Invalid Certificate on every secured website

Hi,


I've just updated to 10.7.4 with Safari 5.1.7 and after the update I'm always getting an Invalid Certificate for secured website.


www.paypal.com

every banking sites

etc


The content is not entirely loaded even if I click "continue".


I don't know if it related but I can't install any Extensions in Safari. I had ClickToFlash and 1Password and neither can be reinstalled after the update. I got a message telling me that the extension cannot be installed.


Thank you

MacBook Air, Mac OS X (10.7.4)

Posted on May 10, 2012 12:56 PM

Reply
147 replies

May 15, 2012 12:05 PM in response to sébastienfromquebec

This problem seems to be a little more insedious than just ocspd not being able to validate from behind a proxy. I've seen such problems even when I'm not behind the proxy.


Even worse it broke certificate based logins to our Cisco VPN since my certificate was issued by an intermediary CA which was suddenly listed as invalid. Even when I tried forcing every certificate in the chain as trusted (in both the login and System keychains), turned off the sane options of using OCSP and CRL in Keychain Access.app it still wouldn't work.


Then I relaized that the daemons used to create the VPN run as the root user.


I had to enable and login to the root user. From there set in Keychain Access.app all of the needed certificates as trusted in the System keychain for the root account.


Now it all seems to function (mostly). There is still the problem of some certificates being marked as having an invalid key length as mentioned by another poster in the thread.


I hope Apple gets this sorted out ASAP.


I hope even more that I'll remember to bring my system back into a sane state after the fix.

May 16, 2012 4:02 AM in response to sébastienfromquebec

So, I went into my local Apple Store yesterday with this thread and my laptop to see if they had any ideas. The 'genius' hadn't encountered this problem with anyone else and because we couldn't recreate it at the Store (because no proxy), he offered to install a bug tracker that would log all errors and then I could take the laptop back in and he could escalate it to engineering. However, for a variety of other reasons, I do not have the patience or time to go through this and so asked him to roll it back to 10.7.3 and I won't update for a while.


So, I'm afraid no solution, however, if someone has the time and patience, it does sound like there will be the option to get it looked at in detail.


Sorry I couldn't be of more help guys.

May 16, 2012 5:28 AM in response to sébastienfromquebec

It is just INCREDIBLE ! Since I update from 10.7.3 to 10.7.4 I m running through major network problems including network configuration which is not saved correctly (e.g., credentials for proxy go back to blank once I close the window to set them). It keeps asking me for certificates all the times, smtp server connection is completely lost (in Mail application) all my extensions in Safari have been uninstalled without my approval.


Anyway ! I bought a Mac because I know that I can rely on it all the time. But having such updates with those kind of bugs afterward I would rather stay on linux.


So please Apple, do something and quick.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Invalid Certificate on every secured website

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.