Mail automatically adds certificates to Keychain Access. How to disable?

Is there a way to tell Mail not to automatically store certificates from digitally signed emails (in this case, using Verisign) in Keychain Access?
The problem is this:
When the old certificate expires from someone else, I create a new one, and have them send a signed email to my address. Mail then automatically adds the new certificate to my Keychain Access. I then go into Keychain Access and delete the old certificate, so that I can send secure and encrypted messages to them. However, if I go back to one of their saved OLD emails, it automatically adds the old certificate back to my Keychain Access. And when I go to create a new email to them, it often will use that old certificate, which no longer works for them.
I am looking for a way to better manage this or find out what others are doing out there with the same problem.
Keychain should have an "archive" section to put old certificates into. These then can be referenced to open old secure and encrypted messages, but not allowed to be used for sending new email.

Additionally, lets say something happens to your certificate and you need to download it again. In this case, from Verisign. A problem I have run into is when I go to Verisign, I am presented with the option of re-downloading my certificate. If I do this, there is no way on the Mac system that you specify this re-downloaded is your certificate. So I have to download a new certificate and then re-add my certificate to the rest of the employees and get theirs.
There needs to be an option to select "This is my certificate". Very much like in AddressBook, how you can specify different VCards as your own.

Similar Messages

  • Trying to delete wifi certificate in Keychain Access; continually crashes

    Every time I try to delete my wifi certificate in Keychain Access, it continually crashes.  Tried it in safe mode, still crashes. I cannot get my Airport extreme 5th gen to pass along an IP address to my Mac even though mac is connected to AE (seen via Network Utility). Thought that deleting keychain password would help.
    OSX 10.10.1
    retina Macbook Pro 13

    Launch the Console application in any of the following ways:
    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
    ☞ Open LaunchPad. Click Utilities, then Console in the icon grid.
    Step 1
    For this step, the title of the Console window should be All Messages. If it isn't, select
              SYSTEM LOG QUERIES ▹ All Messages
    from the log list on the left. If you don't see that list, select
              View ▹ Show Log List
    from the menu bar at the top of the screen.
    In the top right corner of the Console window, there's a search box labeled Filter. Initially the words "String Matching" are shown in that box. Enter the name of the crashed application or process. For example, if Safari crashed, you would enter "Safari" (without the quotes.)
    Each message in the log begins with the date and time when it was entered. Select the messages from the time of the last crash, if any. Copy them to the Clipboard by pressing the key combination command-C. Paste into a reply to this message by pressing command-V.
    ☞ The log contains a vast amount of information, almost all of which is irrelevant to solving any particular problem. When posting a log extract, be selective. A few dozen lines are almost always more than enough.
    Please don't indiscriminately dump thousands of lines from the log into this discussion.
    Please don't post screenshots of log messages—post the text.
    ☞ Some private information, such as your name, may appear in the log. Anonymize before posting.
    Step 2
    In the Console window, select
              DIAGNOSTIC AND USAGE INFORMATION ▹ User Diagnostic Reports
    (not Diagnostic and Usage Messages) from the log list on the left. There is a disclosure triangle to the left of the list item. If the triangle is pointing to the right, click it so that it points down. You'll see a list of crash reports. The name of each report starts with the name of the process, and ends with ".crash". Select the most recent report related to the process in question. The contents of the report will appear on the right. Use copy and paste to post the entire contents—the text, not a screenshot.
    I know the report is long, maybe several hundred lines. Please post all of it anyway.
    If you don't see any reports listed, but you know there was a crash, you may have chosen Diagnostic and Usage Messages from the log list. Choose DIAGNOSTIC AND USAGE INFORMATION instead.
    In the interest of privacy, I suggest that, before posting, you edit out the “Anonymous UUID,” a long string of letters, numbers, and dashes in the header of the report, if it’s present (it may not be.)
    Please don’t post other kinds of diagnostic report—they're very long and rarely helpful.

  • Unable to add info to keychain access

    I can't add any items in Keychain Access anymore.  I click on the + sign, type in all my info, click save but nothing is added.  Any ideas on how to fix this?

    Hi,
    This is no error.
    BW opens a new session for you to create this info-package.
    But if you return to your Process Chain you can select your infopackage.
    Udo

  • Deleting certificates in Keychain Access???

