Safari no longer works with SSL self-signed certificates?

With the last Safari (9.0.3) on OS X (running 10.11.3) and iOS (9.2.1) operating system, I can no longer connect to sites that use self-signed SSL certificates. Previously, I was warned that the site certificate was not "valid", but given the opportunity to continue anyway. This is the behavior I want to come back. It still works fine in Chrome, Firefox. but now just Safari gives me an error "Safari can't open the Page" as it would if it could not reach the server. Specifically, it says "Safari can't open the page https://myselfsignedhost.com because Safari is unable to establish a connection to the server myselfsignedhost.com.

It does not give me the opportunity to inspect the certificate, add the certificate to my keychain, trust the cert, ignore the warning once or anything else that would be useful... He's just pretending like it can't connect. Am I missing something? How to restore old functionality? This 'bug' makes safari completely useless for me.

OK, some info... This seems to apply only to SOME sites with self signed SSL CERT... The only obvious thing I can think is that maybe it applies to sites where the SSL certificate when the page was first loaded?

If I open a new window private, I can access the page without problem. If I open a new standard, I can also open the page, until I quit safari. Once I left, it stops loading with the same error...

If I manually add the SSL certificate to my keychain as being approved, the page also works... There may be a cache of certificate somewhere that is out of date?

Tags: Mac OS & System Software

Similar Questions

  • Can I put OS Lion directly to El Capitan without an intermediate upgrade. I have a MacBook Pro late 2011. Safari no longer works on a lot of web content with this OS not.

    Can I put OS Lion directly to El Capitan without an intermediate upgrade. I have a MacBook Pro late 2011. Safari no longer works on a lot of web content with this OS not.

    Yes.

    (143974)

  • Faced with Windows 2008 R2 PKI, self-signed certificates & view iPad customer Secure Authentication to view connection server: UGH!

    Background: I was instructed to create a VMware View isolated laboratory test so that HIGHER-UPS can see how they could access the VM dedicated as well as how their developers could put related clones on-the-fly. The project was successful! Yay!

    Addendum: A boss wants to see how VMware View works when accessing his computer virtual dedicated via his iPad on the internet... And who needs a secure SSL connection.

    The problem is: the domain name I chose casually because the lab did not belong to me... So I can't have a real certificate from a trusted commercial certification authority.

    So I'll try to roll my own public Windows 2008 R2 PKI and... All that forcing the iPad to use DC/DNS server in the lab... Get only the single get iPad trust view connection server by importing a sort of certificate.

    Can I export/import a certificate of the CA of DC to the iPad via an attachment... And it happens with confidence. But how to create a login to view the server certificate and electronic-mail/import in the iPad so it happens with confidence? Whenever I try to export the certificate of the certificate of the view connection server store, send it to the iPad and install... The connection server certificate appears as 'not reliable' and the VMware View client will not connect.

    (Of course, I could get sloppy and set the iPad Client to accept untrusted connections... "But I want to solve the problem of approved connection).

    I could be missing something royally on the self-signed certificates and certificate chains.

    (It is a first for me dealing with Active Directory Windows Certificate Services. In the past, I always just installed expensive commercial SSL CA certificates in the certificates Windows Server stores before.)

    Any help or direction, you can provide would be appreciated. I'm rather confused.

    See you soon!

    Keegan

    Hello

    Maybe was your initial problem that the provided certificate must be a descendant of a trusted root, such as Verisign cert or

    the root certificate must be installed and all the intermediate certificates in the trust chain down to the one you use?

    Concerning

    AndyR

  • cannot install self-signed certificates sbs2008 on Vista SP2 with IE8

    I use SBS2008 Setup and it is to use self-signed certificates,

    My laptop is Windows Vista SP2 with IE8.

    When I try and connect to my OWA SBS2008 Web site, I get this error: there is a problem with this site's secure certificate.

