Reply
Contributor
Treo 755p (Sprint)
ctsaudits
Posts: 22
Registered: 04-11-2007
0

755P EAS with Exchange 2007 SP1 using self-signed certificate

I'm so grateful to Imaginos who has helped me with this. I was pulling my hair out for a few days that I couldn't get the certificate to install. Now everything works, I just wanted to document the whole thing for people who are still having trouble or will be having this trouble. Here're the things I did.

 

Used Palm Certificate Modification Tools and generated certs.pdb file. Unable to install on device though.

Error: Already exists: C:\Program Files\Palm\KongC\Install\certs.pdb
         Install synchronization failed

 

Last year when we were still using Exchange 2003, I did try to install the old certificate so my Treo can use EAS with SSL, but the EAS with SSL never worked. I guess the old certificate was installed though thru the modification tool. So I downloaded and installed FileZ and followed instruction from http://forums.palm.com/palm/board/message?board.id=activesync&thread.id=1489, deleted CertMgr.PDB, softreset, ran quick install again for the Cert.pdb, log said deleted a file and 1 install was successful.

 

Tried EAS with SSL, still same error: "There was a problem with syncing. SSL error: No trusted root certficate authority list" and in detail option " AirSAMState machine 1913 14721". Softreset again, deleted both Cer.pdb and Cert.pdb on Treo using FileZ, deleted both files from Palm backup folder as well. Softreset, hotsync, no errors. Installed Cert.pdb again using Quick Install. No luck installing certificate, getting a different error "- Invalid handheld file deleted: C:\Program Files\Palm\TEST\Install\certs.pdb OK Install with 1 message(s) ", no cert installed.
Noticed Sprint software 1.04, downloaded and installed 1.07. Still unable to install certificate. "Invalid handheld file deleted."  

 

I tried numerous times with the certificate install, but still the same error "Invalid handheld file deleted". After reading so many posts here, I know Imaginos is very knowledgeable with this stuff and out of desperation, I sent him a PM for help. And he did. I'm a happy camper now. I can't thank him enough.

 

I sent him two certificates, one was from exported from IE --> Tools --> Internet Options --> Content --> Certificate --> Trusted Root Certificates, the other was distributed from my company Remote Web Workplace. He then sent me back a certs.pdb. He said he used Palm Sync Manager v7.0.2 and my first certificate to create the new certs.pdbHis certs.pdb byte count was 430 bytes and mine was 78 bytes. My certs.pdb was generated from Palm Desktop 4.2 which I reinstalled lately from the sprint cd. I followed his directions as below and sure enough the certs.pdb installed successfully this time.

 

-          backup your device-          hard reset it-          doubleclick the certs.pdb file on the pc you use to hotsync your Palm with. (this stages it for install to your Palm on the next hotsync)-          hotsync your Palm-          soft reset the device

-          browse to https://remote.mydomain.com and note the lack of certificate errors  (I did not get any certificate error)

-          configure Versamail with your Exchange account info - <name>@mydomain.com, <pw>, Server = remote.mydomain.com, type=EAS (during our recent server migration from sbs2003 to sbs2008, I know server address has to change from mail.mydomain.com to remote.mydomain.com, a custom dns was created for remote.mydomain.com to point to the same ip mail.mydomain.com uses. I don't know why we had to change the name though. All I know was when I used remote.mydomain.com on a windows mobile device, it worked. The old server address mail.mydomain.com didn't.)

-          Test button should now report success. (Yes, it did).

 

After all that, my Treo started to say receiving for a long time, then it timed out with another error "

“There was a problem with syncing. Can’t connect to server. Please check your network or server settings and try again. Details: AirSamStateMachine.c 1913 4628”

 

Looks like the next thing to tackle is the default Exchange Security Policy. Once I removed the default security policy from the Exchange Power Shell, my Treo starts to sync. Yeeha!

 

Again, I can't thank you enough, Imaginos.


Post relates to: Treo 755p (Sprint)


Post relates to: Treo 755p (Sprint)


Post relates to: Treo 755p (Sprint)

Regular Contributor
Centro (Sprint)
Imaginos
Posts: 102
Registered: 05-25-2008
0

Re: 755P EAS with Exchange 2007 SP1 using self-signed certificate

I love a happy ending to a certificate problem thread.


Post relates to: Centro (Sprint)

Regular Visitor
None
No_Happy_User
Posts: 3
Registered: 03-28-2009
0

Re: 755P EAS with Exchange 2007 SP1 using self-signed certificate

Imaginos.

 

I'm not an IT person. But I figured out my company uses a self-signed SSL certificate on the Exchange. I've read so many threads in different forums where it explains how to import the SSL certificate to the Treo using the Palm Certs Manager Tool. I've followed the procedure countless times. I've performed hard resets on the Treo and no still no results. The error I get is the classic SSL error: No trusted root Update Certificate Authority List.

