• Open Menu Close Menu
  • Apple
  • Shopping Bag
  • Apple
  • Mac
  • iPad
  • iPhone
  • Watch
  • TV
  • Music
  • Support
  • Search apple.com
  • Shopping Bag

Lists

Open Menu Close Menu
  • Terms and Conditions
  • Lists hosted on this site
  • Email the Postmaster
  • Tips for posting to public mailing lists
[Fed-Talk] Re: DHS and DOE Certificates
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Fed-Talk] Re: DHS and DOE Certificates


  • Subject: [Fed-Talk] Re: DHS and DOE Certificates
  • From: Paul Derby <email@hidden>
  • Date: Thu, 26 Oct 2006 14:39:07 -0400

There is no "Common Name" entry in the DOE certificate for "Tom".  Which is unlike my own certificate which does have a "Common Name" of "Thawte Personal Freemail Issuing CA" in my own certificate.  That is part of the "problem".

I try to keep pretty close watch on the contents of my Key Chain.  I'm pretty sure no other certs were added.  And I'm positive no DOE Certificate Authority cert was added.


On Oct 26, 2006, at 12:01 PM, Paul Derby wrote and Michael Kluskens responded:

Well, here is the scenario that doesn't work with certificates from DOE Los Alamos National Labs which uses Entrust:

I send an email to Tom with my Thawte digital signature.

He receives, confirms the email is signed. He replies with a signed email.

His two Entrust certs go on my "login" keychain automatically.

And you can confirm no other certificates were added the first time you received signed email from him? Not that it would be surprising that no other certificates were added, it would be very surprising that you can confirm that, I certainly never noticed the extra certificates I was getting.

The issuer of his cert is: Organization - U.S. Government, organization unit - Department of Energy, Organization Unit - Los Alamos National Laboratory

What is the "Common Name" of the certificate that signed his certificate. You have to double click on the certificate and look down the list of information. First is Subject Name, then Issuer Name, inside that I find Common Name, which is the name of the certificate that signed that certificate. I don't expect their certificates to display differently, however, they could be incomplete.

On top of that you should also find URL's in the certificate information that permit you to get additional information, perhaps even the signing certificate in the case where it was truly not automatically included or auto downloaded by Keychain Access (strictly speaking I don't know what put the signing certificates in my keychain, I just know that when I find an untrusted certificate I also find it's signing certificate once I know what I'm looking for).

There are no URL's in this certificate.  My Thawte certificate doesn't have embedded URL's either.


You can also scroll down your certificate list by arrows and watch for certificates that are not trusted, then determine what type of certificate they are and what certificate signed them (the Common Name not the understandable name).

Michael

The certs from DHS and DOE are the only untrusted certs that I have.  All the rest of my email related certs are trusted, mostly from either Thawte users or DOD users.

Are there any people from DHS or DOE/Los Alamos that monitor this group?  I there anyone from either of these organizations or that works with these organizations that has successfully interoperated with Entrust certs using Apple email?

--
Paul Derby
Chief Enterprise Architect
The Tauri Group
703-647-2745
email@hidden



 _______________________________________________
Do not post admin requests to the list. They will be ignored.
Fed-talk mailing list      (email@hidden)
Help/Unsubscribe/Update your Subscription:

This email sent to email@hidden

  • Prev by Date: Re: [Fed-Talk] DHS and DOE Certificates
  • Next by Date: [Fed-Talk] Local Government Contact in Apple
  • Previous by thread: Re: [Fed-Talk] DHS and DOE Certificates
  • Next by thread: [Fed-Talk] Local Government Contact in Apple
  • Index(es):
    • Date
    • Thread