Cant choose which digital certificate to sign outgoing email in Mail.app

I am posting this here as this post:
http://discussions.apple.com/message.jspa?messageID=5746197#5746197
was archived.
I just wanted to add that this is still an issue for us. We use three digital certificates inside our organization, one from Thawte, one from caCert, and one from our in-house/private CA. All three work perfectly inside all applications that we use them in. There is on issue which is that if the user clicks the icon on the far right side of their outgoing email to "sign" that email, there is no telling which certificate it will use. We want to use the one from Thawte for all outgoing email but it ends up picking one of the other ones instead & as far as I can tell there is no way to control this or change this.
What I am requesting is that Mail.app ask me which certificate I want to use, either once, in preferences, or each email, or something, as sendind with the wrong one is really not workable.
I think 10.5.2 is a real step forward. Thanks for all the hardwork to make the improvements in it that we see.
Thanks so much.
Sjobeck

Somewhere online I found mention that you can assign the cert you don't want to use as untrusted and the one you do want to use as trusted. So in Keychain, double click on your Thawte cert, click on the Trust arrow and change the "When using this certificate:" drop down to "Always Trust". Do the opposite for your other certs.
This way you can still use your other certs for decrypting if anyones uses it to send to you. But you'll always use the trusted cert for signing/encrypting new messages.
I too wish there was a way to explicitly select the cert you want to use but till they allow that, this is the best way I've found to work around the issue.

Similar Messages

  • How to get digital certificate informaiton of the email in mail adapter

    Hi, expert:
    I have a requirement to verify the validation of coming email with digital certification. The mail is with digital certification. If the coming email is valid, I 'll get the attachemt of the mail for further processing. I have a sender mail adapter and receiver file adapter configued.
    I have already my own developed adapter module, which is configued in mail adapter. My question is how to retrieve the detailed certificate information in the adapter module developed by myself. Is it feasible?
    Thanks a lot.

    Hi Oscar !!
    refer this blog & links , you will get all you are looking for
    <b>How to use Digital Certificates for Signing & Encrypting Messages in XI</b>
    /people/varadharajan.krishnasamy/blog/2007/05/11/how-to-use-digital-certificates-for-signing-encrypting-messages-in-xi
    http://help.sap.com/saphelp_nw04/helpdata/en/a8/882a40ce93185de10000000a1550b0/frameset.htm
    Thanks !
    Regards
    Abhishek Agrahari

  • How to filter list of digital certificates for signing PDF

    Is it possible to change the configuration of Reader installation to filter the list of installed certificates that can be used for digitally signing documents?
    The filtered list will appear when users attempt to select a certificate for digitally signing a document.
    Thanks.

    Hi Carla,
    Unfortunately, Extended Key Usage is not one of the properties you can enforce.
    The things you can set are:
    appearanceFilter (i.e. enforce the use of a custom signature appearance)
    certspec(i.e. the signing certificate must meet some specific criteria)  <<<----- This is what you are more interested in, more below
    digestMethod(i.e. enforce the use of a specific cryptographic hashing algorithm)
    filter (i.e. enforce the use of a specific security handler if you want to use something other than the one built into Acrobat)
    legalAttestations (i.e. enforce the reason or purpose of the certifying signature)
    lockDocument (i.e. enforce any further changes to the document after the signature is applied)
    mdp (i.e. the rules for changing the document applied as part of a certifying signature)
    reasons (i.e. a list of one or more reasons the signer can use, as opposed to them adding their own)
    shouldAddRevInfo (i.e. force the inclusion on the revocation information (CRL or OCSP response) in the PDF file)
    subFilter (i.e. require the use of a specific signature format. This is very arcane)
    timeStampspec (i.e. require the use of a specific time stamp server)
    version (i.e the minimum version of Acrobat that can decipher the signature. the only two options are versions 6 or 8)
    The second item is the certspec, and this is what I've been pointing you towards. For the sake of discussion, think of everything you can read in a certificate as an extension. The serial number is an extension, the subject is an extension, the valid from date is an extension, etc. When a certificate is created, some of these extensions are required, other optional, and you can even add in extension that are not publicly defined, and only you will know about.
    Acrobat has the ability to enforce the signer to use a certificate that contains some, but not all of the known extensions. The extensions it can enforce are:
    issuer (i.e. require the use of a certificate that is issued by a specific Certificate Authority)
    keyUsage (i.e. require the signers certificate contain one or more of the nine possible values that can be included)
    oid (i.e. require that the Certificate Policy extension contain a specific value)
    subject (i.e. require that the document is signed by one specific person using one specific digital ID)
    subjectDN (i.e. require that the document is signed by one specific person, but they get to choose which digital ID to use)
    url (i.e. if a required digital ID is not available, where the signer can procure an acceptable digital ID)
    urlType (i.e. if the user is directed to the URL, should it be a web server where they can download a digital ID or a remote signing server where the digital ID stays on the remote server)
    That's it. If it's not one of these items then Acrobat cannot enforce that the item is available. Extended Key Usage is not on the list.
    Steve