    I noticed in my Keychain Acess that I have a slew of certificates which (1) I'm not sure what their purpose really serves and (2) there's a ton of them with names I don't recognize and draws my suspicion.
    What purpose do these certificates serve and what would happen if I deleted them?
    And just to clarify: I'm not talking about my passwords, etc. in Keychain Access. I'm specifically referring to Certificates which I find by clicking on: System Roots and Certificates.
    Thanks for any help.

    If you delete a certificate, the source that gave you the certificate will just offer another one when you authenticate. Certificates are just a way for encrypted connections to establish identity between a client and server. The server will digitally sign a certificate that contains a public key as well as some personal information that's used by the service you're connecting to. Certificates are provided by the service, and can have expiration dates and such.
    Cookies are similar in ways, but they arent as versatile and secure. They're generally used to let your browser keep track of when you last visited a site, perhaps contain a password for the site, and other user settings for a site. Certificates are mainly used for authorizing access to a service.

  • Certificate in keychain access problem

    I have obtained three certificates I have to use to access my corporate exchange server and imported them into the login keychain as directed. They do show up in the "certificates" category of the login keychain but not in the "my certificates" category. This is the category that Entourage looks for when allowing me to select a certificate. As a result, I can't select the certificate I need. Any ideas?

    hi,
    you must import the /system/library/keychain/x509anchors first to your keychain app.
    then use #sudo certtool i zetifikat.cer v k=/System/Library/Keychains/X509Anchors to import it to .../x509anchors. (zertifikat.cer ist your certifikate name) import your certificate (in pem-format) to your keychain. if not in pem-format convert it with ms cert manager (in the office folder of the office app). apply alway trust to the certifikate in keychain.
    cheers
    jens

  • Mail receives mail automatically when I open it. How do you stop this?

    I have set up my Mail to "Check for new mail manually" in preferences. However it checks for mail when I start the program. I'd rather it not and make it a totally manual process.
    Is there any way to stop it?. Thanks!

    Are you sure the account is checked for new mail?
    A .Mac type account is really an IMAP type account so any mailboxes stored on the server (under the .Mac account icon in the mailboxes drawer) are automatically synchronized with the server when first launching Mail and connected to the internet if the account is enabled under the Advanced tab for the account preferences.
    I have 3 POP type accounts, a .Mac account and 2 IMAP type accounts. As a test, I deselected "Include when automatically checking for new mail" for all accounts and then quit and re-launched Mail. None of my accounts checked the incoming mail server for new mail but all server stored mailboxes for my .Mac account were synchronized with the server.

  • Automatic add Critical Patches to baseline (how)

    Hi There,
    I'm busy with configuring our patchmanagement in zcm 10.2.2.
    I'm working with the dynamic devicegroup "windows xp workstations", and there i can add patches to a baseline.
    But, Where can i configure that all critical updates (from vendor Microsoft) must be automatically added to the baseline? (or all criticals from all vendors).
    I don't have much options, I want the same as in Windows update server (that we use before, and at the moment). So i don't have to look each day what new critical patches are in the list and have to manual add them!
    Hope somebody can give me the answer.
    Cheers,
    Tristan

    floort,
    It appears that in the past few days you have not received a response to your
    posting. That concerns us, and has triggered this automated reply.
    Has your problem been resolved? If not, you might try one of the following options:
    - Visit http://support.novell.com and search the knowledgebase and/or check all
    the other self support options and support programs available.
    - You could also try posting your message again. Make sure it is posted in the
    correct newsgroup. (http://forums.novell.com)
    Be sure to read the forum FAQ about what to expect in the way of responses:
    http://forums.novell.com/faq.php
    If this is a reply to a duplicate posting, please ignore and accept our apologies
    and rest assured we will issue a stern reprimand to our posting bot.
    Good luck!
    Your Novell Product Support Forums Team
    http://support.novell.com/forums/

  • Exporting auto-created SSL Certificate using Keychain Access

    Whenever I try, I get:
    "An error has occurred. Unable to export item.
    You fail to provide the necessary administrator authorization."
    Can it be done?

    Got the same problem. It's a mystery to me as well. Happens both at my SL server 10.6.2 at home and at work. I have no idea what is wrong except that it might forget to prompt me. It also doesn't work if I unlock the certificate keychain first.

  • What should I do with duplicate of certificates in keychain access?

