Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Always trust an SSL certificate in Mail

I have a mail account whose server uses an SSL certificate that is self-created... so the certificate is not verified through some SSL vender.

So every time I open Mail.app, it prompts me with a message:
"Mail can't verify the identity of mail.domain.org"
Continue?

And there is a checkbox under the Show Certificate option which states:
"Always trust <certificate> when connecting to mail.domain.org"

Yet checking this box and subsequently typing my password never makes any difference.
It still prompts me each and every time I open mail or switch inet connexions.

Any suggestions?

Message was edited by: J R3

MBP

Posted on Aug 15, 2008 8:21 PM

Reply
9 replies

Aug 16, 2008 3:29 AM in response to J R3

J R3 wrote:
I have a mail account whose server uses an SSL certificate that is self-created... so the certificate is not verified through some SSL vender.

If a certificate is not accepted, it may have expired or it may be invalid for the use to which it is being applied. The most common reason a certificate isn’t accepted is because the certificate authority’s root certificate isn’t trusted by your computer. To trust a certificate authority, it must be added to a keychain, and the certificate trust settings must be set.
And there is a checkbox under the Show Certificate option which states:
"Always trust <certificate> when connecting to mail.domain.org"

Yet checking this box and subsequently typing my password never makes any difference.

Because you didn't tell the Certificate what to use it for. There are options that you can set beneath that one. Select Secure Sockets Layer (SSL) to start with and try to receive some E-Mail.
It still prompts me each and every time I open mail or switch inet connexions.

Contact your E-Mail Provider if your still having problems.

Also you need to setup the Keychain Preferences to validate Certificates using the Internet.

Good Luck. 🙂

Later ...
!http://homepage.mac.com/buzzlightgear/Buzz.tiff!
Buzz

Oct 14, 2008 4:57 PM in response to J R3

Looks like a bug. After telling Mail to trust the certificate for all my accounts, and being asked to sign my user password each time (often twice), the certificate still appears to be not trusted in the Keychain Access program. I set it to 'Always Trust' in Keychain Access, but still Mail prompts me about it for every account every time I relaunch Mail.

Oct 18, 2008 10:06 PM in response to rsgl

I think I found a solution... It's working for me still after logging out and restarting.

First, I deleted ALL of the problematic certificates from Keychain Access and started fresh. I then re-added the root certificate in Keychain Access (before opening Mail) and set it to Always Trust. Keychain Access asked for my password as usual. Next, I launched Mail and selected Always Trust from the dropdown triangle within the dialog box that Mail presented, but did NOT check the "Always Trust" checkbox on the top of the dialog. I did the same thing for the dialog that popped up when I tried to send mail from the account.

One strange thing though is that this prompted me to re-enter my email password and created a second password entry in Keychain Access.

Hope this works for someone else too...

Dec 19, 2008 9:57 AM in response to rsgl

I'm having the same issue with Mail in Mac OS X 10.5.5. No matter how many times I tell Mail to "Always Trust" the certificate, or double-check my settings in Keychain Access, I'm always prompted to manually select whether or not to trust the certificate when opening Mail. I tried member rsgl's workaround, but it didn't work on my machine. Super annoying, especially since I'm hosting multiple domains on this server -- I have to "Always Trust" the same certificate five times in a row!

Hope there's a bug fix in the works for 10.5.6.

Always trust an SSL certificate in Mail

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.