<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=2186" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2017-02-15T18:04:40+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=2186</id>
<entry>
<author><name><![CDATA[fil9o]]></name></author>
<updated>2017-02-15T18:04:40+01:00</updated>
<published>2017-02-15T18:04:40+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2186&amp;p=9401#p9401</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2186&amp;p=9401#p9401"/>
<title type="html"><![CDATA[Re: [HELP] Unable to sign emails (xubuntu thunderbird)]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2186&amp;p=9401#p9401"><![CDATA[
Adding certificate to both 9c and 9d causes pin prompt every time i read a message.<br />However i can send signed emails (after two pin prompts).<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4693">fil9o</a> — Wed Feb 15, 2017 6:04 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[fil9o]]></name></author>
<updated>2017-02-15T17:56:36+01:00</updated>
<published>2017-02-15T17:56:36+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2186&amp;p=9400#p9400</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2186&amp;p=9400#p9400"/>
<title type="html"><![CDATA[Re: [HELP] Unable to sign emails (xubuntu thunderbird)]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2186&amp;p=9400#p9400"><![CDATA[
I have exactly same issue on both OS X and Ubuntu 16.10.<br />Emails are properly decrypted,<br />Trying to send signed message causes same error.<br />Certificate signed by external CA<br />[EDIT]<br />I have yubikey 4<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4693">fil9o</a> — Wed Feb 15, 2017 5:56 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[tzn]]></name></author>
<updated>2016-01-29T09:18:58+01:00</updated>
<published>2016-01-29T09:18:58+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2186&amp;p=8230#p8230</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2186&amp;p=8230#p8230"/>
<title type="html"><![CDATA[Re: [HELP] Unable to sign emails (xubuntu thunderbird)]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2186&amp;p=8230#p8230"><![CDATA[
I sort of figured it out. The certificate also has to be stored in slot 9c for signing.<br />To be able to both sign outgoing mails and decrypt incoming mails the certificate has to be stored in 2 slots, namely 9c and 9d. I don't know if there is a technical necessity for that, but it's a bit confusing and also seems to lead to further problems.<br /><br />I am only able to send one (1) signed message. The first message I send can be signed. Thunderbird asks for the pin, signs the message, and sends it out. But any subsequent attempt to sign mails leads to the same error as stated above.<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Sending of the message failed.<br />Unable to sign message. Please check that the certificates specified in Mail &amp; Newsgroups Account Settings for this mail account are valid and trusted for mail.<br /></div><br />I have to either restart thunderbird or reinsert the yubikey every time I want to sign a message, which is basically for every new mail. That's not really usable.<br /><br />Has anybody else seen that problem and maybe even has a solution?<br /><br /><br />Thank you all.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4163">tzn</a> — Fri Jan 29, 2016 9:18 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[tzn]]></name></author>
<updated>2016-01-28T15:25:15+01:00</updated>
<published>2016-01-28T15:25:15+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2186&amp;p=8229#p8229</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2186&amp;p=8229#p8229"/>
<title type="html"><![CDATA[[HELP] Unable to sign emails (xubuntu thunderbird)]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2186&amp;p=8229#p8229"><![CDATA[
Hello all,<br /><br />i am trying to use the Yubikey NEO as a smart card holding my x509 S/MIME certificate and use that as a security device in both thunderbird 38.5.1and firefox 44.0 on xUbuntu 15.10. <br /><br />I have imported the key and cert to the yubikey:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">sudo yubico-piv-tool -a import-cert -a import-key -s 9d -K PKCS12 -i smime.p12 -p pass</div><br /><br />Key is loaded to the card:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">yubico-piv-tool -a status<br />CHUID:   No data available<br />Slot 9a:   No data available.<br />Slot 9c:   No data available.<br />Slot 9d:   <br />   Algorithm:   RSA2048<br />   Subject DN:   xxx<br />   Issuer DN:            xxx<br />   Fingerprint:   xxx<br />   Not Before:   Jan 18 13:36:27 2016 GMT<br />   Not After:   Jan 17 13:36:27 2019 GMT<br />Slot 9e:   No data available.<br />PIN tries left:   3<br /></div><br /><br />Opensc detects the reader:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">opensc-tool -l<br /># Detected readers (pcsc)<br />Nr.  Card  Features  Name<br />0    Yes             Yubico Yubikey NEO OTP+U2F+CCID 00 00<br /></div><br /><br />Pkcs-tool lists the certificate:<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">pkcs15-tool --list-data-objects<br />Using reader with a card: Yubico Yubikey NEO OTP+U2F+CCID 00 00<br />&lt;snip&gt;<br />Data object 'X.509 Certificate for Key Management'<br />   applicationName: X.509 Certificate for Key Management<br />   applicationOID:  2.16.840.1.101.3.7.2.1.2<br />   Path:            0102<br />   Data (1448 bytes): 538XXXXXXXX0FE00<br />&lt;snap&gt;<br /></div><br /><br />I imported the certificate chain in firefox and thunderbird and set trustlevels to trust them with everything.<br />I then loaded a new security device trying the two modules<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">/usr/lib/x86_64-linux-gnu/onepin-opensc-pkcs11.so<br />/usr/lib/x86_64-linux-gnu/opensc-pkcs11.so<br /></div><br /><br />Login with my pin works and I see my certificate and am able to set it in thunderbirds security dialog for digital signing and encryption.<br /><br />However, whenever I try to send a signed message, sending fails with the following error:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Sending of the message failed.<br />Unable to sign message. Please check that the certificates specified in Mail &amp; Newsgroups Account Settings for this mail account are valid and trusted for mail.<br /></div><br /><br />Curiously, decryption of emails sent to me does indeed work, meaning, the certificate is stored and accessed correctly.<br />I found a post somewhere that claims this is an issue with trust somewhere in the certificate chain. This cannot be the case here, I checked the chain and its trust multiple times, including reseting trust levels, deleting and reimporting the chain, and so on.<br /><br />I'm stuck now.<br /><br />Has anybody any idea why signing does not work?<br /><br />TL;DR<br />Sending signed mails with thunderbird using yubikey as a security device does not work. Decryption, however, works as expected. Any idea why?<br /><br />Thank you all for any insights<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4163">tzn</a> — Thu Jan 28, 2016 3:25 pm</p><hr />
]]></content>
</entry>
</feed>