Digital Certificate

Digital Certificate "There are problems with the signature"

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Digital Certificate "There are problems with the signature" pretzel 09-05-2006
Posted by =?Utf-8?B?cHJldHplbA==?= on September 5, 2006, 9:35 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Dear All,

We are testing out Digital Certificates as a prelude to Secure Messaging
with some of our Clients.

We obtained individual certificates for ourselves (as there is not many of
us) but started our Client on a Business account with a CA.

After setting up one of their users we notice that most times their email is
fine, but other times instead of the usual "rosette" there is a red line and
the statement "There are problems with the signature. Click the signature
button for details."

The message in the Security Properties is "Error: The message contents may
15:05:47 16/08/2006."

As we use an external mail filter (so all our mail is scanned in transit) we
believe that the scanning by our mail filter is causing the Digital
Certificate to detect a modification (or attempt) and hence the error.

My questions are:

1) Is the above assumption correct, and this is normal?

2) Is there anything that can be done to elimiate this (if caused by an
external mail scanner perhaps not)

3)If we move to Secure Messaging where the email is encrypted and hence
cannot be scanned by our mail filter, should I presume that the above error
will not appear and that all will be OK (at least as much as it should be)?

thanks

-----
pbw

Posted by imhotep on September 5, 2006, 1:02 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
pretzel wrote:

> Dear All,
>
> We are testing out Digital Certificates as a prelude to Secure Messaging
> with some of our Clients.
>
> We obtained individual certificates for ourselves (as there is not many of
> us) but started our Client on a Business account with a CA.
>
> After setting up one of their users we notice that most times their email
> is fine, but other times instead of the usual "rosette" there is a red
> line and
> the statement "There are problems with the signature. Click the signature
> button for details."
>
> The message in the Security Properties is "Error: The message contents may
> 15:05:47 16/08/2006."
>
> As we use an external mail filter (so all our mail is scanned in transit)
> we believe that the scanning by our mail filter is causing the Digital
> Certificate to detect a modification (or attempt) and hence the error.
>
> My questions are:
>
> 1) Is the above assumption correct, and this is normal?

Don't quite see how you came to the conclusion the your external mail
gateway is causing this. Are you guessing?

> 2) Is there anything that can be done to elimiate this (if caused by an
> external mail scanner perhaps not)

You need to do more research. Look at your logs. Look for some type of error
code. Something.

> 3)If we move to Secure Messaging where the email is encrypted and hence
> cannot be scanned by our mail filter, should I presume that the above
> error
> will not appear and that all will be OK (at least as much as it should
> be)?


Again, you *REALLY* don't know what the error is. You seem to be "shooting
in the dark". Review your logs and get a better handle on understanding the
problem *BEFORE* you try fixing the problem.

Send you emails log files....

> thanks
>
> -----
> pbw


Imhotep

Posted by Jeff B. on September 5, 2006, 2:01 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I interpret that he is suggesting his mail virus scanner is appending
his messages with a statement that the message has been "scanned by xyz
scanner", as I have seen by many virus scanners do. I have seen this a
lot with incoming mail, myself.

I would be interested to see an answer to this question myself.

If a mail scanner is appending messages with predefined text
(especially, signed or encrypted messages), will that change cause an
error at the recipients end as indicating the signed message has been
altered?

Tks - Jeff


imhotep wrote:
> pretzel wrote:
>
> > Dear All,
> >
> > We are testing out Digital Certificates as a prelude to Secure Messaging
> > with some of our Clients.
> >
> > We obtained individual certificates for ourselves (as there is not many of
> > us) but started our Client on a Business account with a CA.
> >
> > After setting up one of their users we notice that most times their email
> > is fine, but other times instead of the usual "rosette" there is a red
> > line and
> > the statement "There are problems with the signature. Click the signature
> > button for details."
> >
> > The message in the Security Properties is "Error: The message contents may
> > 15:05:47 16/08/2006."
> >
> > As we use an external mail filter (so all our mail is scanned in transit)
> > we believe that the scanning by our mail filter is causing the Digital
> > Certificate to detect a modification (or attempt) and hence the error.
> >
> > My questions are:
> >
> > 1) Is the above assumption correct, and this is normal?
>
> Don't quite see how you came to the conclusion the your external mail
> gateway is causing this. Are you guessing?
>
> > 2) Is there anything that can be done to elimiate this (if caused by an
> > external mail scanner perhaps not)
>
> You need to do more research. Look at your logs. Look for some type of error
> code. Something.
>
> > 3)If we move to Secure Messaging where the email is encrypted and hence
> > cannot be scanned by our mail filter, should I presume that the above
> > error
> > will not appear and that all will be OK (at least as much as it should
> > be)?
>
>
> Again, you *REALLY* don't know what the error is. You seem to be "shooting
> in the dark". Review your logs and get a better handle on understanding the
> problem *BEFORE* you try fixing the problem.
>
> Send you emails log files....
>
> > thanks
> >
> > -----
> > pbw
>
>
> Imhotep


