Mail and Certificate

Hello
today I changed my Mail Connection to SSL. But now a message box always appears. There is a help topic from Apple. I have done: I added the certificate to Keychain with X.509 Anchors and changed the trust settings to "alwasys trus"...
But there is no difference: Everytime I startup Mail the dialogue box appears again...
Any Ideas?
Thanx, and Greetings from Germany
MacBook Pro   Mac OS X (10.4.8)  

I don't know whether this will be helpful to you or not, but, when you added the X509 certificate, how exactly did you do it? When the "Unable to verify SSL server..." dialog box appeared, did you...
1. click on the Show Certificate button
2. drag certficate icon at top left hand corner of extended dialog box to desktop
3. double-click on that icon which will launch the Keychain Access
4. choose X509 Anchors at the pulldown menu
5. then import certificate into keychain
if that's not how you did it, try that. If that still doesn't work, try again, except insert these steps and complete remaining steps in admin-privileged account:
2.1. fast-switch user to admin account
2.2 start Terminal
2.3 move file from regular user account's Desktop to admin account's Desktop:
sudo mv /Users/{prevShortUserName}/Desktop/{fileNameOfCertFile} ~/Desktop/
2.4 change ownership of certfile from regular user to admin user:
sudo chown {adminShortUserName}:{adminGroupName} Desktop/{fileNameOfCertFile}
In Terminal, if you type
grep {domainNameOfMailserverYouAreTryingToAdd} /System/Library/Keychains/X509Anchors
and the mailserver's X509 anchor has, in fact, been added, you should get a response that says
Binary file /System/Library/Keychains/X509Anchors matches
(you may have to do this "grep" from an admin-privileged account)
Also, in Terminal (possibly as an admin user) if you type
ls -lT /System/Library/Keychains/X509Anchors
(those are lower-case "L" in the "ls" and the "-lT") you should see a file modification date and time matching when the anchor was added to the keychain.
I have one other thing you might try, with absolutely no guarantees of success, so I'll hold off on suggesting it until you post back with an outcome for these suggestions.
(if this solves your problem, or is actually helpful towards arriving at a solution to your problem, please consider marking this reply as "helpful" or "solved," in addition to, if applicable, marking this question as "answered"

Similar Messages

  • Mail Security certificate issue and cannot send email from mail app on surface 2

    well im have the same issue like others and coincidently we all started to have this issue just recently like few days ago. Please help us out as on the surface 2 mail app my Hotmail account ( The main account )
    cannot send mails and on the account setting it says there is a problem with the server security certificate. So how to fix it ???

    Does this issue only happen with Hotmail account? Have you tested the account in other mail programs or send a email via web mail in a browser? What is the result if we delete the account then recreate the account?
    Please also refer to solutions in this link:
    Supporting Windows Mail 8.1 in your organization
    See this part Self-Signed Certificates in Windows Mail 8.1
    http://blogs.technet.com/b/exchange/archive/2013/10/18/supporting-windows-mail-8-1-in-your-organization.aspx
    Yolanda Zhu
    TechNet Community Support

  • Digital signature and certificates on Mail

    Hello All,
    I'm new using mac and i have a token with my digital certificate. So i wanna know:
    How can i use subscribe or use a digital signature on Mail. How can i use my certificate to sign the message.
    Thanks,
    Altemir Pacheco

    Altemir ... It's important that the certificate has been created for the e-mail address you want to use as sender e-mail. Your certificate needs to be imported into keychain. Keychain only accepts certificates in a number of formats, among them .p12. You can import in a number of ways, you can for example drop your .p12 file (the certificate) on the keychain icon. Then open keychain and check whether the certificate is visible under "my certificates". It has to appear there and it has to show as "valid" and not as "expired". Control-click on the certificate and set-up a new preferred identity for your e-mail address (I am not sure whether this step actually does any difference but give it a try). Close mail.app and restart mail.app. When you now create a new e-mail and you choose as sender e-mail the e-mail address for which you have the certificate then you should see on the right side, just below the subject line a little symbol which you can click on for activating the signature for the e-mail your writing. Hope all this works.

  • I tried to buy a gift certificate to be e-mailed, and it said "This Apple ID is not currently eligible  to purchase gift certificates" - how come?

