Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
June 19, 2013, 07:16:58 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
669093
Posts
71145
Topics
145753
Members
Latest Member:
lostcoast
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Business / Enterprise Security Products & Services
Digital Certificates
Email Certificate
Thunderbird and OCSP error with Comodo cert
« previous
next »
Pages:
[
1
]
Author
Topic: Thunderbird and OCSP error with Comodo cert (Read 13477 times)
gtmikey
Newbie
Offline
Posts: 9
Thunderbird and OCSP error with Comodo cert
«
on:
December 29, 2008, 07:16:52 PM »
I'm the guy who got his free e-mail certificates from Comodo and installed them in OE and Thunderbird and THEN got SecureEmail. To be honest, I pretty much have SecureEmail turned off and use the certificate functions in Thunderbird and Firefox directly. As I correspond with many people who use webmail such as Hotmail and Yahoo, the SecureEmail one time encryption function to people without their own X.509 certificates is not useful. To the problem!
I recently turned on the OCSP function in Thunderbird version 2.0.0.18 (20081105) for Windows (W2K Pro). This version of Thunderbird and Firefox version 3.0.5 share the certificate store. By turning on OCSP I mean I selected the "Use OCSP to validate only certificates the specify an OCSP service URL". When trying to send an e-mail to a friend who also has a Comodo free e-mail certificate obtained without SecureEmail, I get the error that an OCSP failure has occurred and the certificate could not be validated. I strongly suspect this is a Thunderbird issue but so far I have not been able to find a report of this issue on line. As Comodo's support is excellent, I started my in depth search here.
I have attached screen shots of the two error messages.
The error message does not make it clear which or both certificates cannot be validated. Both certificates show this value in the Authority Information Access Extension OCSP: URI:
http://ocsp.comodoca.com
. My certificate was issued with a not valid before date 2008-10-13 00:00:00 AM GMT and my friend's has 2008-10-22 00:00:00 AM GMT for that value.
BTW Greenwich Mean Time has been replaced with Universal Coordinated Time and AM/PM is meaningless in 24 hour time indicators such as my local time indication for not valid before of 2008-10-12 17:00:00 PM.
OCSPerr01.png
(274.27 KB, 1024x768 - viewed 19 times.)
OCSPerr02.png
(296.36 KB, 1024x768 - viewed 7 times.)
Logged
gordon2008
Comodo Member
Offline
Posts: 47
Re: Thunderbird and OCSP error with Comodo cert
«
Reply #1 on:
January 03, 2009, 11:10:20 AM »
Hi,
Please submit the ticket in the following link
http://support.comodo.com/index.php?_m=tickets&_a=submit
Logged
BigMike
Product Translator
Comodo's Hero
Offline
Posts: 336
Re: Thunderbird and OCSP error with Comodo cert
«
Reply #2 on:
January 05, 2009, 06:57:16 PM »
Quote from: gtmikey on December 29, 2008, 07:16:52 PM
I recently turned on the OCSP function in Thunderbird version 2.0.0.18 (20081105) for Windows (W2K Pro). This version of Thunderbird and Firefox version 3.0.5 share the certificate store. By turning on OCSP I mean I selected the "Use OCSP to validate only certificates the specify an OCSP service URL". When trying to send an e-mail to a friend who also has a Comodo free e-mail certificate obtained without SecureEmail, I get the error that an OCSP failure has occurred and the certificate could not be validated. I strongly suspect this is a Thunderbird issue but so far I have not been able to find a report of this issue on line.
Hm, I had the same problem. All I could find about Thunderbird and OCSP was the hint to disable it...
I thought that's not a big problem, because you can set the CRL update interval down to once per day and adding the needed urls for the CRL's is done in a few minutes - but as I realized, the automatic update mechanism for CRL's seems also to be broken! Oh - and I'm pretty sure, that's a Thunderbird problem
Logged
Latest German translation files for
CIS v6 (draft)
/
CIS v5
/
older versions
malbec
Newbie
Offline
Posts: 2
Re: Thunderbird and OCSP error with Comodo cert
«
Reply #3 on:
November 13, 2009, 08:12:05 AM »
Hi,
I have exactly the same problem: I use Thunderbird version 2.0.0.23 (20090812). I installed the certificate I requested yesterday, but when I select "Use OCSP to validate only certificates the specify an OCSP service URL", wWhen trying to send an e-mail , I get the error "an OCSP failure has occurred and the certificate could not be validated".
If I select "don't use OCSD", evrything works OK.
Did you get an answer to your ticket ?
I thank you in advance for your help.
Logged
gtmikey
Newbie
Offline
Posts: 9
Re: Thunderbird and OCSP error with Comodo cert
«
Reply #4 on:
November 13, 2009, 09:45:55 AM »
The short answer was, "It is a Thunderbird problem. Go tell Mozilla." Mozilla said, "(the silence was deafening.)". So I just turned OCSP off and forgot about it. I imagine it will be fixed when enough complaints register it onto the radar.