    Is it safe to delete duplicate surtificates in keychain or just wait tell it expires?
    (New to mac 1 month)

    Apple will exchange your iPod for a refurbished one for $199 for a 64 GB one and $99 for the others.. They do not fix yours.
    Apple - iPod Repair price              
    A third-party place like the following maybe less. Google for more.
    iPhone Repair, Service & Parts: iPod Touch, iPad, MacBook Pro Screens
    Replace the screen yourself if you are up to it
    iPod Touch Repair – iFixit

  • ITunes screen automatically scrolls to show current song - how to disable?

    Whenever a song starts playing in iTunes the screen instantly scrolls to show the song details. This is very annoying when browsing the library while listening to music as you have to scroll back to the spot you were at each time a new song starts.
    Is there a way to disable this pointless 'feature'?

    Here is an update. Actually what is happening, is the view of the album (in the top with the pictures of the albums) switches to what is playing after a few seconds of inactivity, and the list of songs below that stays where I left off. But when the song is over, the list also switches to the new song that is playing. How do you keep this from happening?

  • Access - How to create Mail Address only list?

    Printing envelopes from mail lists - via Microsoft Excel? Access - How to create Mail Address Only list?
    Bearing my "new boy" status, step by step instruction would be appreciated.

    Hi
    This is a question only about the Microsoft products and has nothing to do with Toshiba notebooks but I have investigated a little bit in the net and found this useful sites:
    http://support.microsoft.com/kb/q141991/
    https://www.nahu.org/member/using%20excel%20to%20create%20lists%20and%20labels .pdf

  • How can I bypass Automatically Add to iTunes?

    I have a large CD collection (>3000) that I've ripped to iTunes in ALAC format; I only listen to CD or better quality music, so I don't have any mp3 or AAC files in my iTunes library. I keep my music on an external hard drive. I recently bought a larger external hard drive and moved all of my music to that drive. For some reason, iTunes chose to put all of my music in a folder called "Automatically Add to iTunes". This was fine, except that I could no longer see the contents of the hard drive; however, I did know that the files were there, becasue of the disc space that they consumed.
    Today, I ripped two new CDs to the hard drive through iTunes and I noticed that iTunes placed the music folders for those CDs outside of the "Automatically Add to iTunes". I decded to drag the new folders into the "Automatically Add to iTunes" folder. When I did so, all of the previous music disappeared and I cannot recover it. Fortunately, I have a copy of Sentuni, so I'll be able to put the music back on the hard drive from my iPods, but this process will require several hours. In addition, ripping my CD collection to iTunes required a lot of time, so I'm not pleased with the "Automatically Add to iTunes" folder feature. Is there a way to disable this feature, so that I can simply put my music on my external drive and be able to see that the folders are there.
    I've been a devoted Apple customer for almost a decade, so I won't get too upset over this issue, but I wish that your developers would have addressed this issue during the development stage. Thanks for your attention to this problem.
    Best,
    Heath

    Heath Watts wrote:
    If only this were the case. I tried to move several albums into the "Automatically add to iTunes" folder, which resulted in thousands of albums being erased from the folder. One should be able to drag a music folder into the "Automatically add to iTunes" folder without iTunes erasing the original contents of the folder.
    It didn't erase anything.
    It automatically added them to iTUnes and moved them to the correct folder (Movies, Music, etc.) in the location shown in iTunes prefs > Advanced - iTunes media folder location.
    I would like to disable the "Automatically add to iTunes" feature in iTunes,
    You "disable" it by not putting anything into it. If you don't want to use it, don't use it.
    If you want to manually manage, do not put anything into this folder.
    Go to iTunes prefs > Advanced and uncheck Copy files to iTunes media folder when adding to library.
    Then File > Add to library adn select what you want to add to iTunes. Do NOT put anything into the Automatically add to iTunes folder
    and would like to be able to see the albums and artists on my external hard drive without having to do Spotlight searches
    You wouldn't have to do Spotlight searches anyway.
    The files are in /Music/Artist/Album folderin the location shown in iTunes prefs > Advanced - iTunes media folder location.
    Also, in iTunes, you can select a song, right click - Show in Finder.

  • Certificate for wifi access

    I am trying to connect to my company's wireless network which uses WPA Enterprise. I need a certificate which our network admin has given me a copy of but I cannot choose it in the connection dialog. It only shows the certificates which are contained in the category "My certificates" in Keychain access. It only contains my .mac certificate. I have imported the necessary certificate into Keychain Access and added it to my login keychain + also X509Anchors but I can see no way to add it to "My certificates". Can anyone help me?

