Version: unspecified (using Devel) OS: Windows CE A key selected for cryptography in the identity manager can be rejected for a variety of reasons. For OpenPGP it could be lack of owner trust. For S/MIME, it can be lack of trust of the root CA key (=> allow-mark-trusted), or a failure to check CRLs (=> disable-crl-checks). But the dialog does not say why the key is rejected. The OK button just stays unselectable (greyed out), frustrating the user because of the lack of any indication why it can not be used to confirm key selection. Reproducible: Always