  • Which digital certificate (SSL) is used when a proxy client is created

    Dears,
    Could someone please guide if there are more than one digital certificate (SSL) added to the SAP system, and we create a proxy client using the 'URL' (https://....) option, than which digital certificate will be used in the check done.
    Thanks.
    Reda

    The names that go on the certificate must match the names you planned when you did the CAS namespace design.
    Some details here:http://blogs.technet.com/b/exchange/archive/2014/02/28/namespace-planning-in-exchange-2013.aspx
    So in your case if the cert does not match the name, then this will prompt users with errors.   They need to match.  As long as all your internal devices trust the issuer of the internal CA then you can use that.   Installing an
    enterprise CA will automatically publish it's root CA  public cert into AD so it works easily.
    Cheers,
    Rhoderick
    Microsoft Senior Exchange PFE
    Blog:
    http://blogs.technet.com/rmilne 
    Twitter:   LinkedIn:
      Facebook:
      XING:
    Note: Posts are provided “AS IS” without warranty of any kind, either expressed or implied, including but not limited to the implied warranties of merchantability and/or fitness for a particular purpose.

  • Saving copy of a doc prompts 'Choose a Digital Certificate'

    Hi All,
    Whenever i tried to save a copy of excel sheet downloaded from portal, it promts 'Choose a Digital Certificate'. This seems to be happening with only few files and not with all. Can anyone help me out removing this cretificate issue.

    Any Suggestion for this

  • "Choose a digital certificate" pop up when save Excel spreadsheet in IE

    One reporting page in our SSL application will generate an Excel spreadsheet. User will be prompted to either Save it to harddrive or Open it within the IE.
    If user chooses to Open it inside IE, then go "File --> Save as", this "Choose a digital certificate" dialog box will pop up, but there's nothing to choose. User has to click on OK/Cancel for about 12 times before it actually allows user the save...
    to create this spread sheet from jsp page i haved used
    <%@ page language="java" contentType="application/vnd.ms-excel; charset=ISO-8859-1"
         pageEncoding="ISO-8859-1" %>

    I don't think this has nothing to do with Excel.
    Go to Tools - Internet Options - Security Tab and click on the "Custom Level" button. Then find the option: "Don't prompt for client certificate selection when no certificate or only one certificate exists" and set it to "enable"

  • Customizing the Choose A Digital Certificate Screen

    We are trying to find out a way to customize the Choose A Digital Certificate Screen that is displayed when the SSLVerifyClient is required so we can make it more user friendly since for some of our users, we need them to select CANCEL or some other option since they don't have the X509 based device at this point.
    Is there anyway to customize this screen and/or overwrite it.
    Thanks in advance.
    KA

    That screen is totally on the browser side, so you have to check with browser providers if it would be possible to customize it.

  • "no access to the digital certificate" - Trying to export my first iOS app from Flash - Help please

    Hello
    I'm trying to export my first iOS app from flash to my desktop / on the device (Flash Pro CC, Iphone5)
    I followed the instructions on the adobe website to build an air app for iOS but on the last step it
    doesn't export the app.
    What I've done so far:
    - Apple developer account
    - creating the certificate + convert it to .p12
    - app ID / Name etc.
    - creating the provisioning profile from apple
    - iOS Air app in flash (Only Text "Hello world" with a tween)
    Now i have to load the certificates into Flash & enter a password (is it the password that
    i entered in the certificate or from my developer account/ Apple ID password? Both didn't work at the end)
    When i klick on publish in the last step than it loads a while but then i get the Error:
    "no access to the digital certificate"
    What is wrong? Can you help me please.

