This site will have limited functionality while we undergo maintenance to improve your experience. If an article doesn't solve your issue and you want to ask a question, we have our support community waiting to help you at @FirefoxSupport on Twitter and/r/firefox on Reddit.

Search Support

Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

Learn More

verify sha256 signed S/MIME Mail from IBM Notes

  • 3 respostas
  • 1 has this problem
  • 2 views
  • Last reply by christ1

more options

Hello, we are using IBM Notes9 to write S/MIME mails signed with a sha256 certificate. Our CA is the DFN Verein. When the received mail is opend with Thunderbird (newest Version), the virification says that the mail was changed and the signature is not valid. Apple mail or outlook saying the signature is ok.

When i write a signed S/MIME mail with a sha1 certificate from Notes all is fine in Thunderbird.

Maybe someone can help us.

Regards Holger

Hello, we are using IBM Notes9 to write S/MIME mails signed with a sha256 certificate. Our CA is the DFN Verein. When the received mail is opend with Thunderbird (newest Version), the virification says that the mail was changed and the signature is not valid. Apple mail or outlook saying the signature is ok. When i write a signed S/MIME mail with a sha1 certificate from Notes all is fine in Thunderbird. Maybe someone can help us. Regards Holger

All Replies (3)

more options

Did you import the DFN CA cert into Thunderbird?

more options

Yes. And here is the chain: https://pki.pca.dfn.de/uni-kassel-ca/pub/cacert/chain.txt

If i send a mail from a Thunderbird or Outlook-Client using this certifikate, the signature is displayed as true in thunderbird. Only sending by IBM Notes to Thunderbird the signature appears as not valid. But sending from Notes to Apple Mail, the signature is displayed as valid.

more options

here is the chain

You'll need all CA certs in the chain in the Thunderbird certificate store.

send a mail from a Thunderbird or Outlook-Client using this certifikate

Which cert? For signing a message the private key of the sender is required. The recipient needs to have the cert (a.k.a. the public key) of the sender in the Thunderbird certificate store. I suppose the user cert used to sign the message has been issued by the DFN CA?

appears as not valid

What is the exact error message?