{"id":1516,"date":"2004-09-11T04:11:00","date_gmt":"2004-09-11T04:11:00","guid":{"rendered":"http:\/\/userpage.fu-berlin.de\/~frers\/cgi-bin\/blosxom.cgi\/edv\/040910-certificates.html"},"modified":"2010-01-23T02:57:10","modified_gmt":"2010-01-23T01:57:10","slug":"some-things-arent-easy-even-when-they-should-be","status":"publish","type":"post","link":"https:\/\/userpage.fu-berlin.de\/frers\/blog\/?p=1516","title":{"rendered":"Some things aren&#8217;t easy even when they should be."},"content":{"rendered":"<p>Motivated by an article in the most recent issue of <a href=\"http:\/\/www.heise.de\/ct\/\" title=\"excellent German computer magazine\">c&#8217;t<\/a> called <em>Absender-Authentifizierung sch\u00fctzt vor Spam<\/em> I decided to give it a shot and install certificates into Mail.app, the default E-Mail programm for OS X. This was not exactly a trivial issue, but the goal was worth it: being able to digitally sign my e-mail and also use encryption. (I am an avid user of <a href=\"http:\/\/www.pgpi.org\/\" title=\"Pretty Good Privacy - international site\">PGP<\/a>\/<a href=\"http:\/\/www.gnupg.org\/\" title=\"GnuPG project homepage\">GPG<\/a> encryption technology since the late nineties, but I also wanted to check out this alternative, since, sadly, very few people actually use PGP.) First I wanted to use the certificate provided by the German mail provider <a href=\"http:\/\/trust.web.de\/\" title=\"root certificates for web.de\">web.de<\/a>. Since that did initially not work as intended, I checked an enormously helpful site called <a href=\"http:\/\/www.macosxhints.com\/\" title=\"tips and tricks for Mac OS X\">macosxhints<\/a>. There I found quite a few tips that helped me tackle certification, signing, and encrypting issues in Mac OS X. Since I had problems with the web.de certificates I decided to follow the advices on that macosxhints and got myself free personal e-mail certificates from <a href=\"http:\/\/www.thawte.com\/email\/index.html\" title=\"provider of free personal e-mail certificates\">thawte<\/a>. After a few experiments I finally got the certificates installed: I had to use either Firefox or Mozilla to install the certificates into these browsers and then was able to ex- and import these certificates into the Mac OS X keychain, which is used by Mail, Safari and other Mac OS X native apps. After importing these certificates everything went as expected. For good measure I later installed the root certificates of web.de , the <abbr title=\"Deutsches ForschungsNetz\">DFN<\/abbr>, and several relevant German universities.<\/p>\n<p>Regarding the problems I had with the web.de certificate: I did not install the web.de root certificates when I first tried to use their certificate for signing purposes, which might be the reason why it did not work. Problem is, I was looking for a link to the root certificates in my personal options pages at web.de but did not find anything. They weren&#8217;t even mentioned, even though I explicitly looked for them. One more thing regarding web.de: the c&#8217;t article gives a link to the <a href=\"http:\/\/trust.web.de\/\">web.de TrustCenter<\/a>, saying that under this link free certificates can be acquired. This is not true anymore. One has to have a web.de account to get a certificate. (The account is free though &#8211; but I think the author thought registration for an account wasn&#8217;t necessary, otherwise it would probably have been mentioned.)<\/p>\n<p>Fingerprints for all of my keys\/certificates can be found at the bottom of the sidebar on this page.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Motivated by an article in the most recent issue of c&#8217;t called Absender-Authentifizierung sch\u00fctzt vor Spam I decided to give it a shot and install certificates into Mail.app, the default E-Mail programm for OS X. This was not exactly a trivial issue, but the goal was worth it: being able to digitally sign my e-mail [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[18],"tags":[180,247,23,44],"class_list":["post-1516","post","type-post","status-publish","format-standard","hentry","category-tech","tag-e-mail","tag-encryption","tag-privacy","tag-spam"],"_links":{"self":[{"href":"https:\/\/userpage.fu-berlin.de\/frers\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1516","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/userpage.fu-berlin.de\/frers\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/userpage.fu-berlin.de\/frers\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/userpage.fu-berlin.de\/frers\/blog\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/userpage.fu-berlin.de\/frers\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1516"}],"version-history":[{"count":3,"href":"https:\/\/userpage.fu-berlin.de\/frers\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1516\/revisions"}],"predecessor-version":[{"id":2375,"href":"https:\/\/userpage.fu-berlin.de\/frers\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1516\/revisions\/2375"}],"wp:attachment":[{"href":"https:\/\/userpage.fu-berlin.de\/frers\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1516"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/userpage.fu-berlin.de\/frers\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1516"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/userpage.fu-berlin.de\/frers\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1516"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}