Re: ?10.4.5 email problem: Where are my X509 CA certs stored?



In article <tY%Nf.13556$43.5023@xxxxxxxxxxxxxxx!nnrp1.uunet.ca>,
"void * clvrmnky()" <clvrmnky.invalid@xxxxxxxxxxxxxxxxxxx> wrote:

Fred Moore wrote:
I'm having problems sending email using my email account's SSL server.
When I attempt to send a message I get a warning like this concerning
the Certificate Authority (CA) certificate for the server (paraphrase):

Unable to verify SSL server wdyllc.com. No root certificate for this
server.

This started a couple of days after re-applying the 10.4.5 update from
my hard drive. (I had to do the reapply because using Software Update
caused other email problems which were fixed w/ the reapply.)

In the dialog box mentioned above, there is a button to 'View
Certificate'. Presumably, this is the CA cert the server is sending me
to validate itself by comparing to an X509Anchors CA cert stored
somewhere on my hard drive. When I click it, it shows the certificate
with a line added in red type,

'This certificate was signed by an unknown authority'

The email sysop sent me the Subject and Authority Key Identifiers for
the 'invalid' cert to make sure the cert being displayed was what the
server is sending. It was. When I checked Mail Help under certificate
error, it says to import a valid certificate into the X509Anchors
section of the Keychain Access utility. The sysop told me how to get a
new valid 'Class 2' cert from a company called Valicert. When I tried to
import it, Keychain Access tells me it already exists so I couldn't
import it. Looking down the list of X509Anchor certs, I finally found
three certs for Valicert (helpfully filed under H for
http://www.valicert.com), one each Class 1, Class 2, & Class 3 (whatever
that means). The details of each of these cert are different from the
cert the SSL email server is sending for validation.

Q1: Any idea why the email CA cert has been labeled as invalid? It was
working just a couple of days ago. All I've done in that time is run the
cron scripts and repair perms (didn't find much).

Q2: To fix this, I thought about deleting the Valicert Class 2 cert and
importing the new Class 2 one. However, before I delete anything I want
to make a backup. Where are these certs stored? Is it in
~/Library/Keychain/<my user name>? This is a single file, most of which
seems to be encoded so I can't tell if anything from Valicert is in
there.

X509 certs and CAs are stored in your keychains. I'd use the fancy
Keychain Access program to manipulate them. You can remove the invalid
CAs from there.

Thanks for the reply. Can I backup just one cert or do I have to backup
the entire file, ~/Library/Keychain/<my user name>? Doesn't seem to be
any way to break out the individual certs.

--Fred
.



Relevant Pages

  • Re: Web Certificate for IIS Server on SBS Domain
    ... Before your reply, I actually ran across rapidssl myself, and have ordered and installed the free 30-day certificate on my site. ... I explained what you'd told me about putting my existing configuration at risk by installing Cert Services, and he said he didn't know that. ... Again, if you're just needing a cert to install on your web server to provide SSL connectivity for remote users, go with an external third-party provider. ... When you add Certificate Services on an internal network, lots of internal communications will start using pieces provided by the Cert Server instead of the defaults from Server 2003, and when things blow up, they can blow up gloriously. ...
    (microsoft.public.windows.server.sbs)
  • Re: Activesync between Windows Mobile 5 and SBS2003 gives error
    ... If you don't find a cert here that matches the URL for OWA, you need to re-run the CEICW wizard on the SBS box and re-create the self signed cert. ... I exported the certificate straight from the server. ... Treo 700wx running Windows Mobile 5. ...
    (microsoft.public.windows.server.sbs)
  • Re: Terminal Services over a VPN
    ... Create a certificate request and submit it to godaddy in order to obtain a public cert. ... You can use the wizard in IIS Manager for this by creating a new website that matches the above name (on your TS server), right-click and choose properties, directory security tab, server certificate button. ... After the install you can stop or delete the website created above since you don't need it for anything. ...
    (microsoft.public.windows.terminal_services)
  • Re: SBS 2003 Premium and Cert Services
    ... that philosphy got blown out of the equation when SBS included Exchange OWA ... "Small Business Server" which is MS claim as to why the risk of exposing the ... the Certificate Server on another server, ... >> Cert, or you could edit the properties of your Certification Authority to ...
    (microsoft.public.windows.server.sbs)
  • Re: Web Certificate for IIS Server on SBS Domain
    ... and installed the free 30-day certificate on my site. ... instructions to install Certificate Services. ... If I can find a way to issue my own cert without risking my SBS setup, ... > Server instead of the defaults from Server 2003, and when things blow up, ...
    (microsoft.public.windows.server.sbs)