    I tried to solve my problem with this solution: http://blogs.technet.com/b/sbs/archive/2008/05/08/installing-a-self-signed-certificate-as-a-trusted-root-ca-in-windows-vista.aspx , don't worry! In date; May 8, 2008

    I also looked at: http://support.microsoft.com/default.aspx?scid=kb; EN-US; 932156 , dated; November 19, 2008

    This link is on the page above: download the update for Windows Vista (KB932156) package now. , dated March 24, 2008. I understand that all of the above links are ment to work with Vista & IE7, there is no mention of the Service Pack level.

    This patch really works on Vista SP2 with IE8 or do I have to change the registry and if so, this key is always the right pair?

    HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ProtectedRoots

    Thank you

    Hello

    Questions like these are much better handled in the TechNet IT Pro Forums.

    My moderator tools cannot transfer messages on Windows forums, please re - ask you question there.

    http://social.technet.Microsoft.com/forums/en-us/itprovistanetworking/threads

  • Configure SSL for OUD 4444 port Admin port-> replace the self signed certificates used

    Hi Experts,

    When installing OUD choose Certification self-signed for ports 1636 and 4444.

    Later I change the certificates used by the port of 1636 to a new key file containing the CA certificates. (Track the steps of: https://docs.oracle.com/cd/E52734_01/oud/OUDAG/security_clients_severs.htm#OUDAG00050)

    But same procedure does not have to replace the self signed certificates used by ports 4444!  Everyone is configured SSL (with Cert CA) on the Administration port?

    I couldn't even start the servers, you see an error:

    """

    category = gravity CORE = NOTICE msgID = 458891 msg = the directory server sent a notification to alert generated by the class org.opends.server.core.DirectoryServer (org.opends.server.DirectoryServerShutdown alert type, alert ID 458893): the directory server started the shutdown process.  Stop was launched by an instance of the org.opends.server.core.DirectoryServer class and the reason for the closure was an error occurred trying to start the directory server: NullPointerException (File.java:277 AdministrationConnector.java:843 AdministrationConnector.java:675 AdministrationConnector.java:182 ConnectionHandlerConfigManager.java:356 DirectoryServer.java:2932 DirectoryServer.java:1584 DirectoryServer.java:10108)

    «[27/sep / 2015:06:22:53-0400] category = gravity = NOTICE msgID = 458955 msg = the directory server CORE is now stopped "«»

    Post edited by: 1976902

    Sorry, I cannot help here - here are a few possibilities.

    Change connector Administration certificate

    https://docs.Oracle.com/CD/E52668_01/E54669/HTML/ol7-genssc-auth.html

    The failure of the handshake could occur for various reasons:

    • Incompatible encryption suites in use by the client and the server. This would require the customer to use (or allow) a suite of encryption supported by the server.
    • Incompatible versions of SSL in use (the server can only accept TLS v1, while the client is capable of using SSL v3 only).
    • Incomplete trust for the certificate of the server path
    • The certificate is issued to another area.
    • incomplete certificate trust path between the certificate for the server, and a certification authority root.
    • In most cases, this is because the certificate is not present in the trust store
  • Cannot use jar with icon files gif and self signed certificate files (Exception in thread "AWT-EventQueue-3" java.lang.NoClassDefFoundError: oracle/ewt/laf/basic/SelColorChange)

    Hi all.

    I use Forms 11 g 11.1.2.1 and updating JRE 7 45.

    I have create a jar file containing gif icons files using this procedure:

    (1) create the jar file:

    set path = % path %; C:\Oracle\Middleware\Oracle_FRHome1\jdk\bin (my ORACLE_HOME/jdk)

    jar - cvf webfigolos.jar *.gif

    (2) self sign the file:

    c:\Oracle\Middleware\asinst_1\bin > sign_webutil.bat c:\Oracle\Middleware\Oracle_FRHome1\forms\java\webfigoicons.jar

    Jars is signed but with a warning:

    Generate a signature key certificate aaosa2015 = auto...

    keytool error: java.lang.Exception: key pair not generated, al alias < aaosa2015 >

    loan is

    .

    There are errors or warnings while generating a self signed certificate. Pleas

    e revisiting.

    .

