Windows Vista Tips

Windows Vista Tips > Newsgroups > ActiveSync > Installed DER Cert. for SSL but still doesn't work? (solution)

Reply
Thread Tools Display Modes

Installed DER Cert. for SSL but still doesn't work? (solution)

 
 
Dave Smith
Guest
Posts: n/a

 
      01-24-2007
I have a Audiovox XV6700 (Windows Mobile 5.0) phone. Like a lot of folks,
I've been struggling to get this device to talk to my Exchange Server. My
IIS has a valid third party certificate, and I had followed the steps Chris
De Herrera had laid out on his website (www.pocketpcfaq.com) for exporting a
DER certificate that the device could read. The phone would take the
certificate, but it still wouldn't let me get to OMA w/o bitching about the
certificate.

Verizon was more than helpful ("you can't do that", "that doesn't work on
our phones", "our phones don't deal with that 'stuff'") after which they
directed me to Microsoft, who had already verified that my cert. was
installed correctly on IIS.

After some late-nite reading of Chris's site, and jumping here and there, I
found a utility (http://www.jacco2.dds.nl/networking/p12imprt.html) that
will import the key you can backup from IIS. After running this on the
phone and importing the cert., everything worked.

So, after several days of battling this, I'm done! Many thanks to Chris and
his great site. If you have a WM5 phone, and are having trouble getting a
cert. installed so that OMA will work, go check out that link.


 
Reply With Quote
 
 
 
 
Jacco de Leeuw
Guest
Posts: n/a

 
      01-25-2007

Dave Smith wrote:

> I have a Audiovox XV6700 (Windows Mobile 5.0) phone. Like a lot of folks,
> I've been struggling to get this device to talk to my Exchange Server. My
> IIS has a valid third party certificate, and I had followed the steps Chris
> De Herrera had laid out on his website (www.pocketpcfaq.com) for exporting a
> DER certificate that the device could read. The phone would take the
> certificate, but it still wouldn't let me get to OMA w/o bitching about the
> certificate.
>
> After some late-nite reading of Chris's site, and jumping here and there, I
> found a utility (http://www.jacco2.dds.nl/networking/p12imprt.html) that
> will import the key you can backup from IIS. After running this on the
> phone and importing the cert., everything worked.


What I think may have happened is that your third-party CA uses intermediate
certificates. Windows Mobile does not retrieve intermediate certificates from
the server if the server is not configured to send them or does not have them
in its certificate store.

The P12imprt utility (glad you liked it, BTW) can install intermediate
certificates if they are included in the PKCS#12 file. P12imprt is mainly
intended to install a personal certificate with a private key but I don't
get the impression that you want to install a personal certificate for
authenticating to the Exchange server. An alternative method is to create
a .CAB file with the intermediate certificate(s):

http://blogs.msdn.com/windowsmobile/...cates_201.aspx

Jacco
--
Jacco de Leeuw private.php?do=newpm&u=
Zaandam, The Netherlands http://www.jacco2.dds.nl
Please note: my real e-mail address is not shown, due to spam.
(Hint: I'm *not* in the military but in the Netherlands...)
 
Reply With Quote
 
Dave Smith
Guest
Posts: n/a

 
      01-25-2007
I would have used a private certificate, but the early reading I did
indicated I needed to use a third-party cert. Now I know better, lol. I've
got your website stashed in my favorites so after this cert. expires in a
year, I can find it if I switch over to a self-generated cert.

Thanks for the utility!

"Jacco de Leeuw" <> wrote in message
news:eA%...
>
> Dave Smith wrote:
>
>> I have a Audiovox XV6700 (Windows Mobile 5.0) phone. Like a lot of
>> folks, I've been struggling to get this device to talk to my Exchange
>> Server. My IIS has a valid third party certificate, and I had followed
>> the steps Chris De Herrera had laid out on his website
>> (www.pocketpcfaq.com) for exporting a DER certificate that the device
>> could read. The phone would take the certificate, but it still wouldn't
>> let me get to OMA w/o bitching about the certificate.
>>
>> After some late-nite reading of Chris's site, and jumping here and there,
>> I found a utility (http://www.jacco2.dds.nl/networking/p12imprt.html)
>> that will import the key you can backup from IIS. After running this on
>> the phone and importing the cert., everything worked.

>
> What I think may have happened is that your third-party CA uses
> intermediate
> certificates. Windows Mobile does not retrieve intermediate certificates
> from
> the server if the server is not configured to send them or does not have
> them
> in its certificate store.
>
> The P12imprt utility (glad you liked it, BTW) can install intermediate
> certificates if they are included in the PKCS#12 file. P12imprt is mainly
> intended to install a personal certificate with a private key but I don't
> get the impression that you want to install a personal certificate for
> authenticating to the Exchange server. An alternative method is to create
> a .CAB file with the intermediate certificate(s):
>
> http://blogs.msdn.com/windowsmobile/...cates_201.aspx
>
> Jacco
> --
> Jacco de Leeuw private.php?do=newpm&u=
> Zaandam, The Netherlands http://www.jacco2.dds.nl
> Please note: my real e-mail address is not shown, due to spam.
> (Hint: I'm *not* in the military but in the Netherlands...)



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
vista installed games wont work hudgybear Windows Vista Games 1 01-15-2008 07:31 PM
How To: HP ScanJet 5300C/Make Work Consistently (Finally!!!) Chad Harris Windows Vista Hardware 5 11-29-2007 05:23 PM
HP Pavilion DV8310CA's Quick Launch Buttons won't work in Vista Bruce G. Windows Vista Hardware 14 09-13-2007 01:12 PM
Games that work so far. Mike MrMunka Gillingham Windows Vista Games 18 07-26-2006 04:30 PM
0x80072f17 - Cert problem? Mike Lee ActiveSync 10 04-20-2006 03:44 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59