 

I recently changed my job. In my previous work experience I had a Treo 650 and had the experience of using Palm OS at its max. For my new job I bought a Treo 755p and now I'm frustrated. What's really strange, I have a co-worker that has an iPhone with EAS configured and works fine.

 

Have you come across anything similar?

 

Regards,


Post relates to: None

Regular Contributor
Centro (Sprint)
Imaginos
Posts: 102
Registered: 05-25-2008
0

Re: 755P EAS with Exchange 2007 SP1 using self-signed certificate

When I started out with a Centro, I had the same issues - and to make it worse, the tool we use now wasn't widely known at the time.  It took even longer for the Centro to be added to the list of devices it worked with.  In the end, I dove in and fought with it til I got it to finally take the Root CA I needed.  In the end, all it took was a hard reset followed immediately by a hotsync where the correct certs.pdb file was imported into the Palm OS.  A quick test of Blazer to that web server's SSL page produced no errors and I was finally on the road to getting EAS to work.

 

Reading your post, I get the feeling you're hitting a road block because you're importing the SSL cert.  That's not the one you want to import.  You want the Trusted Root CA certificate.  PM me with details of the server you're trying to EAS with and I will take a look at the SSL cert and try to direct you to where you can get the Root CA cert.  If I can get it myself, I'll generate a certs.pdb file for you that will need to be hotsync'ed into your handheld (after a hard reset, of course) and it should clear that dreaded "no trusted root!" error.

 

Regards,

Bill


Post relates to: Centro (Sprint)

Contributor
Treo 755p (Sprint)
ctsaudits
Posts: 22
Registered: 04-11-2007
0

Re: 755P EAS with Exchange 2007 SP1 using self-signed certificate

Bill,

I hope you enjoy the gift basket.

 

Christine


Post relates to: Treo 755p (Sprint)

Regular Contributor
Centro (Sprint)
Imaginos
Posts: 102
Registered: 05-25-2008
0

Re: 755P EAS with Exchange 2007 SP1 using self-signed certificate

Sure did Christine!  My teens tore through it and left it looking like a crime scene once I made the mistake of saying "sure, you can have some."  You'd think I would know better by now..

Thanks again for the thoughtful gift.

 

No Happy, I looked at your site and found a few things.  I PM'ed you the root CA you will need to import to your handheld in a ready-to-hotsync certs.pdb file.  The link to download is in the PM.

Also, the SSL cert securing your Exchange2003 server is expired.  That will be an additional problem.  However, your exchange server has the CA running on it and it can be used to generate a new cert for install onto your webserver and get things back up and running.  I can help with that if your admin needs an assist.

My email is in the PM I sent you.


Post relates to: Centro (Sprint)

Newbie
Treo 755p (Sprint)
bethannes
Posts: 4
Registered: 02-05-2009
0

Re: 755P EAS with Exchange 2007 SP1 using self-signed certificate

It seems that a lot of the problems with syncing to e-mail using SSL certificates is associated to the fact that the Palm OS does not support 256-bit SSL.  My company changed their SSL about the 1st of the year and I could not longer get my e-mail.  I tried everything and ultimately found out that problem was the 256-bit SSL.  Does anyone know if Palm is going to fix this?

Regular Contributor
Centro (Sprint)
Imaginos
Posts: 102
Registered: 05-25-2008
0

Re: 755P EAS with Exchange 2007 SP1 using self-signed certificate

Would love to be wrong, but it sure looks like Palm has made it very clear that they don't care about the problems of the old handheld line. All effort is going into Pre at this point since they can't see investing anything in the old phones. They sold what they sold at this point. I'm not happy about it either, but I jumped to a WinMo phone for my daily use, so I can at least keep up with the times - at least if my hardware supports it.
Regular Visitor
None
No_Happy_User
Posts: 3
Registered: 03-28-2009
0

Re: 755P EAS with Exchange 2007 SP1 using self-signed certificate

Imaginos,

 

The IT personnel just issued a new self-signed certificate. I follow the procedure you sent in the PM and still getting the SSL error message. I talked to the IT people and they are considering to purchase a public trusted certificate. I believe there are some certificates that do not work properly with Palm OS. Do you know which ones do work properly?

 

Regards,

Newbie
Treo 755p (Sprint)
mallorys
Posts: 1
Registered: 07-11-2011
0

Re: 755P EAS with Exchange 2007 SP1 using self-signed certificate

Hello, I have tried this and many other suggestions from other threads and still getting the no trusted root certificate error. We don't really have an in-house IT person anymore so I have a programmer who is trying to set it up on our server. He says the cert is not in "IIS", though and I'm wondering if this is my issue. Other users have newer phones, non-palm OS's so I think that's why I'm having an issue and they aren't. Any suggestions? TIA