We are using Microsoft Messenger 7.01/7.02 on our corporate network.
There is an untrusted (default) certificate that has to be installed under
the user's login items in keychain before Messenger will allow the user to
logon locally.
The scenario is that I am trying to fix a mistake on a monolithic image. We
installed Messenger 8.01 by mistake and it went out with the gold monolithic
image.
So what I did was launch Composer, did a New and Modified Snapshot. After
the initial snapshot was created, I did the following steps.
Dragged the 8.0.1 version of Microsoft Messenger to the trashcan.
Emptied the trash. (needed to remove the old version)
Installed Microsoft Messenger 7.02 by drag and dropping the app to the
Applications folder
Lauched Microsoft Messenger and did a partial walkthrough of the installer
but quit it when it asked for the username/password.
I then installed our untrusted certificate by double clicking on it which
opens up Keychain Assistant
Chose Always Trust and saved/oked the cert install window in Keychain
Assistant.
Relaunched Microsoft Messenger 7.02 and quit it a few more times for good
measure
Once that was done, I went ahead and built the package and selected the
checkboxes for Fill User Templates and Fill Existing User Home Directories
Spammed the package out to my test box. It did properly uninstall Messenger
8.01 and installed Messenger 7.02
I then logged in with my domain credentials.
At that point before completed login, I get the window 'The system was
unable to unlock your login keychain' and I have the options of continue
login, create new keychain, or update keychain password.
The problem is that I don't want to update the keychain password, because
the only password it will take is the local admin account I used to create
the package with, it won't unlock with the domain credentials.
What is the proper method for packaging up certificates so that they are
available in all user's login keychains?
Thanks,
Brenton Snyder