Logged
BigMike
Product Translator
Comodo's Hero
Offline
Posts: 336
Re: Thunderbird and OCSP error with Comodo cert
«
Reply #5 on:
November 13, 2009, 10:32:45 AM »
Quote from: gtmikey on November 13, 2009, 09:45:55 AM
"It is a Thunderbird problem. Go tell Mozilla."
In my eyes, this is the only answer Comodo can give. Because it is a bug in Thunderbird. It's not caused by misconfiguration.
Quote from: gtmikey on November 13, 2009, 09:45:55 AM
So I just turned OCSP off and forgot about it.
You should at least keep in mind, that the certificate could have been revoked! That's the purpose of OCSP/CRL's: Checking, if the certificate was reported as compromised.
Quote from: gtmikey on November 13, 2009, 09:45:55 AM
I imagine it will be fixed when enough complaints register it onto the radar.
I wouldn't count on this in the near future. As I read, the problem is known for a long time now.
Logged
Latest German translation files for
CIS v6 (draft)
/
CIS v5
/
older versions
malbec
Newbie
Offline
Posts: 2
Re: Thunderbird and OCSP error with Comodo cert
«
Reply #6 on:
November 13, 2009, 12:15:51 PM »
Thanks to both of you!
So, I'll go on without OCSP, till Mozilla does something...
Quote
You should at least keep in mind, that the certificate could have been revoked! That's the purpose of OCSP/CRL's: Checking, if the certificate was reported as compromised.
Yes. Sure. May be could I chek it manually from time to time? But how?
Logged
BigMike
Product Translator
Comodo's Hero
Offline
Posts: 336
Re: Thunderbird and OCSP error with Comodo cert
«
Reply #7 on:
November 13, 2009, 01:41:40 PM »
You can force a manual download of the certificate revocation list.
First of all, each vendor of certificates provides its own CRL. The address of the CRL can be found in the certificate. So, depending on which vendor issued the certificate of your contact, you may need to add more CRLs.
I'll describe the procedure:
First, look in
Tools -> Properties, Advanced, Certificates. Click on "Certificates...", there select the "Certificates of other people" tab and you'll get a list of all certificates of your contacts.
Double click a certificate, select "Details"
Under "Certificate Layout", you'll find an entry "Extensions" with an subentry, holding urls to download the crl.
Copy one of these urls to clipboard. For COMODO it's
Code:
http://crl.comodoca.com/UTN-USERFirst-ClientAuthenticationandEmail.crl
for example.
Close this window and the certificate manager, back in properties, click on "CRLs...", select "Import" and paste the copied url.
Note, that the automatic download of the CRL won't work, too!!
It seems to be also known to the Mozilla people...
To force a manual update, you have to click "Update" here.
I'm using a localized version of Thunderbird, so my translated names may differ from the original ones.
Logged
Latest German translation files for
CIS v6 (draft)
/
CIS v5
/
older versions
Jim__
Comodo Loves me
Offline
Posts: 124
Re: Thunderbird and OCSP error with Comodo cert
«
Reply #8 on:
November 13, 2009, 05:26:33 PM »
Quote from: gtmikey on November 13, 2009, 09:45:55 AM
The short answer was, "It is a Thunderbird problem. Go tell Mozilla." Mozilla said, "(the silence was deafening.)". So I just turned OCSP off and forgot about it. I imagine it will be fixed when enough complaints register it onto the radar.
What is the bug number for your report? I will vote for it. Voting is one way to draw developer attention to a problem.
Logged
BigMike
Product Translator
Comodo's Hero
Offline
Posts: 336
Re: Thunderbird and OCSP error with Comodo cert
«
Reply #9 on:
November 13, 2009, 06:10:15 PM »
Here's the
bug report for the ocsp issue
on Bugzilla. First reported 2006-05-10 - good luck!
Logged
Latest German translation files for
CIS v6 (draft)
/
CIS v5
/
older versions
gtmikey
Newbie
Offline
Posts: 9
Re: Thunderbird and OCSP error with Comodo cert
«
Reply #10 on:
November 14, 2009, 03:36:59 AM »
Sorry if you took my short summary as a criticism of Comodo. It wasn't meant as such. I figured it was a Mozilla prob but I knew I would get a response from Comodo and hoped, if there was an answer, Comodo would have it. Which work around you have provided. Thank you, Big Mike.
Logged
BigMike
Product Translator
Comodo's Hero
Offline
Posts: 336
Re: Thunderbird and OCSP error with Comodo cert
«
Reply #11 on:
November 14, 2009, 05:23:37 AM »
Quote from: gtmikey on November 14, 2009, 03:36:59 AM
Sorry if you took my short summary as a criticism of Comodo.
I didn't take it as a criticism. I wasn't completely sure if it was clear (to you and anyone else reading this thread) from Comodo's answer, that they can't give any hints on solving this problem, since there simply is no solution.
I just tried to stress this point to spare others from spending hours trying to find the solution.
Logged
Latest German translation files for
CIS v6 (draft)
/
CIS v5
/
older versions
Tags:
Thunderbird
OCSP
E-mail Certificate
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.057 seconds with 22 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com