Ask a Question

Advanced Search

Solution ID : SO22067

Last Modified : 05/18/2018

Managed PKI for SSL - Installation Instructions for Mac OS X 10.7

Solution

 

This document provides instructions for installing a SSL certificate for  MAC OS X 10.7. If you cannot use this solution for your server, Symantec recommends you contact Apple.

NOTE: If you have not yet generated the CSR, please see this solution.

Step 1: Obtain the SSL Certificate

  1. Once your Managed PKI for SSL administrator has approved your Certificate request, you will receive an email with a certificate download link, also attached (cert.cer), as well as in the body of the email itself.
  2. If copying the certificate from the body of the email, copy and paste it into a text file using Vi or Notepad.
    NOTE: Do not use Microsoft Word or other word processing programs that may add characters. Confirm that there are no extra lines or spaces in the file.

    The text file should look like:

    -----BEGIN CERTIFICATE-----
              [encoded data]
    -----END CERTIFICATE-----

    NOTE: Click here to download the certificate from your Managed PKI for SSL subscriber services page.
    Please select X.509 as a certificate format and copy only the End Entity Certificate.
     
  3. Save the certificate as public.txt


Step 2: Install the SSL Certificate

  1. Open up Profile Manager.

     
     
  2. Click on Manage Certificate.

     
     
  3. Replace certificate with the SSL certificate you downloaded in Step 1.


     
  4. Drag the certificate here, and click on Replace Certificate button.

       
     
  5. Then open up KeyChain, you need to configure the certificate to make sure it's trusted.
  6. Download the Intermediate CA certificate from this link.
  7. Select the appropriate Intermediate CA certificate for your SSL Certificate type.
    NOTE: If you are not sure which certificate you have purchased, follow these steps from this link.
  8. Copy and paste it into a text file using Vi or Notepad
  9. Make sure there are 5 dashes to either side of the BEGIN CERTIFICATE and END CERTIFICATE and that no white spaces, extra line breaks or additional characters have been inadvertently added.
  10. Save the file as intermediate.txt.
  11. You can simply drag the CA certificate to the System KeyChain.

     
     
  12. From the KeyChain, examine the certificate.
  13. Once you have examined the details, expand the Trust section and choose Always Trust for both
    X.509 Basic Policy and the When using this certificate pull-down.
  14. Finally, click the Always Trust button.

     
     
  15. Check to make sure the installed certificate is correctly assigned to the web service.

        
     
  16. Verify your installation with the Symantec CryptoReport.