AFP548

AppleMailServer and SSL

Hi All, I just got OS X Server 10.2, and want to setup an IMAP server that supports SSL connections (something I've done in 10 minutes with Linux in the past). Looking through the Server Settings for the Mail service, there are no options for this. After a bit of searching, I found a KnowledgeBase article discussing the topic, "Mac OS X Server 10.2: How to Set Up SSL for Mail Service", Article ID 75335 @ Apple. In addition to requiring some rather obscure manipulations of certain Keychains with "certtool", the main trouble is that the Mail service seems to require you to obtain a trusted SSL certificate from Verisign or Thawte. I tried creating a self-signed certificate and importing it into the certkc Keychain that the article discusses, but I regularly get the error: "SSL Error: valid cert chain, untrusted root." IMAP on regular port 143 without SSL works fine, btw. I was astonished that OS X Server would not let me setup my own secure email server out of the box, so I called Apple Tech Support. After taking 45 minutes to get my name into the database and asking my question, the support guy simply told me that he "isn't allowed to help me fake a root certificate." This, as you might expect, was even more displeasing. Fortunately, I found your web site so I will try to setup stunnel to enable SSL connections to the server. However, I am curious to know if anyone else has tried the above and had better luck. I did some digging, and I suspect the trusted root certificates are stored in the file /Library/Keychains/X509Anchors, but I cannot figure out how to import a newly created and self-signed certificate into this file. Any other insights on this issue would be much appreciated. Cheers, Nick
Exit mobile version