Issue 103449 - Digital Signature shows "all" certificates
Summary: Digital Signature shows "all" certificates
Status: UNCONFIRMED
Alias: None
Product: Writer
Classification: Application
Component: ui (show other issues)
Version: OOo 3.1
Hardware: Unknown Windows XP
: P3 Trivial with 2 votes (vote)
Target Milestone: ---
Assignee: AOO issues mailing list
QA Contact:
URL:
Keywords: needhelp
Depends on:
Blocks:
 
Reported: 2009-07-10 00:18 UTC by pmcbride
Modified: 2014-03-13 16:56 UTC (History)
2 users (show)

See Also:
Issue Type: DEFECT
Latest Confirmation in: ---
Developer Difficulty: ---


Attachments

Note You need to log in before you can comment on or make changes to this issue.
Description pmcbride 2009-07-10 00:18:55 UTC
When attempting to Digital Sign a document on Windows, Writer - will display all
certificates in CAPI incorrectly.  Write should "filter" the certificate list
for certificates that have the following criteria:

a)  digital signature Key usage
b)  non-repudiation key usage.

Currently even "encryption only" certificates are display for signature
(incorrectly).

In addition, if the "Enhanced Key Usage(EKU)" is set to "All Usages" (OID =
2.5.29.37.0), the certificate is not display at all - or some other EKU, then
even "digital signature" key usage certificates are NOT displayed - which they
should be.

Please correct the filtering from CAPI.

Thanks.
Comment 1 eric.savary 2009-07-10 11:51:23 UTC
Reassigned to SBA
Comment 2 Edwin Sharp 2014-03-13 08:39:56 UTC
Please specify steps to reproduce bug.
Comment 3 pmcbride 2014-03-13 16:08:58 UTC
Steps to produce are:
1) have multiple certificates in CAPI
2) try to sign a document in writer
3) popup of what certs can be used - includes ALL CERTS.

A filter needs to be applied during the CAPI search to only allow certificates that are eligible for signing (proper Extended Key Usage).
Comment 4 pmcbride 2014-03-13 16:16:30 UTC
And proper Key Usage (KU).  Currently if a certificate does not have a "Digital Signature" KU - it is still listed as valid to sign with (which is a bug).  With Adobe Acrobat/Reader and Microsoft Office ....only certificates with proper KU are shown.
Comment 5 Edwin Sharp 2014-03-13 16:56:31 UTC
Thank you Paul