Digicert Intermediate Certificate suddenly failing...

Hi all! 
We have an install base of a few hundred Macs ranging from 10.7 to 10.10.  Suddenly, several of the machines seem to be missing the Digicert SHA2 Secure Server CA intermediate certificate.  We noticed the problem after several users reported warnings with our VPN appliance, which uses Digicert certs for ID. 
Reinstalling the certificate from Digicert's site clears up the issue, but I'm trying to root cause the problem.  The issue appears to happen only on 10.9.x, and seems to happen before OR after the 2015.004 security patch.  The patch does not resolve the problem.
I know folks have reported similar issues with Verisign certs and the 2015.004 update. 
Any ideas?  I've only seen this on a very small fraction of systems, so I'm not super concerned, but it is annoying...

I have this issue also. I opened this
HT204658

Similar Messages

  • External USB Maxtor One-Touch 3  suddenly fails to mount on MacBook Pro:

    External USB HD suddenly fails to mount on MacBook Pro:
    My One Touch III 600GB drive, external power supply, suddenly will not mount and is not recognized by the system profiler or Disk Utility, however, drive, connected USB, appears under windows XP.
    1. Power cable and usb cable working.
    2. Using external AC adapter(not relying on USB power).
    3. Other USB devices, mice, flash drives work on both USB ports.
    4. Drive works on Windows, folders and data integrity ok.
    5. Drive format is NTFS.
    6. No Maxtor software installed.
    7. No humming or strange noises emanating from drive.
    8. No problem to January 14, 2008,
    9. Mac OS 10.4.10 updates last downloaded and installed Jan 20, 2008.
    10.1 blip of the light on "The One Touch Button", then light turns solid white.
    Questions:
    1. Does Apple set sleep or lock switch for devices (drives)?
    2. If so, can it be reset manually?
    3. Does Apple have configuration profile for devices, like a registry key?
    4. If so, where is it located?
    Configuration:
    Dual 2 GHz MacBook Pro 15”
    2 GB DDR SDRAM
    OSX 10.4.10
    2 USB Ports Left and Right

    NOTE: This Update is required when using a OneTouch Drive as a bootable device. Seagate suggests that you dismount and disconnect your FireWire Drive before continuing.
    Users have identified issues when connecting OneTouch External Drives to FireWire Ports on their Mac G4 and/or G5 computers. These Problems range from system hangs, kernel panics to slow data transfer rates. The cause of these problems has been traced back to the FireWire Driver. Seagate has resolved these problems through updated FireWire Drivers.
    I am using USB and not trying to use drive as a boot device.

  • Import cert in Cisco 7921 with error "certificate verification failed"

    Hi everyone
    I am trying to install a digit cert on a 7921 and I get the message on import of "certificate verification failed".
    I have tried a number of time, create CSR file then login to certificate web site and get file assigned then import it back to the phone. I used the DER format
    Many thx indeed,
    Roy

    Hi,
    Referencing: https://supportforums.cisco.com/thread/2095711
    Have you followed the steps outlined in page 72 of this guide?  This should be applicable to 792x.
    http://www.cisco.com/en/US/docs/voice_ip_comm/cuipph/7925g/7_0/english/deployment/guide/7925dply.pdf
    Do you have any trace logs from the phone you can post after your attempt to import the cert?

  • Add intermediate certificate to signed jar

    Is it possible to add an intermediate certificate to a signed jar file?
    The users of my applet are asked to trust the certificate showing the hint that the source is not trusted. The root certificate of my code signing certificate is included in the trusted sources.
    Thanks,
    Reinhard

    I have already a full trusted chain consisting of the root, an intermediate certificate and my code signing certificate. The root is included in Java�s trusted roots. But if I sign my jar with my code signing certificate, Java can not build the trust chain, as it does not have the intermediate certificate. If it would be possible to include the intermediate certificate certificate it would work, but appearantly this is not possible with jarsigner.

