Skip to main content
Question

importCACert.sh

  • March 31, 2015
  • 3 replies
  • 8 views

Forum|alt.badge.img+16

If I run the [https://jamfnation.jamfsoftware.com/viewProductFile.html?id=135&fid=459] script on most of my Macs, it seems to work fine. However, on some Macs, I get this error:

Script result: Importing CA Cert...



WARNING
The keychain you are accessing, X509Anchors, is no longer
used by Mac OS X as the system root certificate store.
Please read the security man page for information on the add-trusted-cert command. New system root certificates should
be added to the Admin Trust Settings domain and to the System keychain in /Library/Keychains.

The common thread… a couple of these Macs have 10.10.2 OS.
Plenty of other Macs with 10.10.2 work fine running the same script. I am assuming the ones that fail were upgraded, then upgraded, then upgraded.

Has anyone written a script to delete the x509Anchors keychain?

3 replies

bentoms
Forum|alt.badge.img+35
  • Hall of Fame
  • March 31, 2015

@Kevin why not deploy the cert via a profile?


davidacland
Forum|alt.badge.img+18
  • Valued Contributor
  • April 1, 2015

Same for me. I used to install certs via the security command line tool until around 10.9. Config profiles are so much easier.


Forum|alt.badge.img+16
  • Author
  • Contributor
  • April 1, 2015

Duh.
Pulled too many directions these days I guess.

THANK YOU!