    I decided to upgrade to Leopard to test this out but I still cannot make it work. I click on "Get certificate" but nothing happens. There are some things I am unsure about.
    1. The protocol to use. Our network administrator says the protocol should be EAP, not EAP-FAST, PEAP or LEAP which are the choices in OS X.
    2. The domain to use. I guess it has to be "Login window" as this is the only domain to include a certificate but see next point
    3. When using the "Login window" domain it says that it logs into the wireless network when I log into the Mac and using the same user name and password I use to log in to the Mac. The problem is that my local user name is not the same as the user name I use to log in to the network. Maybe this is the sole reason why it still fails. When I click "Get certificate" I have to submit a user name and password and then I use my network user name but it doesn't work. Is there a way to have the user names be different? If not is it safe to change my short user name on the Mac?

  • Safari keeps asking for Keychain Access

    Everytime I use Safari after some time it asks for Keychain access. I disabled the autofill forms feature already, but it does not stop asking. Does anybody know how to keep Safari from doing this without disabling the password protection of my keychain?
    Honestly said, this erraneous behaviour keeps me from using Safari as Firefox does not make such strange attempts to use Keychain.

    I didn't think before reading this discussion to be related, but now I tend to believe it may be. I've recently started using Papers.app and to get access to some publications under institutional subscription I have to configure both Papers.app and Safari to be authenticated connecting to Internet through my institution's proxy. The problem is that now the keychain access manager keeps asking authorization every now and then what really has become a heavy nuisance, not only occurring while a keep Safari open, but also while using any other application which try to connect to the Internet such as iTunes or Fission.app. Before I started using Papers.app I had devoted one browser to download articles nder subscription in order to limit such nuisance to the time I was browsing them. However, using Papers.app I've been forced to configure Safari to that purposes, reproducing the annoying effects every time I open any application which are connecting to the Internet. I posted a message in the Papers.app but nobody has replied so far. I thought of changing the browser used by Papers.app would help, unfortunately, I couldn't find any way to get so. Now that it seems there is a way to prevent the system from asking for keychain access, it may fix the problem. This is the message I posted in Papers' Support Forum. I'd really appreciate any help or suggestion:
    Can Papers.app use a different browser other than Safari to get authentication from my institution's proxy?
    I am at the University of Barcelona (UB), Spain, we also have an automatic proxy-cache configuration URL (like johnraekwon at the U of Manchester)
    http://www.bib.ub.edu/pac/proxy.pac
    Every time I open the browser I've configured to connect through your University proxy, I get a drop down menu to authenticate with and then I proceed to the URL I head to, only now with UB credentials. More or less like johnraekwon has to do.
    Unfortunately this aunthentication doesn't last for long, you are often requested to authenticate again and again. This nuisance made me decide to devote a browser different from the default browser to download articles, and it's being working rather satifactorily while I only used that browser to download papers from the Internet.
    Now that I tried configuring Papers.app to download those articles which requiring subscription I've found that it only works as long as Safari is configured in the same way, that is, it has to authenticated by the proxy to get access to the Internet. I wouldn't mind using Safari exclusively to browse papers. The problem is that most other applications are also using Safari as default browser and it doesn't seem it can be changed, among them iTunes, which I usually open to download podcasts. Since I've configured Safari to get access through my institution's proxy, it keeps asking me to authenticate, and halting every task in process by doing so.
    For most purposes I don't need to get authorized access, so I wish my default browser not being configured in such a painful manner.
    I'd like to know whether I can change some of Papers.app options to replace Safari as default browser by, I say, Firefox, therefore limiting those repetitive authentications to just the time I'm browsing papers. It let Safari idle to be configured as a default browser to smoothly work for other purposes such as iTunes.
    Thanks for the interest. Any idea will be welcomed.

