Several El Capitan Problems

I think these issues are related, but not sure. Maybe a certificate issue on this computer.

1. Cannot get updates from App Store. I upgraded from Yosemite to public beta El Capitan. After upgrading, I got version 2and version 3 through the app store, but no version 4. If I click on Updates, I get this message: "The certificate for this server is invalid. You might be connecting to a server that is pretending to be “swscan.apple.com” which could put your confidential information at risk." I found a command line to update to version 4, but still no app store updates.

2. Anyconnect will not start correctly. I have version 4.1.04011. If I uninstall, reboot then re-install, I can get connected if I quickly enter my credentials. My connection is fine at that point. If I do not enter the credentials soon enough or disconnect/reconnect, I get the message "The VPN service is not available. Exiting. This is a snippet of the log messages when running Anyconnect:

Aug 6 12:10:54 1usmwhall acvpnagent[24857]: Function: QuickCreatePlugin File: ../../vpn/Common/Utility/PluginLoader.h Line: 199 Invoked Function: PluginLoader::CreateInstance Return Code: -29360116 (0xFE40000C) Description: PLUGINLOADER_ERROR_COULD_NOT_CREATE com.cisco.anyconnect.leaf

Aug 6 12:10:54 1usmwhall acvpnagent[24857]: Function: QuickCreatePlugin File: ../../vpn/Common/Utility/PluginLoader.h Line: 199 Invoked Function: PluginLoader::CreateInstance Return Code: -29360116 (0xFE40000C) Description: PLUGINLOADER_ERROR_COULD_NOT_CREATE com.cisco.anyconnect.service.namcntrl

Aug 6 12:10:54 1usmwhall acvpnagent[24857]: Function: QuickCreatePlugin File: ../../vpn/Common/Utility/PluginLoader.h Line: 199 Invoked Function: PluginLoader::CreateInstance Return Code: -29360116 (0xFE40000C) Description: PLUGINLOADER_ERROR_COULD_NOT_CREATE com.cisco.anyconnect.service.websecurity

Aug 6 12:10:54 1usmwhall acvpnagent[24857]: Function: QuickCreatePlugin File: ../../vpn/Common/Utility/PluginLoader.h Line: 199 Invoked Function: PluginLoader::CreateInstance Return Code: -29360116 (0xFE40000C) Description: PLUGINLOADER_ERROR_COULD_NOT_CREATE com.cisco.anyconnect.service.fireamp_enabler

Aug 6 12:10:54 1usmwhall acvpnagent[24857]: Function: LoadFileToMap File: ../../vpn/PhoneHome/PhoneHomeAgent.cpp Line: 2063 Can't open file /opt/cisco/anyconnect/CustomerExperienceFeedback/config

Aug 6 12:10:54 1usmwhall acvpnagent[24857]: Function: LoadFileToMap File: ../../vpn/PhoneHome/PhoneHomeAgent.cpp Line: 2063 Can't open file /opt/cisco/anyconnect/CustomerExperienceFeedback/history

Aug 6 12:10:55 1usmwhall com.apple.xpc.launchd[1] (com.cisco.anyconnect.vpnagentd[24857]): Service exited due to signal: Segmentation fault: 11

Aug 6 12:10:55 1usmwhall com.apple.xpc.launchd[1] (com.cisco.anyconnect.vpnagentd): Service only ran for 0 seconds. Pushing respawn out by 10 seconds.

3. Pulse Secure will not connect or allow me create profile. I have version 5.1.3.56743. I am able to connect to our UAC server through the web page. I get "Failed to connect to the Pulse Secure service". I manually added the "VeriSign Class 3 Public Primary Certification Authority - G5" certificate referenced in several other posts, such as http://forums.juniper.net/t5/SSL-VPN/Junos-Pulse-DOA-with-El-Capitan-Mac-OS-10-11/td-p/276235/page/4. This is a snippet of the log for Pulse:

00186,09 2015/08/04 12:11:11.368 3 root dsAccessService dsAccessService p58026 tC0B service.mm:79 - 'AccessService' CmdLine: /Applications/Junos Pulse.app/Contents/Plugins/JUNS/dsAccessService

00133,09 2015/08/04 12:11:11.369 3 root dsAccessService dsAccessService p58026 tC0B service.mm:115 - 'AccessService' initializing service...

