On Wed, 25 Aug 2004, Julien Pierre wrote:

> Mariusz Woloszyn wrote:
> > I don't see any way to use client certs in Mozilla _mailer_.
>
> They do work. You can configure your default client cert for SSL under
> edit/preferences/privacy & security/certificates . Set either "select
> automatically" or "ask every time". Admittedly, there is no specific
> setting of the client cert to use to login to each web site. In most

I'm not connecting to a _web_ server.

> cases there is no ambiguity and Mozilla & NSS can determine the right
> cert to use automatically. If not, set "ask every time" and mozilla will
> present you with a dialog to let you select the client cert you want.
>
> Of course that can only work if you installed your client certs in
> mozilla previously (eg. from a PKCS#12 import).
>

This works for Mozilla _browser_ and not for mozilla mailer. :(
If I try to connect to smtps service the mailer does not ask me for any
certificate (although "ask every time" is set).
If the remote peer is configured to not authenticate the client everything
works perfectly, but if the remot end requires certificate I got an Error
Code -12227.
On the server side I got:
Aug 25 16:40:51 XXX stunnel[7890]: SSL_accept: 140890C7:
error:140890C7:SSL routines:SSL3_GET_CLIENT_CERTIFICATE:peer did not
return a certificate

The mailer is configured to _send_ mails through smpts on port 465.

Seems like the client certificate authentication feature is missing in
mozilla mailer (1.7.2).

Regards,

-- 
Mariusz Wołoszyn
Internet Security Specialist, GTS - Internet Partners
_______________________________________________
mozilla-crypto mailing list
[EMAIL PROTECTED]
http://mail.mozilla.org/listinfo/mozilla-crypto

Reply via email to