  • The verification of the server's certificate chain failed

    Hi All,
    Not sure this is the right forum for this but never mind.
    I am trying to get abap2GApps working and am having problems with the client certificates.
    I am getting the below error in ICM :-
    [Thr 06] Mon Jul 30 09:34:47 2012
    [Thr 06] *** ERROR during SecudeSSL_SessionStart() from SSL_connect()==SSL_ERROR_SSL
    [Thr 06]    session uses PSE file "/usr/sap/BWD/DVEBMGS58/sec/SAPSSLC.pse"
    [Thr 06] SecudeSSL_SessionStart: SSL_connect() failed
      secude_error 9 (0x00000009) = "the verification of the server's certificate chain failed"
    [Thr 06] >>            Begin of Secude-SSL Errorstack            >>
    [Thr 06] ERROR in ssl3_get_server_certificate: (9/0x0009) the verification of the server's certificate chain failed
    ERROR in af_verify_Certificates: (24/0x0018) Chain of certificates is incomplete : "OU=Equifax Secure Certificate Authority, O=E
    ERROR in get_path: (24/0x0018) Can't get path because the chain of certificates is incomplete
    [Thr 06] <<            End of Secude-SSL Errorstack
    [Thr 06]   SSL_get_state() returned 0x00002131 "SSLv3 read server certificate B"
    [Thr 06]   SSL NI-sock: local=172.30.7.170:59036  peer=172.30.8.100:80
    [Thr 06] <<- ERROR: SapSSLSessionStart(sssl_hdl=60000000053910f0)==SSSLERR_SSL_CONNECT
    [Thr 06] *** ERROR => IcmConnInitClientSSL: SapSSLSessionStart failed (-57): SSSLERR_SSL_CONNECT {000726d5} [icxxconn_mt.c 2031]
    Having already got the accounts.google.com SSL certificate chain installed and working I can't get the docs.google.com SSL chain working.
    For accounts.google.com they use (this set works) :-
    1) CN=accounts.google.com, O=Google Inc, L=Mountain View, SP=California, C=US
    2) CN=Thawte SGC CA, O=Thawte Consulting (Pty) Ltd., C=ZA
    3) OU=Class 3 Public Primary Certification Authority, O="VeriSign, Inc.", C=US
    For docs.google.com they use a different set of SSL certs. :-
    1) CN=*.google.com, O=Google Inc, L=Mountain View, SP=California, C=US
    2) CN=Google Internet Authority, O=Google Inc, C=US
    3) OU=Equifax Secure Certificate Authority, O=Equifax, C=US
    Can anyone explain what I am doing wrong or how to correct this?
    Thanks
    Craig

    Further UPDATE
    After removing every certificate related to docs.google.com I still get the same error!
    I have even tried downloading the root certificate directly from GeoTrust themselves and yet I still get the same error.
    I have even resorted to running SAP program ZSSF_TEST_PSE from note 800240 to check the PSE and all is well!
    Referring to SAP Note 1318906 suggests I am missing a certificate in the chain but I am not!
    "Situation: The ICM is in the client role and the following entry is displayed in the trace:
    ERROR in ssl3_get_server_certificate: (9/0x0009) the verification of the server's certificate chain failed
    Reason:You try to set up a secure connection to a server, but the validity of the certificate cannot be verified because the required certificates are not available.
    Solution:The missing certificates are listed in the trace file. You must use transaction STRUST to insert these certificates in the Personal Security Environment (PSE) that is used for the connection. The certificates are usually made available to you by the server administrator. If the certificates are public Certification Authority (CA) certificates, you can also request the certificates there."
    What could possibly causing this?
    Please help!
    Craig

  • Install digicert wildcard certificate on 2012 RDSH Servers

    Hi Everyone
    I would like to find out is it possible to install a digicert wildcard certificate on 2012 RDSH Server
    My current RDSH deployment has 2 connection broker and SQL backend, bunch of RDSH 2012 servers in a collection. wildcard certificate is configured in the deployment properties. All servers are part of the domain.
    We already have a RASS servers. So we didn't install RDSH Gateway. External users RDP to the RDSH servers via RASS
    When users connect via RDP it prompt an certificate warning message.
    Please advice
    Thanks

