From: Salt Lake City, UT
DeployStudio 1.6.16 not detecting FQDN SSL Certificate

I have an SSL certificate that I use for all of the network services on my Mac Mini Server.
The common name of the certificate is the FQDN of the server.
For some reason when reconfiguring the DeployStudio Server to use a new sharepoint, it is not allowing me to choose this certificate again.
I am able to choose a code signing certificate, the com.deploystudio.server certificate, the Server Fallback SSL Certificate, or any of the certificates.

Any ideas on why the main certificate that makes the most sense is not able to be chosen in the drop down?


Re: DeployStudio 1.6.16 not detecting FQDN SSL Certificate

Hi I have the same problem.  We use the web service to modify the database computer (computer name, inventory number, ...)  I upgraded a deploystudio to osx 10.11 and ds 1.7.1 so the ds web service run on port 60043.  My automated system that populate the ds database is not able to communicate to web service.  I retrograded the DS to 1.6.16 to make thing work again.

I installed another server for test 10.11 osx and 1.7.1 DS.  I'm not able to chose a certificate other than com.deploystudio.server .  I have a self sign, and an official certificate from go daddy in, I saw them in the keychain too, but not in the deploystudio assistant.  I think that my webapp is not able to connect to the web service because of the certificat that is not approuved.

Is there trick be able to choose another certificate, or to disable the use of ssl?



Re: DeployStudio 1.6.16 not detecting FQDN SSL Certificate

I have a slightly different, yet similar problem. I have 3 certificates on my server that using the FQDN as the common name; 1 self-signed cert and 2 external certs from 2 different CA chains. The DeployStudio Assistant "Network security" step only lists this entry once. From what I can tell, this uses the last certificate that matches.

I was able to track down which cert would be used by running the command `security find-identity "/Library/Keychains/System.keychain"` and the last certificate found under "Matching identities" was the one that DSA used.

If possible, I'd like to see DSA list all the certs that are available under "Matching identities" and possibly show some or all of their SHA1 fingerprints so that it's easier to identify which cert we want to use with DS.

DS 1.7.3


Re: DeployStudio 1.6.16 not detecting FQDN SSL Certificate

I have the same issue.  I have a valid certificate from a 3rd party CA and it is showing up in the keychain and working for other services (showing valid and trusted).  However, I cannot get it to sow up in the DS setup assistant list of certificates and therefore cannot use the web services to update the DB.  I was not able to revert DS back to http in the meantime.  ...DS-1.7.8


