Hi Benny,

Apparently MailMate uses SHA1 for S/MIME signatures:
Content-Type: multipart/signed; 
boundary="=_MailMate_9C9B7CEB-A063-4594-B53C-4CA40977FBE0_="; micalg=sha1;

SHA1 is not considered as secure anymore (https://en.wikipedia.org/wiki/SHA-1). 
I also noticed that Gmail doesn't verify SHA1-signed messages anymore: 'The 
signature uses an unsupported algorithm. The digital signature is not valid.'

I don't know if you use a macOS library for S/MIME? A test from iOS Mail used 
SHA256:
Content-Type: multipart/signed; 
boundary=Apple-Mail-2496A2C0-AD94-4608-8970-57B8A409367C; 
protocol="application/pkcs7-signature"; micalg=sha-256

Thanks,
Jan

-- 
Jan Münnich
j...@dotplex.com | +49 30 20236996-1

dotplex GmbH | www.dotplex.de
Reinhardtstr. 27c, 10117 Berlin, Germany
AG Charlottenburg: HRB 173749 B | USt-IdNr.: DE304968794
Geschäftsführer: Jan Münnich

Attachment: smime.p7s
Description: S/MIME digital signature

_______________________________________________
mailmate mailing list
mailmate@lists.freron.com
https://lists.freron.com/listinfo/mailmate

Reply via email to