Server 2.2.1: Documentation on securing server access via SSL is outdated (10.6 only)

Originator:ciderconsulting
Number:rdar://13431430 Date Originated:15-Mar-2013 12:44 PM
Status:Open Resolved:
Product:Mac OS X Server Product Version:Server 2.2.1 (169)
Classification:Security Reproducible:Always
 
Summary:
The server app doesn't secure remote server access using an SSL certificate that is loaded into server app. Additionally, the help documenting how to enter the SSL identity in the system keychain on the server is 10.6 and outdated talking about Server Admin which is gone now.

Steps to Reproduce:
1. Set up a new Server - enable remote server administration
2. browse to https://server.com:311 from another computer and see that the SSL self-signed certificate is not trusted
3. Install a valid SSL certificate using Server - set all services to use
4. Reboot the server (or killall servermgrd)
5. Test other server resources from the remote computer to see that the SSL certificate for web sharing, etc… is now trusted
6. browse to https://server.com:311 from another computer and see that the SSL self-signed certificate is not trusted

Expected Results:
It would be nice for the Server app to secure com.apple.servermgrd by changing the system keychain identity to use the SSL certificate that the rest of OS X server uses.

Actual Results:
Unable to enter SSL certificate except for following an old support article: http://support.apple.com/kb/HT3930

The steps about Keychain are valid and should perhaps be added to the Server app's built in help.
The steps about open "Server Admin" are wrong on 10.8 since there is no Server Admin and should be deleted or a new KB minted for 10.8 securing of Server Access with SSL.



Regression:
None noted

Notes:
Ideally, Server app would automate this. If not, please update the KB and the help guide to explain how to manually secure 10.8 Server remote access with an SSL certificate.

Comments


Please note: Reports posted here will not necessarily be seen by Apple. All problems should be submitted at bugreport.apple.com before they are posted here. Please only post information for Radars that you have filed yourself, and please do not include Apple confidential information in your posts. Thank you!