    I tried to buy a gift certificate to be e-mailed, and it said "This Apple ID is not currently eligible  to purchase gift certificates" - how come?

    Same problem here and it seems to be a problem that has been occuring, intermittently, for quite a while. I  received the following reply from Apple Support
    "You will receive an email after the matter has been investigated and further information is available."
    As I believe that strength comes in numbers, please open a support ticket:
    http://www.apple.com/support/itunes/

  • IPad and Secure Email Certificate. How to encrypt e-mail using certificates *. p12?

    Dear all!
    I would like your assistance in the following matter:
    iPad and Secure Email Certificate.
    How to encrypt e-mail using certificates *. p12?
    What software do I need to buy?
    Thanks.

    Confirm you have imported your certificates into the Windows Certificate store?
    Check the info below for the proper procedure.
    1. Locate the certificate files you saved on your computer. Double-click the first .P12 file.
    2. In the Certificate Import Wizard Dialog, click Next.
    3. The file you selected displays in the File Name field. (If it is not already displaying in the field, click Browse to select it.) Click Next.
    4. Enter the appropriate backup password:
        For the digital certificate file, enter the password that the Stache web page gave you when you downloaded the certificate.
    5. Clear the Enable Strong Private Key protection option.
    6. Select the Mark this key as exportable option. 
    7. Make sure the default option Automatically select the certificate store based on the type of certificate is selected and click Next.
    8. The application displays a summary of the settings. Click Finish.

  • Mail and Thawte certificates

    I've been trying to use a thawte email certificate with Mail and Mail does not recognize it.
    Actually, I think part of the problem is that keychain access puts the certificate in "Certificates" and won't let me put it in "My Certificates" - can anyone explain why this is happening?
    I've gotten this to work with public/private key pairs in the past, and there are posts all over this discussion board from people with the same problem - has anyone figured this out?

    Hi Michael-
    I was having the exact same prob. Turns out that Safari or the Keychain Util. didn't actually install everything it was supposed to. I found some good directions on R'Reilly's MacDevCenter site which fixed everything: http://www.macdevcenter.com/pub/a/mac/2003/01/20/mail.html.
    I had originally gotten a Thawte Personal Freemail certificate using Firefox. So, following their directions, I went to Firefox prefs./security and backed up the Thawte cert. to a file on my desktop. Next, they said to open the Apple keychain util. and CREATE A NEW KEYCHAIN. Not a new certificate, but a new keychain. Call it whatever. Then, double-click on on the backed-up certificate file and install to your new keychain. Voila. You should see three certificates and one private key (when I initially downloaded the certificate using Safari it only installed two certificates, and in the "login" keychain--which I'll now zap).
    Good luck!
    - TRT

  • Mail and SMTP server settings of ASA Certificate Authority for cisco anyconnect VPN

                       Dear All,
    i have the folloing case :
    i am using ASA as Certificate authority for cisco anyconnect VPN users,the authentication happens based on the local database of the ASA,
    i want to issue a new certificate every 72 hours for the users ,and i want to send the one time password via email to each user.
    so what the setting of the mail and smtp server should be ,
    was i understand i should put my smtp server ip address then i have to create the local users again under(Remte VPN VPN--Certificate management--Local certificate authority --Manage user Database) along with their email addresses to send the one time passsword to them via their emails.
    i sent the email manually ,hwo can automate sending the OTP to our VPN users automatically vi their emails?
    Best regards,

    Thanks Jennifer.
    I did manage to configure LDAP attribute map to the specific group policy.
    Nevertheless, I was thinking whether I can have fixed IP address tied to individual user.
    Using legacy Cisco VPN Client, I can do it using IPSEC(IKEv1) Connection profile, where I set Pre-Shared Key and Client Address Pools. Each Client Address Pools has only 1 fix IP address.
    Example: let say my username is LLH.
    Connection Profile for me is : LLH-Connection-Profile, my profile is protected by preshared key.
    Client Address Pool for me is : LLH-pool, and the IP is 172.16.1.11
    Only me know the preshared key and only me can login with my Connection Profile.
    Using AnyConnect, I have problem. User can use any connection profile because I cannot set preshared key for AnyConnect. In that case, I cannot control who can use my Connection Profile and pretend to be me.
    Example:
    AnyConnect Connection Profile for me is : LLH-Connection-Profile, without any password
    Client Address Pool for me is : LLH-pool, IP is 172.16.1.11
    Any body can use LLH-Connection-Profile, login with another user name, let say user-abc which is a valid user in LDAP server. In that case, ASA assign 172.16.1.11 to user-abc and this user-abc can access server which only allow my IP to access.
    I hope above description can paint the scenario clearer.
    Thanks in advance for all the help and comment given.