    Backup as c: C:\Oracle\Middleware\Oracle_FRHome1\forms\java\webfigoicons.jar

    \Oracle\Middleware\Oracle_FRHome1\forms\java\webfigoicons.jar.old...

    1 file (s) copied.

    Signature using ke c:\Oracle\Middleware\Oracle_FRHome1\forms\java\webfigoicons.jar

    y = aaosa2015...

    .. own made.

    But I can use this file. The application crashes and get this error from the java console:

    network: connection http://myluism-pc:7001/forms/lservlet; jsessionid = p98GTL5Fh6XnQcykySBhLWq2823HwHlPGZ16TYHVv93006N4mmdl!-947562687 with proxy = LIVE

    network: connection http://myluism-PC:7001 / with proxy = LIVE

    Exception in thread "AWT-EventQueue-3" java.lang.NoClassDefFoundError: oracle/ewt/laf/basic/SelColorChange

    at oracle.ewt.laf.oracle.OracleTreeUI.createItemPainter (unknown Source)

    at oracle.ewt.laf.basic.BasicTreeUI._getItemPainter (unknown Source)

    at oracle.ewt.laf.basic.BasicTreeUI.getItemPainter (unknown Source)

    at oracle.ewt.dTree.DTreeBaseItem.getSize (unknown Source)

    at oracle.ewt.dTree.DTree.paintCanvasInterior (unknown Source)

    at oracle.ewt.EwtComponent.paintInterior (unknown Source)

    at oracle.ewt.lwAWT.SharedPainter._paintInterior (unknown Source)

    at oracle.ewt.lwAWT.SharedPainter.paintExtents (unknown Source)

    at oracle.ewt.lwAWT.LWComponent._paintComponent (unknown Source)

    at oracle.ewt.lwAWT.LWComponent.paint (unknown Source)

    at oracle.ewt.EwtComponent.paint (unknown Source)

    at oracle.ewt.lwAWT.SharedPainter.paintExtents (unknown Source)

    at oracle.ewt.lwAWT.LWComponent._paintComponent (unknown Source)

    This used to be a very simple procedure, but it has stopped working...!

    Don't know if the jar file is well born, or if it is corrupt.

    I can't start my application.

    Help, please!

    Best regards, Luis.

    Try again with the JRE 7 10 update, I get a problem with the update of JRE 7 45, but when I tried the update of JRE 7 10, it works fine.

    For the objective test, disable the check

    Java Panel-> advance-> mixed Code-> disable verification (unchecked)

  • RTMPS with self-signed certificate

    Hello

    I have a simple Webcam movie, publish live video
    FMS 2.0.2 r51 dev under Debian 3.1r2 edition
    and then he plays in another video-window.

    It works very well and rtmp, rtmpt, but with rtmps I get
    the error "NetConnection.Connect.Failed".

    I have prepared a simple and all assembled test scenario
    info here: http://pref.dyndns.org:8080/live/live.html

    The certificate has been created by me in this way:
    openssl req - x 509 - days 365 - newkey rsa:1024.
    -self-signed - certificate.pem - keyout pub-sec-.pem

    And implement defaultRoot_/Adaptor.xml:
    "< name HostPort ="edge1"ctl_channel =": 19350 ">: 1935, 80,-443 < / HostPort >"
    ... jumped...
    /Home/afarber/certs/self-signed-certificate.PEM < SSLCertificateFile > < / SSLCertificateFile >
    < SSLCertificateKeyFile type = "EMP" > /home/afarber/certs/pub-sec-key.pem < / SSLCertificateKeyFile >
    secret of < SSLPassPhrase > < / SSLPassPhrase >
    < SSLCipherSuite > ALL:! ADH:! BASS:! EXP:! MD5:@strength < / SSLCipherSuite >

    I'm sure that the server works as I see in the var:
    localhost adapter [2675]: listener started (_defaultRoot__edge1): 443 (secure)

    I also tried to put
    Import mx.remoting.Service;
    Import mx.services.Log;
    Import mx.remoting.debug.NetDebug;
    NetDebug.initialize ();

    at the top of my AS code, but the NetConnection debugger
    window displays no information at all, for some reason any:
    http://pref.dyndns.org:8080/live/NetDebug-empty.gif

    Concerning
    Alex

    I found the solution-

    There is a bug in the current Flash Player:
    If a pop-up window of dialogue for a reason any
    (as unknown CA or not is not host name)
    then the cert will be rejected even if you
    Click 'yes '.