Posted by imhotep on September 5, 2006, 6:40 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Jeff B. wrote:

> I interpret that he is suggesting his mail virus scanner is appending
> his messages with a statement that the message has been "scanned by xyz
> scanner", as I have seen by many virus scanners do. I have seen this a
> lot with incoming mail, myself.
>
> I would be interested to see an answer to this question myself.
>
> If a mail scanner is appending messages with predefined text
> (especially, signed or encrypted messages), will that change cause an
> error at the recipients end as indicating the signed message has been
> altered?

I have seen this also. For example SpamAssassin can have this affect (it
adds a field in the header "X-Spam-Score". I would say any alteration of
the email message would cause this error. Once you sign a message you can
not change a single bit (it will fail the check).

You hit upon a good point, I would guess that this is probably the
culprit...

--Imhotep

>
> Tks - Jeff
>
>
> imhotep wrote:
>> pretzel wrote:
>>
>> > Dear All,
>> >
>> > We are testing out Digital Certificates as a prelude to Secure
>> > Messaging with some of our Clients.
>> >
>> > We obtained individual certificates for ourselves (as there is not many
>> > of us) but started our Client on a Business account with a CA.
>> >
>> > After setting up one of their users we notice that most times their
>> > email is fine, but other times instead of the usual "rosette" there is
>> > a red line and
>> > the statement "There are problems with the signature. Click the
>> > signature button for details."
>> >
>> > The message in the Security Properties is "Error: The message contents
>> > RSA/SHA1 at 15:05:47 16/08/2006."
>> >
>> > As we use an external mail filter (so all our mail is scanned in
>> > transit) we believe that the scanning by our mail filter is causing the
>> > Digital Certificate to detect a modification (or attempt) and hence the
>> > error.
>> >
>> > My questions are:
>> >
>> > 1) Is the above assumption correct, and this is normal?
>>
>> Don't quite see how you came to the conclusion the your external mail
>> gateway is causing this. Are you guessing?
>>
>> > 2) Is there anything that can be done to elimiate this (if caused by an
>> > external mail scanner perhaps not)
>>
>> You need to do more research. Look at your logs. Look for some type of
>> error code. Something.
>>
>> > 3)If we move to Secure Messaging where the email is encrypted and hence
>> > cannot be scanned by our mail filter, should I presume that the above
>> > error
>> > will not appear and that all will be OK (at least as much as it should
>> > be)?
>>
>>
>> Again, you *REALLY* don't know what the error is. You seem to be
>> "shooting in the dark". Review your logs and get a better handle on
>> understanding the problem *BEFORE* you try fixing the problem.
>>
>> Send you emails log files....
>>
>> > thanks
>> >
>> > -----
>> > pbw
>>
>>
>> Imhotep


Posted by S. Pidgorny on September 6, 2006, 5:56 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> I have seen this also. For example SpamAssassin can have this affect (it
> adds a field in the header "X-Spam-Score". I would say any alteration of
> the email message would cause this error.

No. A scanner that adds a text to the (signed) message body is altering it
indeed; adding an extra header doesn't break S/MIME signature, as only the
message body integrity is protected (yes, you can add fake headers and spoof
the From: field).

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-



Similar ThreadsPosted
Invalid Digital Signature in Certificate July 7, 2006, 11:35 am
Digital Signature and Private Key September 3, 2006, 12:23 pm
Digital Signature and Private Key September 7, 2006, 11:28 am
Digital Signature and Private Key September 7, 2006, 11:33 am
Digital Signature and Private Key September 7, 2006, 9:45 pm
Digital Signature with SmartCard October 20, 2007, 4:16 am
How to remove the digital signature of a .exe file? November 17, 2007, 6:16 am
Windows Mobile 5 email encryption and digital signature October 9, 2007, 12:53 pm
digital certificate August 14, 2006, 8:04 am
digital certificate September 18, 2006, 7:07 am

The site map in XML format XML site map

Contact Us | Privacy Policy