Jump to content

Profile Manager issues with 10.8.6 clients everything else fine


Recommended Posts

Posted

Hello,

 

We have just upgraded our macserver to 10.12 and the server app to 5.3.1 today.

 

We have a mix of clients across the school;

 

10.12 clients are still fine

10.11 clients are still fine

10.8 clients no longer talk to profile manager and from the client, if I go to Safari and go to to profile manager I get "Safari cannot open the page https://macserver.fqdn/auth?redirect=https://macserver.fqdn/devicemanagement/webapi/authentication/callback because Safari can't establish a secure connection to the server macserver.fqdn

 

iPads and iPhones are still fine.

 

Whilst I would love to update the 10.8 clients to 10.11 or 10.12, these are in our music suites and none of the software is compatible without buying upgrades.

 

Any help or pointers would be appreciated, I feel like I am going around in circles.

 

I've tried manually installing the SSL certificate on a 10.8 client into the system keychain but still get the same message.

 

Thanks, eddyc

Posted
I read a little while ago that Server.app 5.3 only supports TLS 1.2 (from https://apple.stackexchange.com/questions/280143/tlsv1-alert-protocol-version-when-connecting-via-ssl-to-os-x-server ). According to https://en.wikipedia.org/wiki/Transport_Layer_Security#Libraries , OSX 10.9 (and iOS 5.0) is the first to support TLS 1.1/1.2 (instead of just 1.0). You could try editing the Apache config files mentioned in the StackOverflow link to re-enable TLS 1.0, but that will lower the security of the server for all clients. (I do not have any OSX 10.8/iOS 4 clients so can't verify this works). Another option may be setting up a separate server just for these older macs.
  • Thanks 1
Posted
I read a little while ago that Server.app 5.3 only supports TLS 1.2 (from https://apple.stackexchange.com/questions/280143/tlsv1-alert-protocol-version-when-connecting-via-ssl-to-os-x-server ). According to https://en.wikipedia.org/wiki/Transport_Layer_Security#Libraries , OSX 10.9 (and iOS 5.0) is the first to support TLS 1.1/1.2 (instead of just 1.0). You could try editing the Apache config files mentioned in the StackOverflow link to re-enable TLS 1.0, but that will lower the security of the server for all clients. (I do not have any OSX 10.8/iOS 4 clients so can't verify this works). Another option may be setting up a separate server just for these older macs.

 

You sir are a genius. I have just turned TLS 1 and TLS 1.1 back on by modifying the apache_serviceproxy.conf file as the article says.

 

Stop websites and profile manager services, made the changes, reboot the server and turned websites and profile manager services back on and then everything is back in action.

 

I can't thank you enough - That gives me extra fire power to upgrade all of our music software so we can move to OS X 10.12

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...