    If you are generating a cert self-signed like this:

    OpenSSL genrsa-des3-out ca.key 4096
    openssl req - new - x 509 - days 365 - key ca.key - out ca.crt

    OpenSSL genrsa-des3-out server.key 4096
    openssl req - new - key server.key - out server.csr

    OpenSSL x 509 - req-days 365 - in server.csr - CA ca.crt - CAkey ca.key - set_serial 01 - out server.crt

    (increase the 01 above for each new cert).

    and then import the ca.crt from above in your
    browsers (i.e. double-click on Windows for IE
    Open from Mozilla Firefox and click OK).

    Concerning
    Alex

  • e-mail no longer works with firefox

    Yahoo mail no longer works with firefox. but there is no problems with yahoo mail when I use chrome. This problem started a week ago. today is 02/07/15

    You can try the following steps in case of problems with web pages:

    You can reload webpages and ignore the cache to refresh potentially stale or corrupt.

    • Hold down the SHIFT key and click the Reload button
    • Press 'Ctrl + F5' or 'Ctrl + Shift + R' (Windows, Linux)
    • Press 'Command + shift + R' (Mac)

    Clear the cache and delete cookies only from Web sites that cause problems.

    "Clear the Cache":

    • Firefox/tools > Options > advanced > network > content caching Web: 'clear now '.

    'Delete Cookies' sites causing problems:

    • Firefox/tools > Options > privacy > "Use the custom settings for history" > Cookies: "show the Cookies".

    Start Firefox in Safe Mode to check if one of the extensions (Firefox/tools > Modules > Extensions) or if hardware acceleration is the cause of the problem.

    • Put yourself in the DEFAULT theme: Firefox/tools > Modules > appearance
    • Do NOT click on the reset button on the startup window Mode safe
  • iPod nano no longer works with headphones Bose

    My fairly new nano iPod no longer works with one of my headphones Bose (Bose sport & Quietcomfort) - the iPod no longer meets the headset controls. I know it's the iPod that has a problem that the headphones still work with my phone.

    If you haven't already, do a Reset (reboot) on the iPod

    Learn how to reset your iPod - Apple Support

    If this does not help, he can you want to do a restore of the iPod using iTunes.  This erases the iPod, reinstall its software and sets it to the default settings

    Use iTunes on your Mac or PC to restore your iPhone, iPad or iPod settings - Apple Support

  • Norton Security no longer works with Firefox update, if I'm afraid to use it. I want safety navigation

    According to my info in Firefox I have Firefox 15.0.1 & it is up-to-date.
    I can no longer use Firefox with all my saved bookmarks and familiarity that Norton Security programs I got Comcast no longer work with Firefox. Whenever I use it, it says that my safety is compromised. I don't have any protection. Currently I use internet for purchases, that I count on privacy and security, so I now use Sarari, which I don't like at the well.

    Using Firefox, I Googled, found the info that says everything I need to do is to upgrade my Norton with Live Update and then restart Firefox. Do it, but it doesn't help, still has the same lack of protection.

    See [935636/questions/935636] [MAC] norton does not support firefox 15

  • ASA SHA2 support with self-signed certificates

    Is it possible to use the signature SHA2 algorithm generating a certificate self-signed on an ASA? I can't find any documentation on orders that have control of things like the signature algorithm when you use self-signed certificates. I have seen documentation SHA2 is supported from 8.4.2 for the signature algorithm, but it always refers to the import of a certificate from an external certification authority.

    Hi William,.

    You can only generate self-signed certificate on the SAA SHA1. The solution is to import a certificate from a 3rd party with signature SHA2 algorithm.

