Apple Event: May 7th at 7 am PT

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

iCloud login problem on Sierra, High Sierra? Try this.

My Notes weren't updating on my Macbook Air with High Sierra, so I logged out of iCloud to see if logging back in would fix it, only to find out that I couldn't log back in. Got all of the "Unknown" and "Not at this time, try later errors".


Short story, did all the things, but no success. iCloud is fine, other machines are fine, just not this one. Finally tried logging into iCloud on that machine with Safari and got a "Can't connect to iCloud Servers" error. Ruled out network problems and Firefox connected to iCloud just fine.


Turns out it was a certificate problem preventing this machine from connecting to iCloud. Following the advice in this thread fixed the problem and now iCloud is working correctly again. Download the Apple Intermediate Certificates as mentioned in the first post.


How I solved the Safari 13 and High Sierr… - Apple Community




Posted on Apr 9, 2022 1:11 PM

Reply
85 replies

Apr 20, 2022 11:02 AM in response to patrice289

I had this problem too. 3 days of complete stress as every attempt I made to solve it depleted my photos library (20,000+ photos disappeared). Thanks to this solution I luckily restored my photos and iCloud Drive. Very worried about the May expiration dates as I have also pasted this certificate into my iMac running Catalina which was also locked out of iCloud. Also despite restoring the operating system on my Catalina iMac and Sierra MacBook one of my most important apps no longer works (Tascam us-16x08 Panel Settings app) just will not load at all so not sure if it’s a connected issue or not but too much of a coincidence. My iMac ended up full from iCloud storage with only 17gb free, simply locked up at almost every key stroke. Pretty sure this is apples underhand way of forcing OS and hardware upgrades, I had no certificate expiration warnings at all, very unhappy with apple (paying too whack for 2tb iCloud storage) with lousy customer support.

May 20, 2022 10:23 AM in response to pedrocaiano

Thank you pedrocaiano for adding that solution. I had not expired yet, and hoped I wouldn't, but was nervous when you posted you did. I just looked at my keychain, and I no longer have the Apple IST CA 2-G1 in listed (if I look for it on my computer, it says it exists, but has expired), but I have other certificates that don't expire for at least another year, so I think I had already selected to always trust when I installed. I hope I am in good shape for now.

May 21, 2022 1:20 PM in response to Jasyan7

Just got off the phone with apple Canada support 2nd level engineering. the agent checked his Mac running Monterey and found the same expired certificate.


Summary:

As of May 16, 2022 older versions of OSX can not use iCloud notes… (some, sort of, maybe).


Reason given is that newer OSX have the ability to request the latest certificate and the older don’t.


The issue is not the certificate itself but that the Apple Server will not no longer issue certificates to older OSX (implemented silently May 16).


There will be no update to the downloadable version of AppleISTCA2G1.cer for security reasons.


Apple service supports the latest three versions of OSX that any particular Mac can run.


My MacBook Pro 15” from 2012 is running OSX10.13.3 so it might be within the latest support bracket if I update to OSX10.13.6. The agent could not confirm that updating would fix my problem.


Older versions of OSX are not updated with the latest in Apple’s security features so they can no longer run with iCloud notes unless it is the highest OSX version for that particular Mac… (some, sort of, maybe).


Given all the some, sort of, maybes from Apple I’m gonna wait till Tuesday to see if Apple fixes this anyway.

May 21, 2022 1:43 PM in response to patrice289

That's sorta BS of them. I have some Macs that I will not update because I will lose software that I use regularly and can't replace. I have other Macs that I can update. There is no reason to cut off the older computers functionality. That said, I don't use iCloud for almost anything (for good reason). I just push messages from my phone to my other devices so I don't have to carry my phone around everywhere, and it's easier to type on a computer. On some devices, that, and Find My Mac, are the ONLY reasons I need to keep them logged into my account. This certificate allows me to keep doing those two things.

May 21, 2022 1:49 PM in response to dgd

My iMac Runs on 10.13.6 so updating to the last High Sierra version will not solve the problem.

Glad I found that "other" certificate to extend iCloud use on my iMac until 2025, although I know it's obsolete it still does everything I need it to do. It's not only iCloud Sync and Notes that uses this certificate, iMessages, FaceTime, My Photo Stream, iCal, Contacts etc... all those things are linked to this certificate and stop syncing across devices.

It's unfortunate that we are left to our own devices to sort this out...

May 21, 2022 7:28 PM in response to pedrocaiano

Tried appleistca2g1_bc.cer and it did not work.

I updated one of my machines from OSX10.13.3 to OSX10.13.6. still not working so i'm signing it out of iCloud then back on and see if that works. Is taking a long time... still waiting a few hours for it to save a copy of everything to my Mac before signing out. I'll let it run overnight.


May 22, 2022 8:26 AM in response to pedrocaiano

Solution: Additionally You had to Trust the Root Certificate of Geo Trust which is used in Apple IST CA 2 - G1


The signing Root CA "GeoTrust Global CA" in "System Roots" expired on May 21, 2022.

So set both the original "Apple IST CA 2 - G1" and "GeoTrust Global CA" to "always trust"


This works for me in High Sierra !!!

Notes, Safari, iCloud drive,... now syncing again (reboot not necessary)


puh....

May 23, 2022 10:40 AM in response to OldSchoolAdmin

Finally found what worked for me: (OSX10.13.3)


In Keychain Access:


Set these to “always trust”:

-original "Apple IST CA 2 - G1”

(AppleISTCA2G1.cer)

expired 20220520

Showing in the Keychain column “Login”


-second "Apple IST CA 2 - G1”

(appleistca2g1_bc.cer)

expires 20250507

Showing in the Keychain column “Login”


-“GeoTrust Global CA"

expired 20220520 (when I did this to the one I found a second identical appeared)

Showing in the Keychain column “System” and/or “System Roots”


I set them last night and they still work this morning.

iCloud login problem on Sierra, High Sierra? Try this.

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.