All Topics » Pulse Desktop Clients



Pulse Secure 5.2r5 still not working properly on macOS Sierra


ubiquitouschris
Contributor (0)
Sep 27, 2016 9:13pm
Greetings everyone,

We recently started testing the new Pulse Secure client that supposedly has support for macOS 10.12, but we've been running in to an issue. Every time a user tries to establish a connection to our VPN, they'll initially get a popup stating the following:

You are about to authenticate to an untrusted server. There are problems with the sites security certificate:
The certificate or certificate chain is based on an untrusted root. The certificate chain is not complete.

I have verified on all of our test systems that the proper cert chain is installed and working as I am able to use other resources that rely on the same roots. Clicking the view button on this message and trying to see which certificate its having a problem with results in an indefinite "connecting" display. Has anyone else seen anything like this and figured out a workaround?

Thanks,
UbiquitousChris



zanyterp
Pulse Secure Contributor (40)
Sep 28, 2016 2:34am
Unfortunately, no, we have not seen this in our testing nor seen it reported
Is the connection using a root CA that is in the system keychain?
Do other versions of Mac OS X show problems?
Do other OS versions show problems?
Does macOS Sierra work in Safari with your certificate?
    ubiquitouschris
    Contributor (0)
    Sep 28, 2016 1:52pm
    Is the connection using a root CA that is in the system keychain? Yes.
    Do other versions of Mac OS X show problems? We've installed the same package and settings on machines using OS X El Capitan and have not seen any issues. Everything connects as expected.
    Do other OS versions show problems? To my knowledge, we're only seeing this on Sierra.
    Does macOS Sierra work in Safari with your certificate? I am able to load the VPN pages and see a valid certificate chain in Safari.

    I should mention: a user is still able to connect to the VPN service just by clicking Ok on the certificate prompt that shows. We don't want to teach our users to be clicking through invalid certificate messages though.

    Thanks,
    Chris
    zanyterp
    Pulse Secure Contributor (40)
    Oct 3, 2016 8:51pm
    Thank you for the update; if you have not done so,please open a case and provide an SSL dump and system snapshot for event codes Certificate,SSL,CRL,OCSP,SBR,sbr,dsagentd,ittls and the save all logs output (do you see a reason given in the events log?).
    I don't know if this is a generic issue with tracking the server certificate presented or something specific to the PCS you are using
kasper03
Contributor (0)
Oct 3, 2016 9:18pm
Hello Everyone

We have been testing the new Pulse Secure client that supposedly has support for macOS 10.12, but we've been running in to an issue. Every time a user tries to establish a connection to our VPN, they'll initially get a popup stating the following:

You are about to authenticate to an untrusted server. There are problems with the sites security certificate:
The certificate or certificate chain is based on an untrusted root. The certificate chain is not complete.

After hitting ok we recieve a connection error "missing or invalid client certificate (error 1332)

We are using a safenet token with software version 9.1.10.0. my safenet client sees my certificate on the token.

I am able to use the token to connect to OWA using Safari.

Any help would be appreciated

Thanks

Matt
    ubiquitouschris
    Contributor (0)
    Oct 4, 2016 2:02pm
    I've opened up a case with PulseSecure and its been escalated. I will post here when/if we find a solution.

    Thanks,
    UbiquitousChris
    asd113
    Contributor (0)
    Oct 24, 2016 3:11pm
    Any luck with this? Same exact issue here.
    Black
    Contributor (0)
    Nov 15, 2016 10:35pm
    same here
coma
Contributor (0)
Dec 8, 2016 2:22am
Not able to connect to my university's VPN after the first time. So, I can start up and connect with Pulse Secure [i]once[/I] and if I try to suspend and resume or disconnect and reconnect, it will hang indefinitely. Any fix for this in an upcoming version?
    kita
    Moderator (16)
    Dec 24, 2016 12:48am
    Hello Coma,

    If the Pulse client remains in "Disconnecting" state for several minutes on macOS, we have identified and root caused the issue (PRS-347695). I found another post which I have provided workarounds and solutions.

    https://forums.pulsesecure.net/topic/pulse-connect-secure/1001965-pulse-secure-can-connect-only-once-when-using-mac-os-sierra
Black2
Contributor (0)
Jan 5, 2017 6:57pm
same with 5.2.6 (977) an latest release on device
certificate warning (with valid public certificate), when try to view certificate client gets in non working state