    Here is the value for the same application:-

    ASA support for SHA - 2 for crypto IPsec and operations of the public key infrastructure
    CSCuj67576
    https://Tools.Cisco.com/bugsearch/bug/CSCuj67576/?reffering_site=dumpcr

    Kind regards
    Dinesh Moudgil

    PS Please rate helpful messages.

  • HP OfficeJet printers no longer work with 7 Pro. WHY?

    Dear community of Microsoft,

    I'm at the edge of madness since August 14 I'm more able to print on ANY of my HP Officejet printers (both 4500 and a 6500 all in UNITS).  I checked my e-mail address after this thought maybe there would be something Softronics or H.P. in there as a bug or a problem, and of course, there was something H.P.

    I downloaded and ran the "so-called fix."  It wouldn't work.   I'm at the end of my mind and actually BROKEN printers all over my patio.  Childish, maybe, but you have NO IDEA how bad that company makes me mad after the purchase of 17 computers and 8 printers in recent years.  NONE WORK PROPERLY.  NOT A SINGLE ONE.

    H.P. will NOT help me.  But it's NOTHING new to them.  I will NEVER buy another HP product again.  I tried to print a label of mail for more than two weeks now.

    Yes, I had technicians of various companies go into my computer and no ONE, not even H.P., may fix the problem.

    I'm NOT a violent person at all, but it speaks volumes when we crash one of their own printers by such severe frustration.

    My computer is a HP dv7 4000 (supposedly custom... probably not as I buy direct HP and they TEND to rip off of people... just to tell the truth).

    He was SUPPOSED to be a business personal computer built with 7 Professional on it and Office Pro 10 on it.  He appeared as a computer at home (I only paid $3 000,00 to IT... what I would have expected?  "I'm sarcastic to keep to go completely crazy.)

    It has been printing fine on all printers (two HP 4500, a HP 6500 and a very old Canon BJC 4400).  He will receive NO H.P. downloads software or AT ALL on printing of the H.P..

    PLEASSSSEEEEE HELP ME!   I'm at my wit's end.  Yet once, H.P. has a few download send me before I even found printers does not.  They would not work after I installed it and even NOW they still don't work.

    I've done stabbed to pick up the whole system and reinstall everything but as you, who are likely to pros, know, H.P. aren't configuration that can be restored more than the manufacturer's original no matter WHAT say their textbooks online.  It does NOT work.  The computer was delivered without manuals or software.  I had to buy the upgraded software separately since they refused, when I thought it wasn't the computer I ordered, to accept a return and provide the APPROPRIATE injector (I know, what a shock).

    PLEASE HELP ME!  I can't print anything.  I don't have the original disks for installing the printer... they will not accomplish.  H.P. downloads no longer work.

    Karen > ^ * n ^ *.

    Original title: HP OfficeJet printers no longer work with 7 Pro.  WHY?  How on EARTH (or another planet) can I fix this?

    Hi TuffKitten,

    Have you tried uninstalling and reinstalling the printer drivers?
    Turn your printer off, and then try to manually uninstall all HP printers and drivers.
    or
    Please follow the link below to use the removal for your HP 4500 tool
    Please follow the link below to use the for your HP 6500 removal tool
    Remove temporary files:

    In the Start Menu of Windows, type run in the field search programs and files and press ENTER. (You can also use the keys winlogo + r to bring up the run dialog box ).

    In the result, Run dialog box , type %temp% , and press ENTER.

    Press Ctrl + a (or Organization > select all or Edit > select all) to select all the files, right click and delete all files. (Or press the delete key.)

    Restart your computer.

    Please follow the link below to download and install the latest drivers for printer you.

    http://WWW8.HP.com/in/en/support-topics/printer-installation/install-download-printer-drivers.html

    Please let us know if the problem still persists.

  • Now, this suitcase no longer works with InDesign CC 2015, how to activate fonts?

    Now, this suitcase no longer works with InDesign CC 2015, how to activate fonts?

    Then you have something else.

