You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Client certificate authentication for IMAP ?

Hi,

I'd like to use my shiny new iPhone to read mail from my IMAP server at home but I've currently got the server configured to require a TLS client certificate.

Does anyone know if the mail client on the iPhone supports this authentication mechanism ? I've got the relevant certificate installed on the phone but it doesn't attempt to use it when I connect.

When the phone tries to get mail, I get an error "couriertls: accept: error:140890C7:SSL routines:SSL3 GET_CLIENTCERTIFICATE:peer did not return a certificate" in the server logs.

Just to be clear, this isn't a problem with the server TLS certificate, the phone collects mail perfectly if I just use password authentication but not if the server expects a known client certificate.

Any help would be much appreciated !

iPhone 3G

Posted on Jul 30, 2008 4:45 AM

Reply
1 reply

Aug 3, 2008 8:42 PM in response to algae105

Algae105,

I first tried connecting to my IMAP server (that requires client TLS certificate) with Mac OS Mail from a MacBook Pro Laptop. The attempt failed, but when I turned off client certificate requirement, I was able to connect (and use all normal mail features); I am also able to connect with Thunderbird (on MacBook Pro) to the same server with client certificates turned on. The reason I wanted to try this with Mail from a MacBook is that I think the same settings are used by the iPhone Mail.

My personal SSL certificate and the Certificate Authority certificate are installed in my MacBook Pro KeyChain in such a way that Safari is able to connect to an Apache server with also a client certificate requirement and using certificates issued by the same CA (self-signed). So, the Mac infrastructure is able to handle client certificates.

Finally, my hypotheses was that iPhone mail won't work with client certificate requirement - I tried and it failed with the same server side logs.

It would appear that Mac Mail and iPhone mail don't support client certificates. Bummer.

- Subhashis

Client certificate authentication for IMAP ?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.