    Also, I should say, when I go into my phone on the computer and try to install an app, I get this message:
    Unable to start operation. Installer is already in use.
    Any ideas

  • Mail Security certificate issue and cannot send email from mail app on surface 2

    well im have the same issue like others and coincidently we all started to have this issue just recently like few days ago. Please help us out as on the surface 2 mail app my Hotmail account ( The main account )
    cannot send mails and on the account setting it says there is a problem with the server security certificate. So how to fix it ???

    Does this issue only happen with Hotmail account? Have you tested the account in other mail programs or send a email via web mail in a browser? What is the result if we delete the account then recreate the account?
    Please also refer to solutions in this link:
    Supporting Windows Mail 8.1 in your organization
    See this part Self-Signed Certificates in Windows Mail 8.1
    http://blogs.technet.com/b/exchange/archive/2013/10/18/supporting-windows-mail-8-1-in-your-organization.aspx
    Yolanda Zhu
    TechNet Community Support

  • Upgraded to 10.4.9 now cant receive or send emails using Mail.app

    I just upgraded to 10.4.9 from 10.2.8 and now the new Mail.app(v2.1) can't receive or send emails.
    "Sent" emails only get to the Outbox for trying again later.
    "Get Mail" is answered after 20 seconds with an error stating among other things "The attempt to read data from the server "xxx.xxx.xx.x" failed"
    I connect to the internet through ethernet which is connected to my work's server setup. Ethernet is at the top of the list of the Network Config Options.
    Tried removing the Mail preference file and reentering settings - after settings added, says the server cannot be found.
    It's a Mail.app issue as accessing the web is no problem, sending and receiving mail using Eudora and Thunderbird is no problem.
    The problem occurred after I went to 10.4.9 as I received an email in the short time I was on 10.4.6.
    Tried reinstalling Mail from install disk but it didn't want to install an older version of the program it seems.
    Any advice would be appreciated.
    PowerMac G5 1.8Ghz Uniprocessor   Mac OS X (10.4.9)  

    Mac OS X 10.4.7 introduced connection issues in Mail similar to what you’re observing as a result of (according to the documentation) “Mail now supports connecting to mail servers through a SOCKS proxy”. If that’s the problem, it can usually be fixed by going to System Preferences > Network, choosing the network port configuration used to connect to Internet from the Show popup menu and disabling the SOCKS Proxy in the Proxies section, if it’s enabled.
    And while you’re at it, choose Network Port Configurations from the Show popup menu, and make sure that the configuration used to connect to Internet appears at the top of the list.

  • Digital Certificates and signing

    i am developping a security application that needs to access the web client certificate store to enable him once he choose to submit his form to select which cetificate to sign with; i need to know how to access in java the certificate store on the cient machine.
    thanks

    U store the certificate in u r hard disk,,,and try to read from fileinputstream..
    Sample Code
    InputStream is = new FileInputStream("/anand/Example_test/test.cer");
    CertificateFactory cf = CertificateFactory.getInstance("X.509");
    X509Certificate cert =(X509Certificate)cf.generateCertificate(is);
    System.out.println("Certificate : algname = " + cert.getSigAlgName());
    System.out.println("Certificate : User DN = " + cert.getSigAlgOID());
    System.out.println("Certificate : After = " + cert.getNotAfter());
    System.out.println("Certificate :Before = " + cert.getNotBefore());
    System.out.println("Certificate : User DN = " + cert.getNotAfter());
    System.out.println("Certificate : User DN = " + cert.getSubjectDN().getName());
    Hope this will help
    Rgds,
    Anand

  • Can't choose existing certificate to sign/decrypt email after profile installed

    After playing with iphone configuration utiltiy
    After profile installed, I can't choose existing S/MIME sign/encrypt certificate inside the phone. But ok if I config manually in iphone.
    Is there any purpose for this? Is there anyway to let user choose certificate after profile installed?