    Looks like the bug fixed with this:

  • Self-signed certificate installed successfully but with VR error device

    HI gurus,

    I'm in the middle of the upgrade of RS 5 5.1 RS for replication of vSphere.

    I'm trying to install and register the device VR 5.1.

    On the configuration tab I filled out the Info: and tried to produce the certificate and start the service.

    It comes up with the following msg.

    Self-signed certificate installed successfully.

    WARNING: Bad service state: execv() arg 2 must contain only strings.

    The info I have completed are as follows:

    VRM Host: ip address of host vrm

    Name of the Site of VRM: virtual site of DR (FQDN) appliance

    vCenter Server Address: address of the server vCenter DR FQDN

    vCenter Server Port: 80

    vCenter Server Admin Mail: e-mail administrators

    Thanks in advance!

    Here's your answer...

    Edit the/etc/sysconfig/network/config file.

    Find this line:

    NETCONFIG_DNS_STATIC_SERVERS = «»

    Change the line and put a DNS server IP address in quotes.

    Restart your device and try again.

    Edit: Still one thing, make sure that you deploy the version of the appliance corresponds to your version of vCenter. vCenter Server 5.5 uses the replication device 5.5, 5.1 VC uses 5.1 etc.

  • Can I generate self-signed certificates free for Nexus 9 K?

    Hi, I have 22 9Ks Nexus that I just upgraded to 3,0000 I4 so I can use the REST API.

    I use vRealize Orchestrator for automation, and I can't access the REST API on the Orchestrator help link, as certificates are at expiration.

    I can't find much information on this subject for the 9 K, unless the 9Ks are mode of the AIT, in this case I think that TACS are the only people who can generate a certificate.

    Does anyone know otherwise work around this? Otherwise, I'll have to approach a TAC case for 22 certificates generated :-/

    Cheers, Dom

    I'm not familiar with the technology with what you're trying to integrate, but here's a guide on how generate a custom SSC (self-signed Cert) on a device:
    #conf t
    #hostname DEVICE01-NOTE: must not be changed
    #ip - domain test.local

    generate a General key label SSC_KEY module 2048 rsa key #crypto

    #crypto pki trustpoint SSC_LOCAL
    #subject - name, CN = DEVICE, DC = test, DC = local
    #enrollment selfsigned
    # crl revocation checking
    #rsakeypair SSC_KEY 2048

    #crypto ca enroll COMMAND SSC_LOCAL HIDDEN: initiate the creation of SSC

    % Include the serial number of the router in the name of the topic? [Yes/No]: no
    % Include an IP address in the name of the topic? [None]:
    % Generate self signed certificate router? [Yes/No]: Yes

    Router self-signed certificate created successfully

    After this make sure that you do NOT change the host name of the device :)

Maybe you are looking for

  • iPhone update problem

    I tried to upgrade my iPhone to version 10. Now it tells me to connect to iTunes. I can't do anything with it. It is just frozen. What should I do? I tried to restart. Just get same message.

  • Satellite L500-1ZC - cannot start HARD drive recovery menu

    I need to access the option "Get back to the default software factory with the data of the user", but I have problems at this stage. I tried power + 0 with no luck, even with the power + f12.When the boot menu appears, HDD Recovery is not there as an

  • HP ENVY 17-j001er: the bios password reset

    Hello. I have fogot administrator BIOS password. I am trying to enter the password 3 times & see message: "system disabled 77210195. Can anyone help me to reset the bios password?

  • Wireless with SP4600 XP

    Hi people, I bought a used SP4600, it was delivered to me empty. No problem, I installed Win XP on it. Everything works fine with the exception of: I can't use the internal wireless card. Of course this card needs a driver, but the Toshiba site does

  • ProBook 4530 s: error 1325 on trying to uninstall HP ProtectTools Security Manager

    I'm trying to uninstall HP ProtectTools Security Manager because it is a prerequisite for the installation of Windows 10.  However, try to uninstall through Control Panel > programs and features, I receive the following error message: Title bar: HP P