Skip to main content
Answer

JSS Certificate Communication Problem

  • January 9, 2012
  • 4 replies
  • 27 views

Forum|alt.badge.img+3

We have a signed certificate from GeoTrust on our JSS. So I enabled the new "Use certificate communication with JSS" setting. The warnings said nothing about ensuring that the clients can access the JSS with the certificate- only to ensure that the JSS has a valid certificate.

Well now a bunch of our 10.5 Macs can't connect to the JSS because they don't trust the certificate. I looked and the GeoTrust Root CA is not installed on there. I installed it on one, and now Safari doesn't give the untrusted message, but running jamf log still doesn't work.

Any ideas how I can fix this?

On side note- after all of this, I just found the extension attribute to check for compatibility. I wish in the documentation would have indicated to run that before enabling the setting.

Best answer by ryan_yohnk

I would keep an eye on the thread Don posted. It sounds like a very similar issue. While the command apple4ever posted will add the CA certificate to the System trust, curl on 10.5 uses a different list of trusted CAs. There's a post on the other thread about how to update the list of trusted CAs on 10.5 machines. Let us know if that helps.

Ryan

4 replies

Forum|alt.badge.img+3
  • Author
  • New Contributor
  • January 9, 2012

I should also know that I tried the following command:

sudo /usr/bin/security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain ~/Desktop/GeoTrust_Root.cer

That still didn't work.


donmontalvo
Forum|alt.badge.img+36
  • Hall of Fame
  • February 8, 2012

FYI, another thread with similar issue:

https://jamfnation.jamfsoftware.com/discussion.html?id=3761

Don


Forum|alt.badge.img+12
  • Employee
  • Answer
  • February 15, 2012

I would keep an eye on the thread Don posted. It sounds like a very similar issue. While the command apple4ever posted will add the CA certificate to the System trust, curl on 10.5 uses a different list of trusted CAs. There's a post on the other thread about how to update the list of trusted CAs on 10.5 machines. Let us know if that helps.

Ryan


Forum|alt.badge.img+3
  • Author
  • New Contributor
  • February 23, 2012

Yep, that was the problem. I had to actually manually add the root CA certs to the bundle, but once I did that and put it in the right place, it work.

Thanks!