SSL problem, affecting multiple parts of OS X

I'm having a problem which appears to be related to OSX's built-in processing SSL certificates. The following issues started happening, all at the same time:

- iTunes cannot connect to the music store at all, I get "error 11333".

- Mail.app cannot connect to my mac.com mailbox, it says 'Mail was unable to verify the identity of this server, which has a certificate issued to "mail.mac.com". The error was: The certificate for the server is invalid. Even if I tell it to "Go Online", it will not connect to the mailbox.

- The "dotMac" System Preferences widget cannot connect to the dotMac servers to show my sync settings, iDisk usage, or the list of machines which are connected to the docMac account.

- IF I USE SAFARI, when I try to log into any of the "mac.com" web pages I get an error message saying 'The certificate for this website is invalid. You might be connecting to a website that is pretending to be "www.mac.com" which could put your confidential information at risk." If I click "Show Certificate", it says that Verisign's self-signed certificate is valid (even though I can't find that key in any of my keychains, including "X509Anchors") but the "www.mac.com" certificate says "This certificate has an invalid issuer". IF I USE FIREFOX, I am able to log into the site without any problems.

The common thread to all of these issues is that they all use the SSL routines built into OS X. Firefox uses its own SSL implementation, and the command line "openssl" tool shows the "www.mac.com.pem" file to be a valid certificate (see http://www.jms1.net/www.mac.com.pem.txt to do your own checking if needed.)

iMac G5, Mac OS X (10.4.10)

Posted on Sep 26, 2007 7:25 PM

Reply
8 replies

Oct 17, 2007 1:21 PM in response to John Simpson

i too experience this. i have found that many sites are affected, but all sites use the following chain of trust:

"Class 3 Public Primary Certification Authority" (VeriSign, root CA)
|
-> "Thawte SGC CA" (Thawte Consulting, intermediate CA)
|
-> SSL cert that fails inspection (google, linkedin, etc.)

i have removed my "Class 3 Publ..." as well as the Thawte and the specific site certs.

i have had this problem for about 10 months, putting my start date at January 2007.
anyone else?
any solutions?

-jared

Oct 19, 2007 10:23 PM in response to Jared Eldredge

hello,

i have had a similar problem with both itunes and the abc.com full episode player, the latter which cited the "class 3 public primary certification authority" upon installing...

...which i don't have!

how do i get this certificate? i don't currently have access to my os x installation CD. i foolishly deleted my entire X509anchors keychain several months ago, and i suspect i'm dealing with reverberations.

Oct 22, 2007 8:33 AM in response to John Simpson

I broke down and totally re-installed OSX from scratch... no change.

It's really strange, because sometimes if I reboot, it will work for a few days and then stop working again.

And the part that really ***** is that it makes Mail.app totally un-usable. It seems to be convinced that the certificate for my spamcop.net email address is not valid, which is preventing me from being able to check that account using Mail.app... and since Thunderbird has no problems with that account OR WITH ANY OTHERS, for the time being I'm stuck using Thunderbird (whose handling of PGP I don't really like.)

The only thing I can figure is that the people at Apple are so hung up on the new OS that they've forgotten about their customers who don't already have advance copies of it... HELLO, IS ANYBODY AT APPLE EVEN READING THIS?!?!?!?

Oct 25, 2007 2:04 PM in response to Frank Miller2

hrmmm... it's not affecting my iBook (also 10.4.10 with current updates) so who knows. maybe when i upgrade the iMac to 10.5 tomorrow, that will solve it on the iMac. if not, i'll at least get 90 days' phone support with the 10.5 box and i'll be able to call them without paying extra for the privilege of having them look at the problem.

is there a forum somewhere that apple employees DO monitor?

Dec 2, 2007 2:24 PM in response to John Simpson

I had a similar problem with a CA certificate I generated using OpenSSL on Fedora 5. For some reason OpenSSL is configured to set the X509v3 Basic Constraint "CA:FALSE" even on CA certificates. I think this was what caused the "certificate has an invalid issuer" message in my case. I made a copy of openssl.cnf and modified the configuration to set "CA:TRUE" and used that to generate a new CA certificate.

Message was edited by: John Dalbec

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

SSL problem, affecting multiple parts of OS X

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.