  • Issues with Mail and SMTP and Gmail Accounts

    So this isn't a question....more like a solution that I had to figure out. 
    We have multiple gmail accounts in our family and after upgrading to OSC Yosemite our gmail accounts wen't haywire.  My wife was sending emails that eventually were sent from my gmail account (mass neighborhood emails at that.....and all replies came to me instead of her).  I spent about 2 hours investigating and put together several different threads that finally fixed out problem.  The root of the issue is that you can share the same Incoming Mail Server for all of your gmail accounts and your mail will go to the accounts that it is supposed to go to, but you have to have individual Outgoing Mail Servers for each of your accounts otherwise all outgoing mail will come from one account only.  I don't know why this happened, it is a pain in the butt, but here's how I fixed it with 3 gmail accounts running through 1 mac.    
    1st - you need to remove all of your gmail accounts from mail via Internet Accounts in Settings. Just highlight the account and hit the minus sign at the bottom.  You won't lose anything if you have your gmail settings set to default which backs everything up to Google's servers....it will all load back to you mac and it will all be available online at gmail.com
    2nd - you need to add back all of your accounts one at a time (and follow all of the following steps for each account before adding another).  Select the plus sign and choose Google (for gmail accounts only). 
    3rd - Give your gmail account a recognizable name in the "Name" field (if you have multiple Gmail accounts to add, you will want to distinguish between them).
    4th - type in your username ([email protected]) and password.  Make sure to add the suffix @gmail.com. 
    5th - Check the boxes that you want to add to your mac (mail, contacts, calendars, messages, notes). 
    6th - Click the "Details" button to ensure that you have an adequate description (see # 3 above) if you are going to have multiple gmail accounts to add. 
    7th - Open the Mail app.
    8th - From Mail Preferences/Account Information Tab - make sure that you account is Enabled (check box next to "Enable Account", make sure that you have an adequate description name, email address is correct, Incoming mail server is imap.gmail.com, Username is your normal gmail login username (absent any suffix like .gmail.com), password is your gmail password. 
    9th - Then, from Preferences click on the Advanced tab and....Uncheck "Automatically detect and maintain account settings".
    10th - Then, go back to Account Information Tab and.....from the Outgoing Mail Server (SMTP) dropdown box, select Edit SMTP List....
    11th -  You need to create an individual SMTP Server Account for each gmail account that you plan to add.
    12th - To do this click the plus button.  Server Name should always be smtp.gmail.com.  Type in your own Description (I recommend naming it after the gmail account that you plan to attach it to). 
    13th - TLS Certificate should be "None"
    14th - Click the Advanced Tab - From here, uncheck the box for "Automatically detect and maintain account settings".  Then make sure Port is 587 (default is 25 for some ungodly reason).  Check the box for "Use SSL".
    15th - Set authentication to "Password".  User name MUST contain a suffice (i.e [email protected]).  Password is your normal gmail password. 
    16th - Click OK. 
    17th - Now your back at Preferences/Account Information - Link your account to the SMTP server that you just created by using the dropdown box next to Outgoing Mail Server (SMTP). 
    18th - Save all changes and close out of Mail App. 
    19th - Restart Mail and recheck steps 8-15....for some reason my passwords kept getting erased, but they eventually saved and took. 
    20th - Add another gmail account by following these steps and then recheck all along the way for passwords, suffixes, everything.  You will want to make sure that your accounts are all properly linked to their respective Outgoing Mail Servers (hence the distinct naming descriptions).   
    21st - Once you have added multiple accounts send email between them to make sure that they are being sent from and received to the correct accounts. 

