S/MIME which certificate format

Marco Moock mm at dorfdsl.de
Thu Jun 20 11:20:14 CEST 2024


Hello!

Am 20.06.2024 um 11:07:00 Uhr schrieb Bernhard Reiter via Gnupg-users:

> gpgsm --debug-all --import zert.crt
> 
> gpgsm: can't get authorityInfoAccess: No value
> gpgsm: issuer certificate (#/CN=Sectigo RSA Client Authentication and
> Secure Email CA,O=Sectigo Limited,L=Salford,ST=Greater
> Manchester,C=GB) not found

IIRC the file I sent was only my cert, not the intermediate from the
CA. My cert itself creates the problem, the separate CA intermediate
cert can be imported properly.
I just separated that to track down the issue, which seems to be
related to the end user certificate itself.

> gpgsm: DBG: [no clock] keydb_insert_cert: enter (hd=0x006c3e38)
> Oops, ksba_cert_get_image failed: imagelen=238  hdr=4 len=1523 off=0
> 
> gpgsm: DBG: [no clock] keydb_insert_cert: leave (err=General error)
> gpgsm: error storing certificate: General error
> gpgsm: DBG: [no clock] keydb_release: enter (hd=0x006c3e38)
> gpgsm: DBG: [no clock] keydb_release: leave
> gpgsm: error storing certificate
> 
> gpgsm: no issuer found in certificate
> 
> gpgsm: basic certificate checks failed - not imported
> gpgsm: total number processed: 2
> 
> Marco, it makes sense to mail that certificate to Werner as well,
> he is fastest to see where the error messages comes from.

I've done that.
If anybody else would like to have it for testing purposes, please let
me know.

-- 
Gruß
Marco



More information about the Gnupg-users mailing list