Skip to content Accesskey=4Skip to sub-navigation Accesskey=3View our Accessibility Options MIT Information Services and Technology Home About IS&T Contact IS&T Site Map Search Advanced Search
Getting StartedGetting Services by Topic or Alphabetically Getting Help

On This Page

Introductions

Instructions

Details

Trouble Shooting

List of Websites

Change Log

CertAid



Introduction

CertAid is a tool for Mac OS X that will fix certificate problems users may see with some MIT websites when running Safari on Mac OS X 10.5.4 or later. After renewing or getting a new personal certificate, users will need to update their settings by running CertAid again.

[Back to top]


Instructions

  1. Download CertAid.
  2. Double-click the disk image to mount it.
  3. Launch CertAid by double-clicking on the icon.
  4. Click Update List to download current list or websites to configure.
    Result: You should see a message confirming successful download.
  5. Enter your Kerberos username in the Kerberos Principal field.
  6. Click Set Certificate Preferences. If you have more than one personal certificate installed, you will be prompted to select which one to use. Select and click Choose.
    Result: You should see a message confirming successful creation of the certificate preferences.
  7. In the confirmation window, click OK.
  8. In the CertAid main window, click Close.

[Back to top]


Details

10.5.3 changed Safari's behavior so that the users are prompted to select a certificate before sending it to a web server. The first time a user makes this choice, an identity preference is set in the user's keychain, linking the certificate to that web page. Unfortunately, this change introduced a bug that prevented Safari from connecting to certain websites that required a personal certificate. Apple fixed this issue in 10.5.4, but instead of being prompted to select a certificate, the user must manually configure the identity preference for such website.

CertAid simplifies this process by configuring identity preferences for a list of MIT websites that are known to be problematic.

[Back to top]

Trouble Shooting

If after running this tool, you are still unable to connect to a website listed below, launch Keychain Access and delete any identity preferences that may be set for the website, then re-run CertAid.

[Back to top]


List of Website

Below is a list of website that CertAid will configure:

To request that a website or URL be added to this list, contact swr-core@mit.edu.

[Back to top]


Change Log

1.0.2
  • In order to setup identity preferences for newly installed certificates, all existing IPRFs are created on each run, even if they already exist.
  • Includes several new URLs in default list.
  • Version numbers now correctly reflect current version in app and in Finder.
  • Made several minor UI tweaks.
1.0.1
  • Added code to update settings file from remote location at launch.
  • Updated SiteSettings.plist to include preference for remote location (URL).
  • Changed behavior to create IPRFs for 2 versions of each domain: one with and one without a trailing slash. Either format is acceptable in SiteSettings.plist, but only one is needed. CertAid will generate the other automatically.
  • Changed error messages to be less confusing.
  • Added progress indicator while IPRFs are being created.
  • Spun IPRF creation code off into separate thread to keep progress bar running smoothly.
1.0
  • Intitial Public Release

[Back to top

 

 

   
MIT Home | Getting Started | Getting Services | Getting Help | About IS&T | Accessibility
Ask a technology question or contact the Software Release Team.