More on the .Mac/iChat certificate

dotmac60pxAndreas Amann has compared the new .Mac/iChat certificate with a “normal” one, and posted the results in the comments to another post.

He found two interesting things:

  1. The .Mac/iChat key lacks the ?¢‚Ǩ?ìEmail Address?¢‚Ǩ¬ù field in the ?¢‚Ǩ?ìSubject Name?¢‚Ǩ¬ù section of the key and thus cannot be used for email signing in Apple Mail like a certificate from Thawte or some other CA.
  2. Towards the bottom of the certificate, in contrast to other certificates, Apple has a section called ‘Extended Key Usage”. Here Apple has nominated the second purpose of the certificate as “email protection”:
    dotmac_cert

    From this Andreas suggests that it “looks like Apple still has some plans in the pipeline for later:-)”

You can read more about the .Mac/iChat certificate on the “Apple Root Certificate Authority” section of the Apple web site.

Despite all this, at least one two readers have found that they can sign their emails with their .Mac/iChat certificate.

Does anyone have any further thoughts about, insights into or experience with this?

Similar Posts:

Tags: , , ,

3 Responses to “More on the .Mac/iChat certificate”

  1. Hawk Wings » Blog Archive » .Mac emails get more secure? says:

    [...] the .Mac/iChat certificate is interesting in a number of ways. See the comments and the entry on “More on the .Mac/iChatcertificate”. [...]

  2. Criss Hyde says:

    Signing and encrypting is working for all tested .Mac owning accounts on one machine, and now for some but not all of the same accouns on a second machine. It may help to keep all references to .Mac email and AIM accounts in the address book in lower case. /criss

  3. Hawk Wings » Blog Archive » Use your iChat certificate to sign Mail.app emails says:

    [...] Although I couldn’t get it to work, some people like David Dunham were able to use their new iChat digital certificates to sign .Mac emails. And it looked like Apple had future plans to use the certificate for email signatures. [...]

Leave a Reply