Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Software - Troubleshooting and Discussion > Mac OS X > Safari HTTPS Problem with thawte certificate

Safari HTTPS Problem with thawte certificate
Thread Tools
jjj
Fresh-Faced Recruit
Join Date: Feb 2004
Location: Germany
Status: Offline
Reply With Quote
Mar 26, 2004, 05:02 PM
 
Hey Folks,

I got a serious problem with a special https server...

It's certificate is signed by thawte...
thawte's CA certificates are included in Panther's shipping keychains.

Nevertheless, if I try to access https://bds.mercedes-benz.com/
safari tells me that it's unable to establish a secure connection.

So I tried getting the cert with openssl :

openssl s_client -showcerts -connect bds.mercedes-benz.com:443

with the following "success" :

CONNECTED(00000003)
depth=1 /C=ZA/ST=Western Cape/L=Cape Town/O=Thawte Consulting cc/OU=Certification Services Division/CN=Thawte Server CA/emailAddress=server-certs@thawte.com
verify error:num=19:self signed certificate in certificate chain
verify return:0
30531:error:1408F455:SSL routines:SSL3_GET_RECORD:decryption failed or bad record mac:s3_pkt.c:424:



So I tried some variation :

openssl s_client -ssl3 -connect bds.mercedes-benz.com:443

now with 'normal' success!

So... why is it working with ssl3, but not with v2.... strange.


Well.... why does safari have such a great problem with this page that it doesn't even
ask whether to continue or not ?

I also tried enabling the debug menu and activating lax certification checks... no success at all!


Summary :
- Safari has access to system wide keychains
- Thawte's certificates are included in these keychains
- openssl does only work with ssl3 ???
- Safari just denies access to the page.

Any helpful ideas ? Further thoughts ?
Is it a problem of safari's SSL implementation ? Or is it a problem of this website ?

BTW: IE and Mozilla are working flawlessly !

Thanks for every useful idea !
     
Dedicated MacNNer
Join Date: Mar 2002
Status: Offline
Reply With Quote
Jan 1, 2005, 08:47 PM
 
I have the exact same problems with https and safari. I'm running 10.3.7.
http://winlab.csbnet.se Visit the Mac Demo Scene.
     
Mac Elite
Join Date: Aug 2001
Status: Offline
Reply With Quote
Jan 1, 2005, 09:26 PM
 
No idea if this is related, but one machine I have access too has started having pretty much *every* site with a certificate pop up a warning saying it's expired. Any ideas on why/what to do about it? (This is mostly Camino, but I believe I checked Safari as well)
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 09:17 PM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2