Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Can't access https sites since upgrade

I upgraded my late 2013 model MBA yesterday with el capitan, and ever since I have been unable to access certain websites through https. These sites include amazon, twitter, and apple.com. I'm getting an error that "You cannot visit signin.aws.amazon.com right now because the website uses HSTS." This seems to occur on safari and chrome, but interestingly not firefox. No problems like this prior to the upgrade.


Help is much appreciated in advance.

MacBook Air, OS X El Capitan (10.11), null

Posted on Oct 1, 2015 5:21 PM

Reply
5 replies

Oct 2, 2015 9:39 AM in response to utnuc

Back up all data.

Launch the Keychain Access application in any of the following ways:

☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)

☞ In the Finder, select Go Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.

☞ Open LaunchPad and start typing the name.

From the Category list in the lower left corner of the window, select My Certificates. In the list of certificates on the right, there may be one or more have a name that begins with "DigiCert" or "VeriSign". Export each such certificate by dragging it to the Desktop, then delete it from the keychain. If there are any certificates marked with a red "X" as expired or invalid, regardless of name, delete them without exporting.

Next, select Certificates from the Category list. Look carefully at the list of certificates in the right side of the window. If any of them has a blue-and-white plus sign in the icon, double-click it. An inspection window will open. Click the disclosure triangle labeled Trust to disclose the trust settings for the certificate. From the menu labeled

Secure Sockets Layer (SSL)

select

no value specified

Close the inspection window. You'll be prompted for your administrator password to update the settings.

Now open the same inspection window again, and select

When using this certificate: Use System Defaults

Save the change in the same way as before.

Revert all the certificates with non-default trust settings. Never again change any of those settings.

Again, delete all expired or invalid certificates.

Log out or restart the computer. Test. If all is now well, back up again, then delete the certificates you exported to the Desktop.

Apr 23, 2016 10:12 PM in response to Linc Davis

Sorry to bring this one back up from the mostly dead, but i'm having this same problem on El Capitan 10.11.4, but i'm unable to delete the expired certificates off my keychain. There is no delete option with "right-click", highlighting and pressing delete isn't doing anything, and i can't drag them to the Trash directly from the keychain.


I'm able to access the sites on Chrome so i've been doing a little direct hunting for the exact keychain and now wikipedia.org works again, but most other https sites (with the colored lock sign) aren't working.


Am i missing something obvious here?

Can't access https sites since upgrade

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.