes to Apple Mail, the signature is displayed as valid.

more options

here is the chain

You'll need all CA certs in the chain in the Thunderbird certificate store.

send a mail from a Thunderbird or Outlook-Client using this certifikate

Which cert? For signing a message the private key of the sender is required. The recipient needs to have the cert (a.k.a. the public key) of the sender in the Thunderbird certificate store. I suppose the user cert used to sign the message has been issued by the DFN CA?

appears as not valid

What is the exact error message?