    Wow! Oh my goodness Patrick, thank you so much man. That's a ton of informatiion to take the time to write out step by step and share with strangers.  I really, really am grateful to you.  I've been dealing with this for a month, half the month I kept changing my passwords and kept assuming I was making some mistake.  It used to work fine.  About a week ago I started looking for a solution and couldn't find one that worked. 
    You have changed that sir!  I'm good to go, stress level will lower when I am on my Mac, and I'm so glad to not have all these messages popping back up that I was done with! 
    Muchos Gracias Amigo!  Owe you one...

  • How can I install an E-Mail CA Certificate?

    I have a friend who just bought an iPhone within the past month. Where can I find the information necessary on how to guide her to install an E-Mail CA Certificate on her iPhone?

    You can select another email that is not important/you want to delete then hold down the command key and highlight the email you don't want to open. Then click on delete!

  • Has anyone had recent issues with iCloud mail and Outlook 2011?

    Two days ago without warning when sending an e-mail from Outlook 2011 from a MacBook Pro running 10.8. (Have a .mac account), I had an error pop up, see below.
    Tried entering the password but the same error popped up. Thought there might be an error with the keychain so verified and ran a repair. Still the error continued. I checked that the password was still working and logged into iCloud. I then launched Mac Mail and this worked fine and so also my iPhone / iPad etc. Nothing I did made it possible to send e-maills from my .mac account although I could receive them.
    For the last couple of days I have been using my MacBook AIr for sending mails for the same account via Outlook 2011. This has been working fine all day until 25 mins ago when the same error message popped up on this Mac too. Went through the same set of tests and again Mac Mail works and so does the password.
    Have tried to Google for a solution but can't find anything relevant. Could this be Microsoft trying to cause problems for Apple users, some rogue update, iCloud security certificate issue, or something more sinister. Any suggestions for a fix gratefully received, as currently I can't use Outlook 2011 on either Mac.

    Hi guys!
    I am also having big trouble syncing my iCloud acc. I am able to send email, but i cannot recieve any. I have tried almost everything. I have tried using p01, p02, p99 servers, without solving the problem. I have tryed typing "INBOX" and "/" in IMAP root, still not working. Have anyone got a solution?
    I am using:
    OS X 10.9.1
    Outlook 2011 for mac v. 14.3.8
    I really hope someone has got an answer!
    Sorry the text in the screenshots are in danish. I hope you get the idea anyway.

  • Mail and web server on same machine

    hi to all,
    i have jes 4 suite installed on the same machin: uwc runs on port 81 and 443 (secure) and mail can be accessed on:
    https://mail.dom.com
    I want to create a new web instance to host the web content. It will be access at:
    http://www.dom.com
    What needs to be done so that users do not access
    https://www.dom.com as web mail
    and http://mail.dom.com as web server?
    thanks!
    Linda.

    What is on port 80 is the webserver that should host the website.
    What is on port 81 is the webserver instance hosting the webmail. I installed a certificate and created a new LS so that users access the webmail through https. port 81 is firewalled.
    There is no command called 'host' on Solaris. Actually the DNS admin will register www.dom.com and mail.dom.com to have the same IP since mail and web are installed on the same machine.
    The server processes that exist should be the mail processes and the 2 web instances processes. the first instance should listen to port 443 and 81. The second instance should listen to port 80.
    the urls that a user might type:
    https://mail.dom.com
    http://www.dom.com
    http://mail.dom.com
    the last url is what I want to change. Normally this should display the website. I don't want this result. I want to display the webmail page i.e. https://mail.dom.com. If this is not feasible, I want to display a page showing the 2 other urls.
    thanks,

  • E-mail Gift Certificate To Yourself?

    Is it possible with iTunes to send an e-mail Gift Certificate to yourself?
    It sounds like a weird idea, but I'd like to put £10 credit on to my own account, without going out and having to buy a physical plastic card each time.

    I have done this and it works.
    I do it because I want to make sure I don't spend more than AU$50 a month. When you just use your credit directly for purchase it's not easy to see how much you are spending over a month. You get many small transactions on your card. If you do the email gift certificate then you can see at the top of the iTunes Store how much money you have left until next time you purchase another gift certificate.
    You might want to check out whether any retailers do any specials. JB HiFi in Australia had a deal recently of 2 $30 iTunes Gift Cards for $50. Apparently they do this from time-to-time.