    Hi,
    Thank you for posting in Windows Server Forum.
    Can you please provide the error\warning\event ID you are facing?
    Basic requirements for Remote Desktop certificates:
    1. The certificate is installed into computer’s “Personal” certificate store. 
    2. The certificate has a corresponding private key. 
    3. The "Enhanced Key Usage" extension has a value of either "Server Authentication" or "Remote Desktop Authentication" (1.3.6.1.4.1.311.54.1.2). Certificates with no "Enhanced Key Usage" extension can be used as well. 
    The certificates you deploy need to have a subject name or subject alternate name that matches the name of the server that the user is connecting to.  So for example, for Publishing, the certificate needs to contain the names of all of the RDSH servers
    in the collection.
    More information.
    Certificate Requirements for Windows 2008 R2 and Windows 2012 Remote Desktop Services
    http://blogs.technet.com/b/askperf/archive/2014/01/24/certificate-requirements-for-windows-2008-r2-and-windows-2012-remote-desktop-services.aspx
    Hope it helps!
    Thanks.
    Dharmesh Solanki
    TechNet Community Support

  • Certificate authentification failed

    I need help i have adobe reader 9 on my computer trying to update i get an error message certificate authentification failed, what do i need to do to update can some one help me.

    For Flash Player (according to your PM to me):
    Flash Player for ActiveX (Internet Explorer)
    Flash Player Plug-in (All other browsers)
    Flash Player (Mac OS X)

  • SQL Server not starting - FallBack certificate initialization failed

    I can not start my SqlServer 2008 Express. The problem seemed to start when I changed my "Built In account, Log in as" from Local Service to Local System. If I try to change back to Local Service I get the messagebox with WMI Provider Error, "Cannot find object or property. [0x80092004]".
    Getting a bit confused, but read http://support.microsoft.com/kb/900497    mentioned about 
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\MSSQL.1\MSSQLServer\SuperSocketNetLib, Value name: Certificate, Type: REG_SZ not having a valid value then 2005 would not starte - my value is blank. Changing it to 0 did not work.
    How can I import a valid certificate using SQL Server Configuration Manager. And how do you turn off Forced Encryption? Not sure if this would fix it, but couldn't hurt.
    ======================================
    2009-03-08 01:39:06.01 Server      Error: 17190, Severity: 16, State: 1.
    2009-03-08 01:39:06.01 Server      FallBack certificate initialization failed with error code: 1.
    2009-03-08 01:39:06.01 Server      Unable to initialize SSL encryption because a valid certificate could not be found, and it is not possible to create a self-signed certificate.
    2009-03-08 01:39:06.01 Server      Error: 17182, Severity: 16, State: 1.
    2009-03-08 01:39:06.01 Server      TDSSNIClient initialization failed with error 0x80092004, status code 0x80. Reason: Unable to initialize SSL support. Cannot find object or property.
    2009-03-08 01:39:06.01 Server      Error: 17182, Severity: 16, State: 1.
    2009-03-08 01:39:06.01 Server      TDSSNIClient initialization failed with error 0x80092004, status code 0x1. Reason: Initialization failed with an infrastructure error. Check for previous errors. Cannot find object or property.
    2009-03-08 01:39:06.01 Server      Error: 17826, Severity: 18, State: 3.
    2009-03-08 01:39:06.01 Server      Could not start the network library because of an internal error in the network library. To determine the cause, review the errors immediately preceding this one in the error log.
    2009-03-08 01:39:06.01 Server      Error: 17120, Severity: 16, State: 1.
    2009-03-08 01:39:06.01 Server      SQL Server could not spawn FRunCM thread. Check the SQL Server error log and the Windows event logs for information about possible related problems.
    2009-03-08 01:39:06.07 spid14s     Clearing tempdb database.
    =====================================
    Any help would be appreciated.
    TheBrenda

    I know it's probably too late to help with the original poster, but we had this same issue and nothing we tried resolved the problem. Finally, we opened a technical incident with Microsoft and this is the solution that we were provided:
    Take backup of below registry key.
    HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid This key should ideally have the GUID of the machine without curly braces, so {xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx} becomes xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
    Then delete the braces.
    Try to reboot and start the SQL service . If service don’t start then Uninstall and reinstall SQL.
    The above solution worked on two separate machines exhibiting this problem.

