为提升您的使用体验,本站正在维护,部分功能暂时无法使用。如果本站文章无法解决您的问题,您想要向社区提问的话,请到 Twitter 上的 @FirefoxSupport 或 Reddit 上的 /r/firefox 提问,我们的支持社区将会很快回复您的疑问。

搜索 | 用户支持

防范以用户支持为名的诈骗。我们绝对不会要求您拨打电话或发送短信,及提供任何个人信息。请使用“举报滥用”选项报告涉及违规的行为。

详细了解

Recipient's "encrypt-only" S/MIME certificate deemed not valid by Thunderbird

more options

My Thunderbird version at the moment is 102.13.0 (64-bit) running under Linux but the issue is not limited to either this particular version, nor the OS - colleagues running Thunderbird on Windows boxes report the same thing. We deal with an organization which issues their own S/MIME certificates. For a long time it worked flawlessly - we imported their CA as trusted, imported personal certificates of email recipients and everything worked smooth. Lately they started issuing two different certificates per person - one for signing emails, another for encryption. And now since emails from them come with a signature created with a certificate which has "Digital Signature" and "Non Repudiation" uses - everything works fine "inbound". The problem starts if we want to send encrypted emails back to them. Even if we import the encryption certificates we get (those have only "Key Encipherment" usage) and the certificates themselves are valid in any possible way (lifetime, proper CA chain imported and so on), still Thunderbird tells us it can't find proper certificate to encrypt the message.

My Thunderbird version at the moment is 102.13.0 (64-bit) running under Linux but the issue is not limited to either this particular version, nor the OS - colleagues running Thunderbird on Windows boxes report the same thing. We deal with an organization which issues their own S/MIME certificates. For a long time it worked flawlessly - we imported their CA as trusted, imported personal certificates of email recipients and everything worked smooth. Lately they started issuing two different certificates per person - one for signing emails, another for encryption. And now since emails from them come with a signature created with a certificate which has "Digital Signature" and "Non Repudiation" uses - everything works fine "inbound". The problem starts if we want to send encrypted emails back to them. Even if we import the encryption certificates we get (those have only "Key Encipherment" usage) and the certificates themselves are valid in any possible way (lifetime, proper CA chain imported and so on), still Thunderbird tells us it can't find proper certificate to encrypt the message.

所有回复 (1)

more options

Hi "Crack my back" Perhaps the folks at #openpgp:mozilla.org on Matrix can help

Cheers! ...Roland