Hi Stefan, On Tue, 25 Feb 2003 19:30:01 -0500 Stefan Tanurkov <[EMAIL PROTECTED]> wrote:
>> S/MIME certificates expire. It happens. > > You sound like somebody died. ;-) > > Well, generally, you are right - messages signed on a particular date > must be valid even if the key is expired. To make it short: albeit your points are valid: what about simply displaying: "Signature valid, message not tampered with but certificate expired"??? It will still show up as "Valid", but the user can decide if he/she trust the signature due to it's expiration or not. He/she can have a look for herself on the "Created" and "Received" date and decide if the cert already was expired when it was used or not. At least this behavior would show up the "state" most exactly: correct signature, no alteration in the message but I (the S/MIME system) am unable to tell you about validity of the certificate at date/time "today/now". Just my 0.02 <currency of your choice> -- Pit ________________________________________________________ Current beta is 1.63b6 | "Using TBBETA" information: http://www.silverstones.com/thebat/TBUDLInfo.html

