Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Software - Troubleshooting and Discussion > Mac OS X > Tiger and Certificates (security)

Tiger and Certificates (security)
Thread Tools
Professional Poster
Join Date: Sep 2000
Location: San Francisco
Status: Offline
Reply With Quote
Apr 30, 2005, 01:59 PM
 
Can someone provide a decent explanation of how the Tiger Keychain handles certificates? Although they provide a nice assistant, much of the jargon is confusing. I would like to have certificates for each of my email accounts so that I can send signed and encrypted emails. How do I go about this?

Also, I noticed that the assistant can generate a certificate authority. Does this mean that anyone can become an authority? What are the practical implications of this?

kman
     
Professional Poster
Join Date: Oct 2002
Location: Off the Tobakoff
Status: Offline
Reply With Quote
Apr 30, 2005, 02:01 PM
 
Yeah, I'd like some help here, as well. Though I've added the Mail security certificates to my keychain, I can't seem to find the option to add these signatures to outgoing mails. In 10.3, once I added the certificates, outgoing mail was secured by default.
"You rise," he said, "like Aurora."
     
kman42  (op)
Professional Poster
Join Date: Sep 2000
Location: San Francisco
Status: Offline
Reply With Quote
Apr 30, 2005, 02:03 PM
 
Did you just create your own using Keychain or did you use Thawte (or some other service) and import them? Can you use thawte through the keychain assistant?

kman
     
kman42  (op)
Professional Poster
Join Date: Sep 2000
Location: San Francisco
Status: Offline
Reply With Quote
Apr 30, 2005, 02:16 PM
 
The certificate assistant Learn More button says, "you can obtain a personal certificate from .Mac". Anyone know how to do that?
     
Professional Poster
Join Date: Oct 2002
Location: Off the Tobakoff
Status: Offline
Reply With Quote
Apr 30, 2005, 02:28 PM
 
Originally Posted by kman42
Did you just create your own using Keychain or did you use Thawte (or some other service) and import them? Can you use thawte through the keychain assistant?

kman
I used Thawte; I downloaded them again and they imported into Keychain Assistant automatically. I, however, cannot find the option to use them in Mail. I've sent myself test messages and the certificates are not embedded.
"You rise," he said, "like Aurora."
     
kman42  (op)
Professional Poster
Join Date: Sep 2000
Location: San Francisco
Status: Offline
Reply With Quote
Apr 30, 2005, 02:32 PM
 
Did you use Firefox or does Safari now work? My thawte certs expired about a week ago and I was holding off renewing them since I had heard Tiger would contain cert generation support.
     
Professional Poster
Join Date: Oct 2002
Location: Off the Tobakoff
Status: Offline
Reply With Quote
Apr 30, 2005, 02:38 PM
 
Originally Posted by kman42
Did you use Firefox or does Safari now work? My thawte certs expired about a week ago and I was holding off renewing them since I had heard Tiger would contain cert generation support.
Safari. I used Safari in 10.3 and it worked also.

Here are some examples:
http://www.entourage.mvps.org/smime/req_safari.html
"You rise," he said, "like Aurora."
     
kman42  (op)
Professional Poster
Join Date: Sep 2000
Location: San Francisco
Status: Offline
Reply With Quote
Apr 30, 2005, 03:06 PM
 
I just created a new cert through thawte and downloaded it using safari. It opened in keychain and then I was able to send an email to myself using the cert to sign it. I didn't have to do anything to add it to the account; mail just picked it up automatically.

kman
     
Professional Poster
Join Date: Oct 2002
Location: Off the Tobakoff
Status: Offline
Reply With Quote
Apr 30, 2005, 03:19 PM
 
Originally Posted by kman42
I just created a new cert through thawte and downloaded it using safari. It opened in keychain and then I was able to send an email to myself using the cert to sign it. I didn't have to do anything to add it to the account; mail just picked it up automatically.

kman
Hmmm...I wonder why it didn't work for me. Can you show me a screenshot of the signed part of the email and the compose window?
"You rise," he said, "like Aurora."
     
kman42  (op)
Professional Poster
Join Date: Sep 2000
Location: San Francisco
Status: Offline
Reply With Quote
Apr 30, 2005, 04:56 PM
 



I can't seem to get the encryption to work though. I'm sending the email to myself at another account and it says I don't have the public key even though I just got the cert for that acct and can send signed emails from that account. And the cert is present in Keychain.
     
Mac Elite
Join Date: May 2001
Location: Vancouver
Status: Offline
Reply With Quote
Jun 2, 2005, 01:37 AM
 
My existing certs were moved over when I copied over my keychain and I was also able to renew one of my mail certs through Thawte no problem.

Didn't catch the bit about .mac at first but I imagine that Apple will soon be adding that (hopefully for free) infrastructure into the .mac system so that all subscribers can easily sign mail.

The Create a CA part is probably just a GUI for the tools that were already included in 10.3 (I did a writeup for macosxhints a while back on setting up a private CA for enabling SSL for your webserver).

Good to see Apple getting around to these bits.
Macbook (Black) C2D/250GB/3GB | G5/1.6 250GBx2/2.0GB
Free Mobile Ringtone & Games Uploader | Flickr | Twitter
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 12:27 AM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2