Skip to main content
Question

Root certificate import and change to "Always Trust"

  • November 9, 2016
  • 30 replies
  • 416 views

Show first post

30 replies

Forum|alt.badge.img+4
  • Contributor
  • April 6, 2021

Another few bits - the certs are ECDSA (not RSA). I wonder if there’s some process that breaks if that’s the case.


sdagley
Forum|alt.badge.img+25
  • Jamf Heroes
  • April 6, 2021

@JamieG Have you tried one configuration profile with a single certificate payload for all certs? Have you verified that Keychain Access can import the cert files used to create your certificate payload?


Forum|alt.badge.img+4
  • Contributor
  • April 7, 2021

Narrowing down on my issue - for some reason, our RootCA, is not recognised by macOS as a Root (e.g. the orange certificate), instead it's recognised as an Intermediate... (blue certificate)

I have no idea why this is happening, but that would make sense for the rest of the problems.

So what makes a root a root? It's seen as it's own issuer etc.. and we haven't seen any issues in our Microsoft AD world.


sdagley
Forum|alt.badge.img+25
  • Jamf Heroes
  • April 7, 2021

EDIT: Removed non-useful suggestion


Forum|alt.badge.img+4
  • Contributor
  • April 8, 2021

Got to the bottom of the issue - turns out our RootCA was using specifiedECDSA which a lot of stuff doesnt like, changed it back to sha384ECDSA as it should have been (not the MIcrosoft frig on it)