00133,09 2015/08/04 12:11:11.369 3 root dsAccessService dsAccessService p58026 tC0B service.mm:141 - 'AccessService' initializing service...

00162,09 2015/08/04 12:11:11.430 3 root dsAccessService dsAccessService p58026 tC0B accessService.cpp:673 - 'AccessService' plugin NetMonitor, manual start, not starting

00174,09 2015/08/04 12:11:11.430 3 root dsAccessService dsAccessService p58026 tC0B accessService.cpp:673 - 'AccessService' plugin ConnectionStoreService, manual start, not starting

00171,09 2015/08/04 12:11:11.430 3 root dsAccessService dsAccessService p58026 tC0B accessService.cpp:669 - 'AccessService' plugin ConnectionManagerService, queuing start task...

00163,09 2015/08/04 12:11:11.455 1 root dsAccessService dsAccessService p58026 tC0B verify.cpp:62 - 'dsVerifySignature' SecStaticCodeCheckValidity failed. (status=-67050)

00232,09 2015/08/04 12:11:11.455 1 root dsAccessService dsAccessService p58026 tC0B accessPluginLoader.cpp:113 - 'AccessService' plugin /Applications/Junos Pulse.app/Contents/Plugins/ConnectionManager/connectionMgr.dylib, invalid signature

00163,09 2015/08/04 12:11:11.455 3 root dsAccessService dsAccessService p58026 tC0B accessService.cpp:673 - 'AccessService' plugin jamUIPlugin, manual start, not starting

00170,09 2015/08/04 12:11:11.455 3 root dsAccessService dsAccessService p58026 tC0B accessService.cpp:673 - 'AccessService' plugin HostCheckerService, manual start, not starting

00162,09 2015/08/04 12:11:11.455 3 root dsAccessService dsAccessService p58026 tC0B accessService.cpp:673 - 'AccessService' plugin eapService, manual start, not starting

00161,09 2015/08/04 12:11:11.455 3 root dsAccessService dsAccessService p58026 tC0B accessService.cpp:673 - 'AccessService' plugin TMService, manual start, not starting

00167,09 2015/08/04 12:11:11.455 3 root dsAccessService dsAccessService p58026 tC0B accessService.cpp:673 - 'AccessService' plugin iveAccessMethod, manual start, not starting

00167,09 2015/08/04 12:11:11.455 3 root dsAccessService dsAccessService p58026 tC0B accessService.cpp:673 - 'AccessService' plugin vpnAccessMethod, manual start, not starting

00166,09 2015/08/04 12:11:11.455 3 root dsAccessService dsAccessService p58026 tC0B accessService.cpp:673 - 'AccessService' plugin uiModelService, manual start, not starting

00149,09 2015/08/04 12:11:11.455 3 root dsAccessService dsAccessService p58026 tC0B accessService.cpp:383 - 'AccessService' notify plugin status, 11 plugins

00164,09 2015/08/04 12:11:12.343 1 root dsAccessService dsAccessService p58026 t2F03 verify.cpp:62 - 'dsVerifySignature' SecStaticCodeCheckValidity failed. (status=-67050)

00222,09 2015/08/04 12:11:12.343 1 root dsAccessService dsAccessService p58026 t2F03 accessPluginLoader.cpp:113 - 'AccessService' plugin /Applications/Junos Pulse.app/Contents/Plugins/JamUI/uiPromptPlugin.dylib, invalid signature