    I just thought I would put myself on this discussion, since I can't find anything to "fix" this problem. It seems to work for some people, but not others...
    I have everything set up the same way as nebbbben. Server is set up, certificate installed, VPP set up, and everything works great for some of my users.
    For about half of my users- I can send out invites, they will click on the invite and login to the App Store, but they will never show up in Profile Manager as registered for VPP on the Mac Server. For those that do- pushing apps is easy and transparent, although there is as much as a half-hour time delay. For those that can't get registered, no matter how many invites I send them, there isn't any way to distribute the apps. It's very frustrating, and the only "answers" I can find just say it should "just work."
    I'm assigning apps to the users specifically, not to groups. I have no doubt it would work fine if the Server/VPP ever showed they were registered. The invite system seems to be hit-and-miss.
    I'm wondering if there is a command-line hack or some other setting that can be changed to reset their App Store settings to try again?

  • Can't choose which AppleID to use in Apple's new Cards app

    Apple's new Cards app is forcing me to use an AppleID to purchase that I don't want to use.  I can't find anywhere to set which ID to charge the Card to.  The Store setting in Settings is ignored by Cards it seems.  What gives?  This is using iOS 5.

    You can't install OVI Maps on the mem card. The country maps will be installed on the mem card though.
    ‡Thank you for hitting the Blue/Green Star button‡
    N8-00 RM 596 V:111.030.0609; E71-1(05) RM 346 V: 500.21.009

  • My mail app is not quitting and i need to update a app in apple store which is not letting me do because the mail app is in use

    i try to quit it but it won't work just like the finder app that you can't close i need help

    Open up the Activity Window - if there are bars with stop signs by them - that don't seem to be moving press the stops signs to stop what is going on.
    If you can't open it or nothing is there - you may just have to power down.  
    I have had mail seem to be stuck so I can disconnect from the internet - so if I cant do a controlled shut down - I just power the system down by holding the power button down.   

  • Certificate alert every time I open Mail.app

    Every time I open Mail, I get a certificate alert saying that the following certificate is not valid:
    smtp.emailsrvr.com
    My belief is that if it is not a valid certificate, then I don’t want to use it.
    Is this a TLS certificate?
    Is there a way to determine which e-mail account that uses it?
    Is this cert used for iCoud?
    Is there a way to tell my computer to never use it and to never alert me again?
    It is mostly an annoyance. And a concern that my computer will keep trying to use an invalid certificate.

    1. It's a certificate of authicity given by the server through which you are trying to send e-mail.
    2. In Mail Preferences > Accounts > Any account there is a SMTP dropdown menu. Select Change SMTP-Server list. From there you can see a list of SMTP servers configured. You can also see which e-mailaddress they are assigned to, if any.
    3. For certain I can say that this isn't used for iCloud.
    4. You can delete this SMTP server.
    If this SMTP server is being used legitemately by one of your e-mailadresses, you need to contact your e-mail provider to aquire an valid certificate.

Maybe you are looking for

  • HT5058 Syncing Exchange Account in iCal with iCloud

    I have successfully added an Exchange account calendar to my iCal. Problem is I can't get my Exchange calendar to sync with iCloud. How do I get my Exchange account calendar to sync with iCloud since they appear in different sections? Thank you.

  • 1 1/2 year old dv4t screen failure and upgrade question

    Hi, I need some help troublshooting my HP dv4t notebook PC.  First of all, let me mention that I am pretty good with computers as I have my CompTIA A+ and Network+ 2009 certifications and I work full time in a computer store as a repair technician bu

  • What is the best way to upgrade from OES2 running on SLES 10

    Tonight was so frustrating. I was half way doing upgrade of an OES 2 SP3 (running on SLES 10 sp4). Wanted to upgrade to SLES 11 SP2 and OES 11 SP1. Is there a way to just patch the server using installation source as the ISOs? Because I was upgrading

  • ITunes "Check for updates" don't work for two specific app

    I have iPhone 4S, and iTunes at Windows 7 PC. Clean install. I've bought an GPS navigation app, Turkey Navigation iGO Primo app, which was free at first release day. My problem is, when I click the button "Check for updates" at iTunes(PC), it don't s

  • Do I have to change my flash player when I install Firefox

    I am thinking about changing my Internet Browser (IE) and I want to ask do i have to change the version of my flash player and other features because I usually download them on IE. For Example some programs have different kind of Mirror Links and the