  • Get message, "certificate authentication failed" when downloading

    Get message "certificate authentication failed" when downloading Adobe flash

    Download and run the offline installers
    Flash Player: http://helpx.adobe.com/content/help/en/flash-player/kb/installation-problems-flash-player- windows.html#main-pars_header
    Adobe Reader: http://get.adobe.com/reader/enterprise/

  • Server certificate verification failed: issuer is not trusted

    Tried to sign in to a couple of websites lately and got this message:
    Server certificate verification failed: issuer is not trusted
    What is going on and how do you fix?

    hello, unfortunately this is an issue caused by the website, which uses an intermediary certificate but doesn't properly [https://www.ssllabs.com/ssltest/analyze.html?d=https%3A%2F%2Fphp.net%2F&hideResults=on implement a trusted path to the root certificate authority].
    in order to work around that you'd have to manually install the missing certificate and trust it to verify websites in firefox: https://ssl-tools.net/certificates/a1e08f9a6a21691dc96bc3b9fa59a7cadd6d4cc4.pem

  • Having trouble installing adobe flash player- keep getting "Certificate Authintication failed", help

    having trouble installing flash player, keep getting "certificate authentication failed", did all the troubleshooting - did "unistall" stil nothing works.  Any suggestions

    What is your operating system & version?
    What is your web browser?
    [topic moved to Flash Player forum]

  • Online certificate check failed

    I downloaded viber a while ago on my nokia 5230 and it was working perfectly. Recently when I opened viber on my phone I received a message saying that there s a new version of viber available on ovi store that I should get. Which I did. But when updating viber my phone says online certificate check failed. And the installation stops there. What does that mean? Can someone please help? This is highly frustrating. Almost smashed my phone because of that. Please help.
    Solved!
    Go to Solution.

    Tasha0190 wrote:
    I received a message saying that there s a new version of viber available on ovi store that I should get. Which I did.
    I guess, you used this item.
    Although scoobyman’s answer solves this issue, it opens up your Nokia to viruses and other bad applications. Signing makes sure, the author of the app is the one he claims to be. Signing makes the author responsible for what he does. If an author does something bad, his certificates gets revoked. OCSP makes sure, the signature is still good. Therefore, revert these two settings, after you installed an app you are trusting.
    Furthermore, an application from the Nokia Store should work with any setting. Any error or warning message is not acceptable and should be forwarded to the Nokia Store team for further analysis.
    a) Menu » Settings » Installations » Installations settings » Software installation
    The state of this item does not matter because Viber is signed correctly. Therefore, ‘Signed only’ works for Viber and is recommend.
    b) Menu » Settings » Installations » Installations settings » Online certificate check (OCSP)
    The state of this item does matter. Therefore, please, set is at least to ‘On’. In Wireshark, I checked that the certificate is not revoked but good. Therefore, I have no idea what is wrong here. It this not normal.
    Conclusion:
    Set ‘Online certificate check’ from ‘must be passed’ to ‘On’. If you still get the installation security warning ‘Unable to verify supplier’, report this to the Nokia Store team for further investigation.
    Change ‘Software installation’ from to ‘off’ only when you are absolutely trusting that app. Revert ‘Software installation’ to ‘signed only’ after the installation of that single particular app.

