<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
	<channel>
		<title>www.ritlabs.com [Topic: TheBat Voyager and Sectigo AddTrust External CA Root certificate issue]</title>
		<link>http://www.ritlabs.com</link>
		<description>New posts in TheBat Voyager and Sectigo AddTrust External CA Root certificate issue of  forum at www.ritlabs.com [www.ritlabs.com]</description>
		<language>en</language>
		<docs>http://backend.userland.com/rss2</docs>
		<lastBuildDateTag>Tue, 23 Jun 2020 00:03:02 +0300</lastBuildDateTag>		<item>
			<title>TheBat Voyager and Sectigo AddTrust External CA Root certificate issue</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic14833/message49999/">TheBat Voyager and Sectigo AddTrust External CA Root certificate issue</a></b> <i>expired certificate issue</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			Thank You very much. S/MIME and TLS option worked. But can i somehow fill the inner base of TB with these certificates from crt files?<br />When i try to do import crt in address book TB displays that there is nothing to import. I can manually add new entries and attach certificates to it, but even if they are in address book, I still can&#39;t fetch mails - error is the same.<br /><br />EDIT:<br />Don&#39;t know if i made it correctly but for<br />Główny: &quot;SE&quot;, &quot;AddTrust AB&quot;, &quot;AddTrust External TTP Network&quot;, &quot;AddTrust External CA Root&quot; - i have attached updated AAA Sectiago certificate (without removing the old one), and for Wystawca: &quot;US&quot;, &quot;New Jersey&quot;, &quot;Jersey City&quot;, &quot;The USERTRUST Network&quot;, &quot;USERTrust RSA Certification Authority&quot; i have attached USERTrustRSAAAACA. Now TB is able to fetch mails. <br />
			<i>23 June 2020 00:03:02, <a href="http://www.ritlabs.com/en/forums/">Krzysztof Jachowicz</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic14833/message49999/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic14833/message49999/</guid>
			<pubDate>Tue, 23 Jun 2020 00:03:02 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>TheBat Voyager and Sectigo AddTrust External CA Root certificate issue</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic14833/message49997/">TheBat Voyager and Sectigo AddTrust External CA Root certificate issue</a></b> <i>expired certificate issue</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			<br />====quote====<br />I have installed new set of Sectigo AAA cross certificates in Windows 7:<br />=============<br /><br />The Bat / Voyager, by default, use their own certificate store. The certificates are stored in the Address Book, where you can import certificates too (in the address book, use <B>View | Certificate Address Books</B> to see them).<br /><br />Certificates stored in Windows itself will only be used if you go to <B>Options | S/MIME and TLS</B> and choose to use the Microsoft CryptoAPI instead of The Bat's own certificate store.<br /><br /><br />====quote====<br />TheBat is still trying to go by old "AddTrust External CA Root" and "USERTrust RSA Certification Authority" even if i have removed them from system.<br />Is TheBat unable to take alternative chain path? Is it TheBat fault, or mail provider fault for pointing such chain to verify?<br />=============<br /><br />The certificate itself dictates against which higher-level certificate it must be verified. If that parent certificate is missing, or has expired, nothing can be done. <br />
			<i>22 June 2020 20:11:23, <a href="http://www.ritlabs.com/en/forums/">Daniel van Rooijen</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic14833/message49997/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic14833/message49997/</guid>
			<pubDate>Mon, 22 Jun 2020 20:11:23 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>TheBat Voyager and Sectigo AddTrust External CA Root certificate issue</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic14833/message49994/">TheBat Voyager and Sectigo AddTrust External CA Root certificate issue</a></b> <i>expired certificate issue</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			Hello. I can&#39;t check mails by TLS from one of providers due to expiration of Sectigo AddTrust External CA Root.<br />I am user of Voyager version 6.8.4.1 (i know it is quite old version but it worked till now without much issues).<br />The provider certificate is valid till march 2021 but when i try to check for new mails or send mails i get (sorry for local names):<br /><br />&gt;2020-06-22, 17:14:16: FETCH - Wystawca: &quot;GB&quot;, &quot;Greater Manchester&quot;, &quot;Salford&quot;, &quot;Sectigo Limited&quot;, &quot;Sectigo RSA Domain Validation Secure Server CA&quot;. Ważny od 2018-11-02 do 2030-12-31 23:59:59.<br />&gt;2020-06-22, 17:14:16: FETCH - Wystawca: &quot;US&quot;, &quot;New Jersey&quot;, &quot;Jersey City&quot;, &quot;The USERTRUST Network&quot;, &quot;USERTrust RSA Certification Authority&quot;. Ważny od 2000-05-30 10:48:38 do 2020-05-30 10:48:38.<br />&gt;2020-06-22, 17:14:16: FETCH - Główny: &quot;SE&quot;, &quot;AddTrust AB&quot;, &quot;AddTrust External TTP Network&quot;, &quot;AddTrust External CA Root&quot; Ważny od 2000-05-30 10:48:38 do 2020-05-30 10:48:38. Ten certyfikat wygasł!<br />!2020-06-22, 17:14:16: FETCH - Błąd fazy potwierdzania TLS: Nieważny certyfikat serwera (Ten certyfikat wygasł).<br /><br />Steps i took:<br />I have installed new set of Sectigo AAA cross certificates in Windows 7:<br />AAACertificateServices.crt, SSLcomDVCA_2.crt, USERTrustRSAAAACA.crt, and removed expired AddTrust External CA Root and USERTrust RSA Certification Authority.<br />It didn&#39;t change the outcome.<br />Then i removed RootCA.EBD and IntermCA.EBD as some forum user suggested and the outcome is now:<br /><br />&gt;2020-06-22, 17:22:18: FETCH - Wystawca: &quot;GB&quot;, &quot;Greater Manchester&quot;, &quot;Salford&quot;, &quot;Sectigo Limited&quot;, &quot;Sectigo RSA Domain Validation Secure Server CA&quot;. Ważny od 2018-11-02 do 2030-12-31 23:59:59.<br />&gt;2020-06-22, 17:22:18: FETCH - Wystawca: &quot;US&quot;, &quot;New Jersey&quot;, &quot;Jersey City&quot;, &quot;The USERTRUST Network&quot;, &quot;USERTrust RSA Certification Authority&quot;. Ważny od 2000-05-30 10:48:38 do 2020-05-30 10:48:38. Ten certyfikat wygasł!<br />&gt;2020-06-22, 17:22:18: FETCH - Brak wydawcy: &quot;SE&quot;, &quot;AddTrust AB&quot;, &quot;AddTrust External TTP Network&quot;, &quot;AddTrust External CA Root&quot;.<br />!2020-06-22, 17:22:18: FETCH - Błąd fazy potwierdzania TLS: Nieważny certyfikat serwera (Ten certyfikat wygasł).<br /><br />TheBat is still trying to go by old &quot;AddTrust External CA Root&quot; and &quot;USERTrust RSA Certification Authority&quot; even if i have removed them from system.<br />Is TheBat unable to take alternative chain path? Is it TheBat fault, or mail provider fault for pointing such chain to verify? <br />
			<i>22 June 2020 18:42:17, <a href="http://www.ritlabs.com/en/forums/">Krzysztof Jachowicz</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic14833/message49994/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic14833/message49994/</guid>
			<pubDate>Mon, 22 Jun 2020 18:42:17 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
	</channel>
</rss>