00187,09 2015/08/04 12:11:12.343 1 root dsAccessService dsAccessService p58026 t2F03 accessPluginLoader.cpp:607 - 'AccessService' trying to create instance on plugin jamUIPlugin while in state 1

00175,09 2015/08/04 12:11:12.344 1 whall PulseTray Pulse p57970 t1607 accessServiceApi.mm:110 - 'AccessServiceProxy' createInstance of plugin jamUIPlugin failed with error 0xe00103ee

00136,09 2015/08/04 12:11:12.358 3 whall PulseTray Pulse p57970 t1607 DialogManager.cpp:187 - 'JamUI' No plugin interface available - rc = 1006

00164,09 2015/08/04 12:11:12.375 1 root dsAccessService dsAccessService p58026 t300B verify.cpp:62 - 'dsVerifySignature' SecStaticCodeCheckValidity failed. (status=-67050)

Answered by Max108 in 42004022

That makes sense - normally weeding out expired certs and setting the remainder to defaults will fix the issue, but there must have been something wrong with the implementation of the Symantec CA Cert.

When you installed it, are you sure you followed steps 7 to 10 of the last post of the page you linked to? You can try that again now that you've followed the procedure I outlined above (although I suggest double-clicking it rather than importing it) and it may work for you this time - as it has for the others posting on the Junos forum.

Welcome to the club.

The Certificate Invalid/No App Store connect dealie is fairly commonplace, apparently.

Have read a fair number of complaints of this on non-Apple forums.

I'm having the problem...and I think getting a fixed version, if we can't connect to the App Store should prove interesting and tricky.

Hi whall2947,


Sounds like it could be a certificate problem, like you say. Following the steps below sorts that out in most cases, but let me know how you get on:


First:


  1. Open Keychain (by pressing CMD+Space and then typing “Keychain”).
  2. Then type veri into the Keychain app's searchbar.
  3. For each of the VeriSign certificates, do the following:
    • Check that the certificate is still valid (far right column) and delete it if it isn't.
    • Double-click it, which brings up it's own window and expand the "Trust" menu.
    • Make sure "When using this certificate:" is set to "Use System Defaults", not "Always Trust".

      The remaining 10 should be left at "no value specified".


If the above doesn't work, use the following steps to reset the cache of accepted certificates.

  1. Open the Finder.
  2. Choose Go to Folder from the Go menu.
  3. Type /var/db/crls/ in the Go window.
  4. Click Go.
  5. Delete crlcache.db and ocspcache.db by dragging these files to the Trash (put the names in the search bar to find them)
  6. Enter an administrator password if you are prompted.
  7. Restart the system and test for the issue.


Max.

Hi Max - Thanks for the suggestions. I tried following your steps, but still no change. I cannot get updates from the app store and Anyconnect and Pulse will not start correctly.

I can post the links to update to Beta 4 directly using the same source that the App Store does but I'm guessing you'd prefer to have the App Store back. Did the App Store and AnyConnect issues occur after installing the Symantec CA Cert or before?

I had the App Store and Anyconnect problems before I installed the other Verisign/Symantec cert. In addition to your suggestion of setting the cert to defaults, I deleted the cert and now the App Store and Anyconnect work. Still no joy with Pulse, so I will see if I can get a different version of the Pulse client. Thanks for the response.

Accepted Answer

That makes sense - normally weeding out expired certs and setting the remainder to defaults will fix the issue, but there must have been something wrong with the implementation of the Symantec CA Cert.

When you installed it, are you sure you followed steps 7 to 10 of the last post of the page you linked to? You can try that again now that you've followed the procedure I outlined above (although I suggest double-clicking it rather than importing it) and it may work for you this time - as it has for the others posting on the Junos forum.

That did the trick. The only difference was that I double-clicked the cert rather than importing it into Keychanin Access. Thanks for all the help.

Glad you've got it sorted 🙂

Several El Capitan Problems
 
 
Q