  • Two Macbook pros circa 2009 in our temporary household in Turkey suddenly failed to boot and got stuck on the grey screen. They were able to boot at the Apple store, but not when we brought them back to our apartment. Could this be a coincidence?   A

    Two Macbook pros circa 2009 in our temporary household in Turkey suddenly failed to boot and got stuck on the grey screen. They were able to boot at the Apple store, but not when we brought them back to our apartment. Could this be a coincidence?   A

    THank you Ogelthorpe. When my wife's computer I went on line to the site that you sent and tried everything But nothing worked. When my son came to visit and his MacBook Pro did exactly the same thing we became suspicious - too much of a coincidence. We took both computers somewhere else, out of our apartment, and they both booted. We ran disk utility on both, but the report in both cases was that there are no issues with the hard drive.  Back in our apartment neither will boot up. My MacBook Pro is a later model with a solid state drive and it seems to work fine here.. I tried an external drive and it works fine. We think that this has something to do with some kind of magnetic interference in our apartment to which the 2009  drives are susceptible.  It is indeed a mystery!
    alf

  • [solved] mutt, msmtp & gmail not working, TLS certificate veri. failed

    Today I can't send emails again, ending up with this message:
    msmtp: TLS certificate verification failed: the certificate hasn't got a known issuer
    msmtp: could not send mail
    I got this issue a week ago, then I downloaded the ca-certificates package and changed everything according to http://mychael.gotdns.com/blog/2007/04/ … archlinux/ the it worked again, but today it's back
    Anyone with the same issue or working config?
    My config here:
    account gmail-sec
    host smtp.gmail.com
    protocol smtp
    auth on
    user [email protected]
    password mypass
    tls on
    port 587
    tls_trust_file /usr/share/ca-certificates/mozilla/Thawte_Premium_Server_CA.crt
    Last edited by drag0nl0rd (2008-07-30 09:33:09)

    shining wrote:
    drag0nl0rd wrote:@shining: on that wiki page is a link to another web page which explains the certificates issue
    (msmtp, TLS, and ArchLinux gives instructions on how to configure the certificate for msmtp.) and on that page I found a week ago the solution for my problem. So now I put a comment with the latest used certificate. But if you have time, you can of course also change the wiki page
    Ok I see, there is a comment on that external page. Well, that will do for now.
    However, what I would like to see eventually is a small wiki page dedicated to msmtp, with all required information on it, so that we don't need to look at other blog post. And then replace the msmtp section on mutt page by a simple link to that new msmtp page.
    There is no reason to tie msmtp with mutt.
    As I expected, I eventually ran into this problem and had to fix it, which reminded me of this thread.
    So here it is :
    http://wiki.archlinux.org/index.php/Msmtp
    http://wiki.archlinux.org/index.php/Mutt#Sending_Mail
    Please do not hesitate to improve it as you see fit.

  • Installation error: Certificate authentication failed

    Hard drive crashed. Restoring files on new drive, Keep getting "Certificate authentication failed" when trying to install Adobe Reader. How do I fix that?

    Use the offline installer from http://get.adobe.com/reader/enterprise/

Maybe you are looking for

  • Drivers for ThinkVisio​n USB Soundbar (40Y7616)

    After installation of new ThinkVision USB Soundbar (40Y7616) on Windows XP the device is not recognized by OS, it shows as "USB Audio Device" in device manager, but Windows can not find a driver, and no driver was shipped with the speakers.  Search o

  • Sqlldr using decimal only works direct? why?

    I am loading data from a file received from a client. It contains char, smallint and decimal data. after creating a .ctl file to load the file, it will only load if i use direct=true why? All columns are defined and line-up with the data (looking at

  • I have the latest MacBook Pro , 13"

    . Which adaptator do i need to connect my computer to a hdmi port on a tv?

  • Can't hear caller/the​y can't hear me

    Does anyone have a solution for  Can hear caller/they can't hear me on the Palm Pre?

  • Folder question~mark at startup  :(

    when i start up my computer i get a folder with a blinking question mark. it then starts up fine, but i'd rather not get that sinking/scary feeling every time i startup... how can i get rid of it>?