importCACert.sh

Kevin
Contributor II

If I run the [https://jamfnation.jamfsoftware.com/viewProductFile.html?id=135&fid=459] script on most of my Macs, it seems to work fine. However, on some Macs, I get this error:

Script result: Importing CA Cert...



WARNING
The keychain you are accessing, X509Anchors, is no longer
used by Mac OS X as the system root certificate store.
Please read the security man page for information on the add-trusted-cert command. New system root certificates should
be added to the Admin Trust Settings domain and to the System keychain in /Library/Keychains.

The common thread… a couple of these Macs have 10.10.2 OS.
Plenty of other Macs with 10.10.2 work fine running the same script. I am assuming the ones that fail were upgraded, then upgraded, then upgraded.

Has anyone written a script to delete the x509Anchors keychain?

3 REPLIES 3

bentoms
Release Candidate Programs Tester

@Kevin why not deploy the cert via a profile?

davidacland
Honored Contributor II
Honored Contributor II

Same for me. I used to install certs via the security command line tool until around 10.9. Config profiles are so much easier.

Kevin
Contributor II

Duh.
Pulled too many directions these days I guess.

THANK YOU!