  • Mail & Mavericks & Keychain Access

    Hello,
    After updating to Mavericks (from Mountain Lion), I noticed that there's a new keychain called "local items" inside Keychain Access App.
    so I have a couple of questions regarding this and my usage of Mail:
    1) from what I read in this forum, "local items" is the keychain created by Mavericks, it should sync to the login keychain (which is usually, and certainly in my case, the default keychain, meaning it is in bold face on the left hand side of the Keychain Access window). And as far as I understand, if you have icloud enabled, this keychain would be called "icloud keychain", if not, it will remain the name "local items", is this correct? I do not want to have anything to do with icloud, so I don't have any icloud keychain. When I log into the my account on the mac both the login and the "local items" keychain are unlocked (I guess this makes sense if they are supposed to be synced. So basically this is my understanding of this "local items" keychain, please correct/inform me if this understanding is not correct.
    2) now, I noticed that the passwords that I typed in for my e-mail accounts (set up in Apple's Mail) are saved inside this "local items" keychain. So everything seems to be fine. However, I noticed that the passwords saved inside this "local items" keychain cannot be edited in the "access control" panel (this is accessed by double clicking the password item and click on the "access control" tab.) This is odd because all the other items in the "login" keychain can be edited in this way.
    3) so my main goal is to ask Mail to NOT remember my password (I know this is not the prefer setting for most users, but I prefer to have it this way). In Leopard, Mail had a little checkbox where you set up your account that asks the application to NOT remember the password. This is really handy because it prompts me to re-enter the password whenever I restart the application, which is exactly what I want it to behave. But since upgrading to Mountain Lion (I'm not sure how it is in Snow Leopard or Lion, as I jumped from Leopard straight to Mountain Lion, and now to Mavericks), this box has disappearred. I found a work around online. Before Mavericks, the mail account passwords are saved (if I remember correctly) in the login keychain, the work around works by saving (i.e. dragging) all your email  passwords into a separate/new keychain (let's call it Keychain A) which has a different password than your login keychain (which, by definition, is unlocked upon login). So I set this up and Mail automatically knows to prompt me to enter the password for Keychain A in order to access my e-mail account passwords. This doesn't behave exactly like unchecking "remember the password" box in Leopard, but it comes close. and I was happy with this work around. However, now having upgraded to MAvericks, Mail insisted on using "local items" as keychain, and keeps asking me the passwords for my e-mail accounts (NOT the  local item keychain password, since my local item keychain IS synced up with Login keychain, therefore they are both unlocked upon me logging in) so that it can store them. The thing is I do NOT want the e-mail passwords to be stored inside "local items" keychain (because I don't want account access to equal e-mail access (for reasons I do not want to get into, but I feel like this is not too much to ask and was possible before so why not now?).
    Could someone please help me out with this?  I've called Apple, and they were quite annoyed with me because the person I talked to keeps saying that I'm not using keychain for the way it is suppoed to be used, but my question then, is, if I canot get applications to use special keychains I set up, what's the use of the function "add new keychain" inside keychain access?  (in fact, the phone supporter basically keep saying "I don't know" to my questions and finally offered me to talk to a senior advisor, at that point I had to leave (and after 1hour on the phone I was quite fed up anyway). so I thought I should turn to the forum.....
    so a recap/summary:
    my login and local items keychain sync up fine
    but I don't want Mail to store my e-mail passwords in the local items keychain
    I want to make Mail use another keychain (i.e. a keychain I set up myself), can we possible to this?
    or another other work around that will make Mail to prompt me to enter passwords when I fire up the application (not constantly, but just when I restarting the application, OR after the computer wakes up)
    I'd appreciate any pointers!
    thank you very much!
    sakura

    I have the same concerns.  I'm frustrated that the Mail app doesn't currently allow you to use a separate keychain for the passwords.  After many years with Keychain I am being tempted to look to a third party.  Or perhaps it's time to look for a third party mail app?  This is a security issue since email is the primary way that a password change is verified with other accounts. 

Maybe you are looking for

  • My iPod Touch 5 Will Not Turn On... At All.

    My iPod touch 5 will not turn on. It's not that it's dead, nor that I turned it off. I left it on, wrapped my earbuds around it, plunged it into my backpack and headed out... In the rain. I had an otterbox case on it too. I come home, leave it to chi

  • Best Practise to handle Data Refresh & Hierarchy

    Hi, During a recent discussion with one of our BI user groups, the questions were raised as what the best practice are to handle the following two issues. Issue 1: If entries are posted to the prior periods in SAP R/3 (outside of the daily auto-refre

  • Create an image and text rollover in Dreamweaver?

    I'm wanting an image and text to have a link and then the image and text to change to another image and text automaticly.  Here is a link that I want it to look like.  (local hot spots) Is there a way in Dreamweaver to do it or by inserting HTML code

  • Anyone having issue with email notification delay in ES4?

    After upgrade from ES2 to ES4, we're experiencing an email notification delay when a task is assigned to an individual or group queue. It's not consistent, but happen enough that we can some what replicate it. It's almost like an email notification f

  • How do I install and work the speaktext for ebooks app?

    I just downloaded the speaktext for ebooks, and I'm haveing a hard time understanding the instructions. I want this app to read the book while I'm doing something else.