Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Client certificate authentication for IMAP ?

Hi,

I'd like to use my shiny new iPhone to read mail from my IMAP server at home but I've currently got the server configured to require a TLS client certificate.

Does anyone know if the mail client on the iPhone supports this authentication mechanism ? I've got the relevant certificate installed on the phone but it doesn't attempt to use it when I connect.

When the phone tries to get mail, I get an error "couriertls: accept: error:140890C7:SSL routines:SSL3 GET_CLIENTCERTIFICATE:peer did not return a certificate" in the server logs.

Just to be clear, this isn't a problem with the server TLS certificate, the phone collects mail perfectly if I just use password authentication but not if the server expects a known client certificate.

Any help would be much appreciated !

iPhone 3G

Posted on Jul 30, 2008 4:45 AM

Reply
1 reply

Aug 3, 2008 8:42 PM in response to algae105

Algae105,

I first tried connecting to my IMAP server (that requires client TLS certificate) with Mac OS Mail from a MacBook Pro Laptop. The attempt failed, but when I turned off client certificate requirement, I was able to connect (and use all normal mail features); I am also able to connect with Thunderbird (on MacBook Pro) to the same server with client certificates turned on. The reason I wanted to try this with Mail from a MacBook is that I think the same settings are used by the iPhone Mail.

My personal SSL certificate and the Certificate Authority certificate are installed in my MacBook Pro KeyChain in such a way that Safari is able to connect to an Apache server with also a client certificate requirement and using certificates issued by the same CA (self-signed). So, the Mac infrastructure is able to handle client certificates.

Finally, my hypotheses was that iPhone mail won't work with client certificate requirement - I tried and it failed with the same server side logs.

It would appear that Mac Mail and iPhone mail don't support client certificates. Bummer.

- Subhashis

Client certificate authentication for IMAP ?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.