Exchange & Certificate Issue ( Digital ID name cannot be found by underlying security )

Posted on 2008-11-18
Last Modified: 2012-05-05
Our network consist of roughly 400 workstations and our mail system is Exchange 2003.  We use the Microsoft certificates which are deployed using AD for Digital ID's and Encryption.

Our issue is that several people receive encrypted or digital signed emails and when they try to open the email they receive the following message:

"Your digital ID name cannot be found by the underlying security system"

I've checked the users Certificates and they have the ones from AD and I'm stumped so any help would be greatly appreciated.
Question by:FSYR
    LVL 33

    Accepted Solution

    Check the certificate on the message against the one in that pc's keystore. it is possible that the user has been issued two certificates (on two separate machines), and the received email is the "wrong" one for that machine.
    LVL 1

    Author Comment


    Yes several of the users have been receiving different certs but about half using the same exact cert on all workstations.  I found one user that couldnt open my encrypted emails so I exported my certs and added them to her workstation and vice versa and she's still unable to open my emails.

    Any suggestions?

    LVL 33

    Assisted Solution

    by:Dave Howe
    Hmm. you should be able to open your own emails if your cert is on the workstation (as you usually encrypt mails to yourself as well as the recipient) but really you need to verify the cert that the mail was sent to.

    otherwise all I can think of is that there is an unsupported (on that workstation) cryptographic algo in that message.  you could try accessing using (for example) thunderbird and imap to see it that gives different results.

    Featured Post

    What Is Threat Intelligence?

    Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

    Join & Write a Comment

    Suggested Solutions

    Use these top 10 tips to master the art of email signature design. Create an email signature design that will easily wow recipients, promote your brand and highlight your professionalism.
    Check out this infographic on what you need to make a good email signature that will work perfectly for your organization.
    In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…
    The viewer will learn how to create a normally distributed random variable in Excel, use a normal distribution to simulate the return on an investment over a period of years, Create a Monte Carlo simulation using a normal random variable, and calcul…

    729 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    16 Experts available now in Live!

    Get 1:1 Help Now