Educause Security Discussion mailing list archives

Re: Apple Devices not trusting Comodo SSL Certificate on initial Wireless Connection


From: Jim Williams Jr <Jim.Williams () PCT EDU>
Date: Wed, 18 Oct 2017 17:59:21 +0000

Thanks for the info.  Our cert actually does match up with the apple store serial number.  I double checked with the 
link that you sent to verify that serial number “00 e8 2f 6a 34 a8 9b a6 49 f8 f8 1a 52 46 5f cc 56” was listed.  Maybe 
the solution would be to just buy a cert from another provider.  I was hesitant to do this though, didn’t want to waste 
the money if the same problem would result.


From: Babak Oskouian [mailto:boskouia () mills edu]
Sent: Wednesday, October 18, 2017 1:50 PM
To: Jim Williams Jr <Jim.Williams () pct edu>
Subject: Fwd: Apple Devices not trusting Comodo SSL Certificate on initial Wireless Connection

Hi Jim,

We have the exact same problem at Mills College. It turns out that the Comodo Cert in Apple store has a different 
serial number (it is older) than the cert we purchased.  We tried installing an older cert that matched the one Apple 
has, and that fixed the issue for Apple devices but broke the trust for all other devices, so we reverted.

Here is a link that will show you what Apple has in their Trust Store:

https://support.apple.com/en-us/HT207177

Babak


Babak Oskouian, Ph.D. | Campus Network Engineer | Information Security Officer

Mills College | 5000 MacArthur Blvd | Oakland, CA 94613-1301

Office: Stern Hall 007; Phone: 510-430-2224<tel:510-430-2224>



________________________________
This email may contain confidential information about a Pennsylvania College of Technology student. It is intended 
solely for the use of the recipient. This email may contain information that is considered an “educational record” 
subject to the protections of the Family Educational Rights and Privacy Act Regulations. The regulations may be found 
at 34 C.F.R. Part 99 for your reference. The recipient may only use or disclose the information in accordance with the 
requirements of the Federal Educational Rights and Privacy Act Regulations. If you have received this transmission in 
error, please notify the sender immediately and permanently delete the email.

Current thread: