Windows Vista Tips

Windows Vista Tips > Newsgroups > ActiveSync > Synchronization failed due to an incorrect SSL certificate common name

Reply
Thread Tools Display Modes

Synchronization failed due to an incorrect SSL certificate common name

 
 
Stuart Mackie [MCP, MSP]
Guest
Posts: n/a

 
      11-07-2004
Hi. I am trying to get Activesync to work with Exchange 2003 (SBS2k3) and
an i-mate PDA2k. I've searched online for the error I am getting and have
found a number of suggestions but cannot resolve the problem. I have IIS
configured with SSL required for the default website including MS
Activesync, Exchange and OMA etc.

I have installed our domain certificate on the PDA as a root certificate.
At the moment if I remove the SSL requirement from the Default web site, and
configure the PDA not to use SSL, I can get the PDA to sync without problem.
But if I enable SSL on both server and client the sync fails with
"Synchronization failed due to an incorrect SSL certificate common name".

The only part of this process which didn't work as expected was importing
the domain certificate into the PDA. I copied the SBS2k3 generated
certificate from the C:\ClientApps\SBScert to the PDA. On trying to import
it I got the error "Cannot access certificate". In the end I exported the
domain certificate from a workstation, copied it to the PDA and it imported
without problem. I've checked the certificate and it is identical to the
SBS2k3 cert, but I'm still suspicious this is related

Can anyone point me in the right direction on the best way to

--
Thanks,
Stuart Mackie [MCP, MSP]
www.stu.uk.com


 
Reply With Quote
 
 
 
 
Chris De Herrera
Guest
Posts: n/a

 
      11-08-2004
Hi,
Try "If you see an error INTERNET_45 which means that the "security
certificate on the server is invalid" it may be because you are using a self
generated certificate instead of one that is issued by a trusted authority
like Verisign. (The Pocket PC was checking to make sure that the
certificate was official). To sync with the self generated certificate,
Run CERTCHK.EXE off or install the AS_Cert_Off.cab on the Pocket PC, and
then you should connect fine. For users of Exchange 2003, you need to
download DisableCertChk.exe
http://www.microsoft.com/downloads/d...displaylang=en
to test without a digital certificate. " from the ActiveSync Troubleshooting
Guide
http://www.cewindows.net/faqs/active...ation%20Server


--
Chris De Herrera
http://www.cewindows.net
http://www.tabletpctalk.com
http://www.pocketpctalk.com
http://www.mobilitytalk.com

"Stuart Mackie [MCP, MSP]" <newsgroups@--REMOVE_THIS-NO_SPAM--stu.uk.com>
wrote in message news:...
> Hi. I am trying to get Activesync to work with Exchange 2003 (SBS2k3) and
> an i-mate PDA2k. I've searched online for the error I am getting and have
> found a number of suggestions but cannot resolve the problem. I have IIS
> configured with SSL required for the default website including MS
> Activesync, Exchange and OMA etc.
>
> I have installed our domain certificate on the PDA as a root certificate.
> At the moment if I remove the SSL requirement from the Default web site,
> and configure the PDA not to use SSL, I can get the PDA to sync without
> problem. But if I enable SSL on both server and client the sync fails with
> "Synchronization failed due to an incorrect SSL certificate common name".
>
> The only part of this process which didn't work as expected was importing
> the domain certificate into the PDA. I copied the SBS2k3 generated
> certificate from the C:\ClientApps\SBScert to the PDA. On trying to
> import it I got the error "Cannot access certificate". In the end I
> exported the domain certificate from a workstation, copied it to the PDA
> and it imported without problem. I've checked the certificate and it is
> identical to the SBS2k3 cert, but I'm still suspicious this is related
>
> Can anyone point me in the right direction on the best way to
>
> --
> Thanks,
> Stuart Mackie [MCP, MSP]
> www.stu.uk.com
>
>



 
Reply With Quote
 
Stuart Mackie [MCP, MSP]
Guest
Posts: n/a

 
      11-08-2004
Hi Chris, thanks for your response. I have downloaded and tested the
software for disabling the SSL checking. If I disable SSL checking, the PDA
will sync with SSL enabled.

The problem now is I can't work out which certificate is the correct one to
export from my SBS2k3 server, or what I'm doing wrong I've exported the
domain/server certificate which is listed in the Trusted Root Certificate
Authorities on the server and workstations, and imported it into the PDA,
but still get the SSL error message if SSL checking is enabled.

--
Thanks,
Stuart Mackie [MCP, MSP]
www.stu.uk.com


"Chris De Herrera" <> wrote in message
news:...
> Hi,
> Try "If you see an error INTERNET_45 which means that the "security
> certificate on the server is invalid" it may be because you are using a
> self generated certificate instead of one that is issued by a trusted
> authority like Verisign. (The Pocket PC was checking to make sure that
> the certificate was official). To sync with the self generated
> certificate, Run CERTCHK.EXE off or install the AS_Cert_Off.cab on the
> Pocket PC, and then you should connect fine. For users of Exchange 2003,
> you need to download DisableCertChk.exe
> http://www.microsoft.com/downloads/d...displaylang=en
> to test without a digital certificate. " from the ActiveSync
> Troubleshooting Guide
> http://www.cewindows.net/faqs/active...ation%20Server
>
>
> --
> Chris De Herrera
> http://www.cewindows.net
> http://www.tabletpctalk.com
> http://www.pocketpctalk.com
> http://www.mobilitytalk.com
>
> "Stuart Mackie [MCP, MSP]" <newsgroups@--REMOVE_THIS-NO_SPAM--stu.uk.com>
> wrote in message news:...
>> Hi. I am trying to get Activesync to work with Exchange 2003 (SBS2k3)
>> and an i-mate PDA2k. I've searched online for the error I am getting and
>> have found a number of suggestions but cannot resolve the problem. I
>> have IIS configured with SSL required for the default website including
>> MS Activesync, Exchange and OMA etc.
>>
>> I have installed our domain certificate on the PDA as a root certificate.
>> At the moment if I remove the SSL requirement from the Default web site,
>> and configure the PDA not to use SSL, I can get the PDA to sync without
>> problem. But if I enable SSL on both server and client the sync fails
>> with "Synchronization failed due to an incorrect SSL certificate common
>> name".
>>
>> The only part of this process which didn't work as expected was importing
>> the domain certificate into the PDA. I copied the SBS2k3 generated
>> certificate from the C:\ClientApps\SBScert to the PDA. On trying to
>> import it I got the error "Cannot access certificate". In the end I
>> exported the domain certificate from a workstation, copied it to the PDA
>> and it imported without problem. I've checked the certificate and it is
>> identical to the SBS2k3 cert, but I'm still suspicious this is related
>>
>> Can anyone point me in the right direction on the best way to
>>
>> --
>> Thanks,
>> Stuart Mackie [MCP, MSP]
>> www.stu.uk.com
>>
>>

>
>



 
Reply With Quote
 
Chris De Herrera
Guest
Posts: n/a

 
      11-10-2004
Hi,
From what I understand the SSL checking means that the certificate is
checked against the publicly issued certificates of vendors like Verisign.
Since you are locally signing the certificate it doesn't make sense to check
it since it will fail.


--
Chris De Herrera
http://www.cewindows.net
http://www.tabletpctalk.com
http://www.pocketpctalk.com
http://www.mobilitytalk.com

"Stuart Mackie [MCP, MSP]" <newsgroups@--REMOVE_THIS-NO_SPAM--stu.uk.com>
wrote in message news:...
> Hi Chris, thanks for your response. I have downloaded and tested the
> software for disabling the SSL checking. If I disable SSL checking, the
> PDA will sync with SSL enabled.
>
> The problem now is I can't work out which certificate is the correct one
> to export from my SBS2k3 server, or what I'm doing wrong I've exported
> the domain/server certificate which is listed in the Trusted Root
> Certificate Authorities on the server and workstations, and imported it
> into the PDA, but still get the SSL error message if SSL checking is
> enabled.
>
> --
> Thanks,
> Stuart Mackie [MCP, MSP]
> www.stu.uk.com
>
>
> "Chris De Herrera" <> wrote in message
> news:...
>> Hi,
>> Try "If you see an error INTERNET_45 which means that the "security
>> certificate on the server is invalid" it may be because you are using a
>> self generated certificate instead of one that is issued by a trusted
>> authority like Verisign. (The Pocket PC was checking to make sure that
>> the certificate was official). To sync with the self generated
>> certificate, Run CERTCHK.EXE off or install the AS_Cert_Off.cab on the
>> Pocket PC, and then you should connect fine. For users of Exchange 2003,
>> you need to download DisableCertChk.exe
>> http://www.microsoft.com/downloads/d...displaylang=en
>> to test without a digital certificate. " from the ActiveSync
>> Troubleshooting Guide
>> http://www.cewindows.net/faqs/active...ation%20Server
>>
>>
>> --
>> Chris De Herrera
>> http://www.cewindows.net
>> http://www.tabletpctalk.com
>> http://www.pocketpctalk.com
>> http://www.mobilitytalk.com
>>
>> "Stuart Mackie [MCP, MSP]" <newsgroups@--REMOVE_THIS-NO_SPAM--stu.uk.com>
>> wrote in message news:...
>>> Hi. I am trying to get Activesync to work with Exchange 2003 (SBS2k3)
>>> and an i-mate PDA2k. I've searched online for the error I am getting
>>> and have found a number of suggestions but cannot resolve the problem.
>>> I have IIS configured with SSL required for the default website
>>> including MS Activesync, Exchange and OMA etc.
>>>
>>> I have installed our domain certificate on the PDA as a root
>>> certificate. At the moment if I remove the SSL requirement from the
>>> Default web site, and configure the PDA not to use SSL, I can get the
>>> PDA to sync without problem. But if I enable SSL on both server and
>>> client the sync fails with "Synchronization failed due to an incorrect
>>> SSL certificate common name".
>>>
>>> The only part of this process which didn't work as expected was
>>> importing the domain certificate into the PDA. I copied the SBS2k3
>>> generated certificate from the C:\ClientApps\SBScert to the PDA. On
>>> trying to import it I got the error "Cannot access certificate". In the
>>> end I exported the domain certificate from a workstation, copied it to
>>> the PDA and it imported without problem. I've checked the certificate
>>> and it is identical to the SBS2k3 cert, but I'm still suspicious this is
>>> related
>>>
>>> Can anyone point me in the right direction on the best way to
>>>
>>> --
>>> Thanks,
>>> Stuart Mackie [MCP, MSP]
>>> www.stu.uk.com
>>>
>>>

>>
>>

>
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Security Update error: Windows XP (KB973768) Agusto Windows Update 7 01-03-2010 08:29 PM
Vista RTM - Blue screen (BSOD) on Install Toshiba M400 TabletPC kevin forsythe Windows Vista Installation 3 11-18-2006 02:50 AM
Stop 0x0000007b after Setup BobMiller Windows Vista Installation 8 08-05-2006 09:29 PM
Stop 0x0000007b at end of Install BobMiller Windows Vista Installation 2 08-03-2006 06:52 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59