  • Mail gives certificate warning with SSL off

    Since upgrading to Yosemite, every time I open Mail I get a Server Certificate warning for each mail account even though I have SSL off for them.
    At first I couldn't turn SSL off, each time I unchecked the SSL box and saved then went back in it was checked again. I then realised there was an additional checkbox in the Advanced section for Allow Insecure Authentication which kept the non-SSL settings. However, even though SSL is off for all four of my mail accounts I still get the warning about the server certificate each time I start Mail and it check the mailboxes for the first time.

    Hi
    Similar issue with Mail 'allow insecure authentication'. It keeps unchecking itself on restart, screen saver log out etc.
    The mail account is SSL but at the server end so doesn't need SSL in the Mail app.
    Might try with it on anyway...
    D

  • Mail and Twitter not working

    Hi all,
    I'm having issues with setting up my mail and twitter account. I folllowed all instructions for mail but the imap server appears to be offline. Also when I open notification centre and try to tweet, it sends me to system preferences to set up my twitter account. I type my user name and password but it says they're incorrect although I use them to log on the site.
    What do u suggest I do?
    Cheers,
    Z

    Hi Yogiraj,
    Welcome to the Nokia Support Discussions!
    This thread may help you with your concern:
    http://discussions.nokia.com/t5/Asha-and-other-Nokia-Series-30/nokia-asha-306-Certificate-invalid-ac...
    Let us know the outcome.

  • Deleting X509 anchors and certificates

    Mail server certificates (file extension .cer) can be added as X509 anchors or as certificates. If one wants to delete an anchor or certificate from wherever they are kept (where are they?) how does one do it?

    Hi rha3675, Peter,
       I have not tried any of this but it would be my guess that the only thing either of you can do is to delete every reference you can find to the contents of the keychains. It sounds like some of the applications themselves keep references to what they store in the keychain. It's possible that that information is reread when the system boots so you might try a reboot but if the apps keep references then you'll have to delete them, possibly by hand.
       After the reboot I would first open the Keychain Access application and delete every item in every keychain. In each keychain, select the "All Items" category, select and delete all entries. You might have to delete the keychains but hopefully not.
       Then look for references in the individual applications. For instance, open the Safari preferences, select the "AutoFill" tab, edit each type of form and remove all of the references. Do the corresponding thing with each problematic application.
       Then I would use Pacifist as I described above and reinstall the default keychains and keys. Having the public keys of major authorities like VeriSign and Thawte is really convenient when surfing the web. Finally, I would reboot again.
    Gary
    ~~~~
       I try to keep an open mind, but not so open that my brains fall out.
             -- Judge Harold T. Stone

Maybe you are looking for

  • Raising Exceptions in XSLT mapping.?

    Hi, When there is an mapping exception, in UDF, i raise an exception... Similar is the case with Java & ABAP mappings. Now, How do i raise mapping exceptions in XSLT mapping (Java & ABAP)..? --DJ

  • Query - Opening Balance

    Hello, I'm using SAP 8.81 PL 6 and would like to come up with a query that displays the opening of an account at a given date. I have checked through the forums and come across the below query which unfortunately displays no results. SELECT T0.[Trans

  • FaceTime is not working in iPhone 4S using Vodafone in Kolkata, India

    Hi, I am using iPhone 4S model number: MD258AE/A. I bought it in Bahrain and using Viva FaceTime worked. But in Kolkata I am using Vodafone 3g. imessage got activated but I am not able to activate FaceTime. I tried sending message to UK number but it

  • BR0970W Database administration alert

    I get this error in DB13  in CheckDB, . BR0970W Database administration alert - level: ERROR, type: MISSING_INDEX, object: (table) SAPCRM.VCSMONITOR Please suggest the fix for this. Thanks Shaji

  • TOC highlighting not synched

    Can anyone offer a solution for my problem? When I hit <F1> to open the help from my application, the TOC highlights to the correct Context ID Tag. If I close the help and then <F1> from a different application form, the Help opens correctly, with th