Persistent Trust Certificate Requests

Since updating to Mojave, I've been getting a request to verify that I trust my wifi certificate every time I open my computer. I double check every time that the "always trust this certificate" box is checked, but the prompt still comes up next time I log in. I've tried forgetting the network and reconnecting, but it didn't fix the problem. Is there a way to fix this?

MacBook Air 13", macOS 10.14

Posted on Feb 27, 2019 8:41 PM

Reply
Question marked as Top-ranking reply

Posted on Feb 28, 2019 4:02 AM

A typical home WiFi setup would not use certificate based security, this implies you are referring to an office based WiFi network.


If so then the obvious answer is to use a proper trusted certificate in the first place rather than a self-signed certificate. Typically these have to be bought but it is possible in most cases to use the free LetsEncrypt certificate service. These last 90 days before needing to be renewed so either this is more work or you need a script to automate renewing them. Your IT department should look in to this.


Alternatively if you must use self-signed certificates then what you are supposed to do is install and trust the public key aka certificate of your organisations self-signed root Certificate Authority. If you do this then any certificates signed by that self-signed rootCA e.g. your WiFi certificate will then be automatically trusted since you have trusted the rootCA itself.


The public key aka certificate of the self-signed rootCA needs to be added to your computers System keychain not your login or local items keychain.


Remember the rootCA is different to a server or WiFi or VPN certificate. Again your IT team should be able to help you.

Similar questions

1 reply
Question marked as Top-ranking reply

Feb 28, 2019 4:02 AM in response to riversound10

A typical home WiFi setup would not use certificate based security, this implies you are referring to an office based WiFi network.


If so then the obvious answer is to use a proper trusted certificate in the first place rather than a self-signed certificate. Typically these have to be bought but it is possible in most cases to use the free LetsEncrypt certificate service. These last 90 days before needing to be renewed so either this is more work or you need a script to automate renewing them. Your IT department should look in to this.


Alternatively if you must use self-signed certificates then what you are supposed to do is install and trust the public key aka certificate of your organisations self-signed root Certificate Authority. If you do this then any certificates signed by that self-signed rootCA e.g. your WiFi certificate will then be automatically trusted since you have trusted the rootCA itself.


The public key aka certificate of the self-signed rootCA needs to be added to your computers System keychain not your login or local items keychain.


Remember the rootCA is different to a server or WiFi or VPN certificate. Again your IT team should be able to help you.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Persistent Trust Certificate Requests

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.