AFP548

SSL Certificate for iChat Nightmare

Hey all, hoping somewhere out there can point me in the right direction. I worked for a School District where we implemented our own CA (based on the excellent 'rolling your own ca' article found on AFP548), installed the CA on all clients, then created a SSL Certificate for our iChat server and finally go rid of that pesky "Insecure Login" error that iChat kept coming up with. I have since moved to another School District that already has 2000 laptops deployed across the province, and an iChat server installed, and was frustrated by that Insecure Login error. I (quite confidently) assumed that I could do the same thing as before, but using a GoDaddy cert to avoid having to visit all 2000 laptops to install the CA. However, I'm having problems... Basically, we purchased the SSL Cert from GoDaddy, downloaded it and imported it into Server Admin and configured the iChat server to use it for SSL. Following the directions from GoDaddy I also installed the 'Intermediate" cert into the "System" keychain on the Server. I then restarted the iChat service and happily proceeded to fire up iChat on a client... and got the same insecure login message. D'oh. I've been fighting this for a day now, with the help of GoDaddy tech support, which doesn't seem to know how to do things on the Mac. I configured the web service to use the same certificate (to see if it worked there, and to make testing easier) and my browsers accept that Certificate (after I installed the Intermediate CA on the server, before that it gave a certificate warning). But according to GoDaddy the SSL 'Chain' does not go to the correct CA... It should end up at the GoDaddy root CA, but it stops at their Class 2 Secure CA. I've been told that I need to configure my server to follow the chain to the Root CA, but neither of us has any idea how to do that on a Mac server. Anyone have any advice to offer? Thanks in advance. Jeff
Exit mobile version