Certificate Assistant - certificate already exists

I seem to have backed myself into a corner with Certificate Assistant.

I created a new keychain, and a self-signed CA. Then I created a server cert for SSL for my https needs. I then noticed that the server cert wasn't a leaf of my CA, but a completely self signed cert. So I deleted it from my keychain.

When I recreate the cert, as a leaf of my CA, I get an error at the very end of the cert creation. The error states the process could not be completed "certificate already exists". It then has the two keys in my keychain but not the cert. I've looked high and low and have found no information on how to clear this up. I've stepped back, rm'ed the keychain, and recreated the CA, but when I again create the server cert, which has to have the hostname.domain.com, it will again present the same error.

Any ideas?

PowerBook G4 1.5Ghz, MiniMac 2Ghz, G4 tower 1ghz, G3 iBook, and others, Mac OS X (10.5.3), x.4 servers and x.5 servers.. not sure which i actually like thus far

Posted on Jun 23, 2008 6:05 PM

Reply
4 replies

Jun 25, 2008 2:29 PM in response to Sean Flynn

So having searched high and low for the old crt (which i had previously deleted from keychains, and from server certs) and not finding it. {searched using command line - 'security dump -d' <- [This dumps all contents of all used keychains] and a "defaults read com.apple.security" <- [This dumps out your keychain search list] } I felt reasonably certain that it wasn't in my keychains, nor in my certs, but possibly stuck in some .plist.

From there I followed some sage advice from an Apple developer I'd managed to finagle into helping me (quiet praise to accessible apple resources) and rather than letting Certificate Assistant iterate the leaf certificate, I iterated the serial number myself.

Suggestion from Apple:
"Just for kicks, try creating the leaf again, but say 'Override defaults' and give it a serial number of 2"

and this problem went away, and my cert generated fine.

w00t!

Aug 1, 2008 7:37 AM in response to Sean Flynn

Sean Flynn wrote:
I seem to have backed myself into a corner with Certificate Assistant.


Me too, only it's a slightly different corner:

I'm trying to create a new CA. I filled out all the fields on the first page, and upon clicking continue, am greeted with:

A Certificate Authority configuration file already exists with that name. Please pick a different name.


Any ideas?

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Certificate Assistant - certificate already exists

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.