Solved

Certificate Purposes

Posted on 2008-06-13
7
1,645 Views
Last Modified: 2008-07-05
Hello,

I have a personal email signing certificate from Thawte. The certificate is issued in my name. The certificate is installed in the system.

If I look at the certificate from Internet Explorer Options/Content/Certificates, or from MMC, I see two purposes of the certificate: "proves your identity to a remote computer" and "Protects email messages".
But if I send an email signed with this certificate, and then look at the certificate already in the email (sent or received - same thing), I see only purpose "Protects email messages". Same in Outlook and in Outlook Express.

Why I don't see "proves your identity" purpose in the certificate in email?
0
Comment
Question by:Vadim Rapp
  • 4
  • 3
7 Comments
 
LVL 18

Expert Comment

by:PowerIT
Comment Utility
The identity purpose is used for remote access to systems, not for signing email.

J.
0
 
LVL 40

Author Comment

by:Vadim Rapp
Comment Utility
http://technet2.microsoft.com/windowsserver/en/library/2746cc74-5401-443b-898f-5dc53b1cbcb01033.mspx?mfr=true says

-------------------
Certificates issued to persons
Once you have purchased a certificate and you use it to digitally sign an e-mail message, the message recipient can verify that the message has not been altered during transit and that the message came from you
-------------------

What purpose is used to "verify that the message came from you"?

Thawte website says:

http://www.thawte.com/secure-email/web-of-trust-wot/index.html?click=main-nav-products-wot
-------------------------------
The thawte Web of Trust (WOT) is a Certification system that allows your identity to be validated for use in your Personal Certificate.

Join for free and:

    * Sign your mail
.....
-------------------------------------

so, Thawte is giving inaccurate information, and in fact you can't sign your email with their certificate?
0
 
LVL 18

Expert Comment

by:PowerIT
Comment Utility
I think you read this wrong. That's the second purpose: 'Protect email message'. By signing it you also verify your identity, because you have the certificate with the private key.
Signing an email and validating your identity to a remote system are two diferent purposes with the same goal.

J.
0
Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

 
LVL 40

Author Comment

by:Vadim Rapp
Comment Utility
I understand that "protect email message" means that certificate ensures that the email has not been tampered with wince it left the sender.

But I'm interested in the 2nd purpose. On Thawte, you can get generic email certificate issued to "email user" that protects email message; but you can go further and acquire your personal certificate by showing your id to their notary - see "web of trust" above. Then you get your personal certificate issued to your real name. That, as I understand, is what is achieved by the purpose "proves your identity", and that's what Thawte means when they say "allows your identity to be validated for use in your Personal Certificate". What I don't understand is how sender's identity can be validated by the recipient if the certificate does not say that it can be used for this purpose.
0
 
LVL 40

Author Comment

by:Vadim Rapp
Comment Utility
Discussing this in security-related newsgroup gained much more results.

http://groups.google.com/group/microsoft.public.security/browse_thread/thread/43c941fb3bad6020/c4d142ac3162877f
0
 
LVL 18

Expert Comment

by:PowerIT
Comment Utility
I'm sorry, I forgot to continu on this question. Agree the closure.

J.
0
 
LVL 40

Accepted Solution

by:
Vadim Rapp earned 0 total points
Comment Utility
if you still have input, we can continue - even though the discussion in the newsgroup gained many responses, there was no final explanation of what actually happened. If you read my last post in there, with the examples about government official and about recording studio, you will see.
0

Featured Post

What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

Join & Write a Comment

Even if you have implemented a Mobile Device Management solution company wide, it is a good idea to make sure you are taking into account all of the major risks to your electronic protected health information (ePHI).
This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now