Funkcionalnosć tutoho sydła so přez wothladowanske dźěła wobmjezuje, kotrež maja waše dožiwjenje polěpšić. Jeli nastawk waš problem njerozrisuje a chceće prašenje stajić, wobroćće so na naše zhromodźenstwo pomocy, kotrež na to čaka, wam na @FirefoxSupport na Twitter a /r/firefox na Reddit pomhać.

Pomoc přepytać

Hladajće so wobšudstwa pomocy. Njenamołwimy was ženje, telefonowe čisło zawołać, SMS pósłać abo wosobinske informacije přeradźić. Prošu zdźělće podhladnu aktiwitu z pomocu nastajenja „Znjewužiwanje zdźělić“.

Dalše informacije

Self-signed encryption cert stopped working in Thunderbird 60.2.1

  • 7 wotmołwy
  • 1 ma tutón problem
  • 78 napohladow
  • Poslednja wotmołwa wot Matt

more options

I've used a self-signed certificate for years to send and receive encrypted emails with family. I don't use Enigmail or PGP.

Somewhere near Thunderbird 60.2.1, this stopped working. When I try to send an email, Thunderbird reports:

   "Sending of the message failed.
   You specified encryption for this message, but the application either failed to find the 
   encryption certificate specified in your Mail & Newsgroup Account Settings, or the certificate has expired."

The certificate has not expired, and it can be found in the Certificate Manager. Viewing details it says "This certificate has been verified for the following uses: SSL Certificate Authority". I can't remember if this used to say something different.

The CA is my own generated CA called "self-signed".

Did something tighten down recently?

I've used a self-signed certificate for years to send and receive encrypted emails with family. I don't use Enigmail or PGP. Somewhere near Thunderbird 60.2.1, this stopped working. When I try to send an email, Thunderbird reports: "Sending of the message failed. You specified encryption for this message, but the application either failed to find the encryption certificate specified in your Mail & Newsgroup Account Settings, or the certificate has expired." The certificate has not expired, and it can be found in the Certificate Manager. Viewing details it says "This certificate has been verified for the following uses: SSL Certificate Authority". I can't remember if this used to say something different. The CA is my own generated CA called "self-signed". Did something tighten down recently?

Wubrane rozrisanje

gbell12 said

Matt said
I think the key is self signed certificates are not valid for encryption.

Just recently? Because these same certs have been working for years.

I "sort of" follow certificate changes, but in all honesty most of it goes over my head. One of the reasons is the Thunderbird community use the Firefox certificate manager and store, so the developers never touch the stuff really. SO I try and follow it a bit, but usually the first we know about certificate changes are when something stops working.

I think perhaps this bug is relevant https://bugzilla.mozilla.org/show_bug.cgi?id=1485013 "The problem appears to that certs without the x509 v3 extensions cannot be added."

This might be relevant https://bugzilla.mozilla.org/show_bug.cgi?id=1475348

This is also in the current sort of timeframe. https://bugzilla.mozilla.org/show_bug.cgi?id=1122239

But given how easy it is to get a SSL/TLS certificate https://letsencrypt.org/ really is it worth messing around with self signed ones.

Tutu wotmołwu w konteksće čitać 👍 0

Wšě wotmołwy (7)

more options

I should note that I've checked the release notes.

And in the message compose window, if I go Security->View Security Info, it does indeed show that the status is Invalid, but no indication as to why.

Wot gbell12 změnjeny

more options

Wot gbell12 změnjeny

more options

I think the key is self signed certificates are not valid for encryption.

more options

Matt said

I think the key is self signed certificates are not valid for encryption.

Just recently? Because these same certs have been working for years.

more options

Wubrane rozrisanje

gbell12 said

Matt said
I think the key is self signed certificates are not valid for encryption.

Just recently? Because these same certs have been working for years.

I "sort of" follow certificate changes, but in all honesty most of it goes over my head. One of the reasons is the Thunderbird community use the Firefox certificate manager and store, so the developers never touch the stuff really. SO I try and follow it a bit, but usually the first we know about certificate changes are when something stops working.

I think perhaps this bug is relevant https://bugzilla.mozilla.org/show_bug.cgi?id=1485013 "The problem appears to that certs without the x509 v3 extensions cannot be added."

This might be relevant https://bugzilla.mozilla.org/show_bug.cgi?id=1475348

This is also in the current sort of timeframe. https://bugzilla.mozilla.org/show_bug.cgi?id=1122239

But given how easy it is to get a SSL/TLS certificate https://letsencrypt.org/ really is it worth messing around with self signed ones.

more options

According to http://kb.mozillazine.org/Getting_an_SMIME_certificate

"Let's Encrypt does not currently offer S/MIME certificates"

I grabbed 4 from comodo for all the people in my family, but unfortunately they expire in a year! When the "Greg CA" was acceptable to TBird, my certs had a 10-year expiry :)

Thanks for the info Matt.

more options

I know the pain, as comodo is the last free S/mime certificate issuer I use them myself.

The only other option is enigmail and while I do not use it, it has become much more user friendly in recent years is my understanding. (at least you get to issue and revoke your own certificates.)