Invalid Certificate on every secured website

Hi,


I've just updated to 10.7.4 with Safari 5.1.7 and after the update I'm always getting an Invalid Certificate for secured website.


www.paypal.com

every banking sites

etc


The content is not entirely loaded even if I click "continue".


I don't know if it related but I can't install any Extensions in Safari. I had ClickToFlash and 1Password and neither can be reinstalled after the update. I got a message telling me that the extension cannot be installed.


Thank you

MacBook Air, Mac OS X (10.7.4)

Posted on May 10, 2012 12:56 PM

Reply
147 replies

Jul 13, 2012 5:35 AM in response to sébastienfromquebec

We had the same problem here with our own mail server. Thanks to the helpful support from Stalker (Communigate Pro), it turned out that the problem was that the certificate used a key length of only 512 bit. I created a new certificate with 2048 bits, and the problem was solved!


This may help at least those of you who have administrative access to their mail server.


Christoph Reichenberger

Ergonis Software GmbH

Jul 15, 2012 5:23 AM in response to Christoph Reichenberger

I can also confirm Christoph's solution is working!


Let me note my clients are not behind a proxy like most of you on this list, we only have issues with mail server certificate not being accepted by Mail.app - regardless it's set to 'Always Trust'.


Seems like Apple quietly lifted the minimum key length limit of acceptable certificates from 512 to '?' with 10.7.4 update (I had no time to figure out the exact value). But as Christoph suggested we recreated the mail servers certificate - now its 4096bit and works perfectly, I only had to delete the old certificate from keychain and set the new one to 'Always trust'. Mail.app is not complaining about certificate anymore.


Thank you Christoph!


edit:


turns out I missed to read the tech.note from Apple about 10.7.4:


"Description: Certificates signed using RSA keys with insecure key lengths were accepted by libsecurity. This issue is addressed by rejecting certificates containing RSA keys less than 1024 bits."


for more details read:


http://support.apple.com/kb/HT5281?viewlocale=en_US&locale=en_US

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Invalid Certificate on every secured website

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.