Hi Stefan,

On Tue, 25 Feb 2003 19:30:01 -0500 Stefan Tanurkov <[EMAIL PROTECTED]>
wrote:

>> S/MIME certificates expire. It happens.
> 
>  You sound like somebody died. ;-)
> 
>  Well, generally, you are right - messages signed on a particular date
>  must be valid even if the key is expired.

To make it short: albeit your points are valid: what about simply
displaying: "Signature valid, message not tampered with but certificate
expired"???

It will still show up as "Valid", but the user can decide if he/she
trust the signature due to it's expiration or not. He/she can have a
look for herself on the "Created" and "Received" date and decide if the
cert already was expired when it was used or not.

At least this behavior would show up the "state" most exactly: correct
signature, no alteration in the message but I (the S/MIME system) am
unable to tell you about validity of the certificate at date/time
"today/now".

Just my 0.02 <currency of your choice>
-- 
Pit

________________________________________________________
 Current beta is 1.63b6 | "Using TBBETA" information:
http://www.silverstones.com/thebat/TBUDLInfo.html

Reply via email to