Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

wildcard ssl

So our company has a Wildcard SSL Certificate that we use for most of our websites, and I've just setup a new 10.8 server for the use of profile manager. I've added our Wildcard SSL certificate to the systems keychain and trusted in but for the life of me I can't get the SSL Cert to take. I see it listed in the Server manager and select it and save the changes, but then I open up the SSL Cert again and there is nothing selected.


Any ideas?


Thanks in advance.

Mac mini, OS X Mountain Lion (10.8.2)

Posted on Oct 2, 2012 3:24 PM

Reply
21 replies

Oct 2, 2012 6:49 PM in response to stephen.willis.smith

So in server app go to


Hardware>Settings then click edit beside SSL certificate


Click manage certs and hit the + and create certificate identity


On the first page of the wizard you want to check "override defaults" step through the rest of the wizard (pretty straight forward) until you get to the Subject Alternate Name extension. in the dNSName you want to enter *.mydomain.com. Finish the wizard and allow it access to your keychain.


Then use that cert and "generate certificate signing request (CSR) and use that to create your SSL. Download your certs. Go back into server app

Hardware>Settings then click edit beside SSL certificate

Select the cert you made and click on the gear "Replace Certicate with signed or renewed Cert" and drag in your server.mydomain.com.crt cert (the one you downloaded).


Next open up keychain access app and select:

System

Certificates


then drag in the intermediate cert (need to enter your local admin password)


That should link your cert up


Let me know if that makes sense

Oct 2, 2012 8:10 PM in response to stephen.willis.smith

Thanks Stephen for the information. It is a GoDaddy cert and I did import their intermediate cert too.

Still no luck.


The additional steps you provided are for requesting a new cert, but I can't do this as we use the wildcard on a bunch of other servers. I've just eported our main wildcard cert and import that into our required web hosts.

It imports fine on to the Mac, but for whatever reason it's not taking in the server setting (Hardware > Settings > SSL).


Any other suggestions?

Thanks.

Oct 4, 2012 7:34 PM in response to stephen.willis.smith

Thanks for the tips. I was doing the custom options. The wildcard SSL actually works for the other options, but just not the websites. I'm not too sure what's going on.


I'm kind of abonding ship with this. I'll just use our company's internal signed certs for now. Stops the errors internally atleast, but extrnal use still has the errors.


Thanks everyone for the help.

Oct 29, 2012 3:31 PM in response to eysfilm

I had the same issue but got it resolved. The problem was that I had added my wildcard certificate to the keychain before installing Server. This meant that the key file wasn't present in /etc/certificates - if you look in /etc/certificates you will see only 3 files for your wildcard cert (cert, chain and concat) but no 4th (key) file.

Here's how I fixed it:


Reverse the bad import:

1. Server -> Hardware -> Settings -> SSL Certificate: Edit -> Manage Certificates -> select wildcard certificate -> Remove

2. Open Keychain and remove the matching Private key


Import again correctly:

1. Server -> Hardware -> Settings -> SSL Certificate: Edit -> Manage Certificates -> Import a Certificate Identity -> drag in certificate file(s)


Now when you look in /etc/certificates you will see 4 files for your wildcard cert and Server.app will happily assign it to all services.

Dec 11, 2012 1:14 AM in response to eysfilm

I had to get Server Manager back to 'Not Configured' before it would accept my Wildcard Cert for all services. iChat service was 'stuck' using my self signed certificate. I had to manually set iChat to 'None' then enable and disable iChat to clear it. Note that I was not using iChat before. I still had to enable and disable it to clear its certificate.


I could not get my wildcard certificate to work until I did this.

Dec 27, 2012 12:52 PM in response to DSHJ

Double-click on your certificate that you want to create a CSR for, then click the Renew button. I was flumoxed by this at first as well. There appears to be a bug where you are required to enter the Department name in the form, I just entered "n/a", and everything went through fine.


~Mike

wildcard ssl

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.