Reply
Tech Support
Pre 2 p102una (Unlocked NA)
thetreoguy
Posts: 1,605
Registered: 12-22-2006
0

Palm OS EAS importing Outside SSL Certificates

[ Edited ]

For those interested in how to import their SSL certificate into their Palm OS Treos/Centros, please go here.  Please review the entire documentation for it includes a PDF listing the CAs that can be used for PalmOS and has a notes section to help you avoid compatibility issues that yield those odd Airsam errors.  It also contains the tool to use for importing your certificate onto your Palm OS Treo/Centro.  For a quick read, here are the notes to pay attention to when you or your company wants to create and use a cert for Palm OS EAS:

 

  • This tool is not compatible with Windows Vista.
  • The person using this tool must have administrative privileges on the desktop machine on which Palm Desktop is installed.
  • The user must have the certificate to be added to the device locally available on the PC with Palm Desktop installed.
  • The root certificate to be added to the device must be obtained from the server.
  • GoDaddy Class 2 certificates do not work with Palm OS devices.
  • SSL v3 certificates which rely on the Subject Alternate Name field to do load balancing across virtual site names do not work with Palm OS devices.

 

Also of the reports I've been getting about SSL errors have been the result of users using the new GoDaddy Class 2 cert.  Unfortunately at this time, they are not not compatible since going over exclusively to the RFC 5280 compliance. 

 

If you are following the above and still having SSL issues with EAS, please reply here or make a new post.  I may request your server address and maybe test acct via PM.  Thanks!


Post relates to: Treo 650 (Unlocked GSM)


Post relates to: Treo 650 (Unlocked GSM)

Message Edited by cygnusX1 on 11-12-2008 01:20 PM
=========================
http://www.hpwebos.com
HP webOS is on Twitter and Facebook too, http://www.twitter.com/palm
http://www.facebook.com/palm


HP LOVES to hear feedback. Drop us your ideas at
http://www.hpwebos.com/feedback

6Ts: Six ways to get your HP webOS phone working again: www.hpwebos.com/6Ts
Newbie
Centro (Sprint)
mitemom
Posts: 3
Registered: 11-09-2008
0

Re: Palm OS EAS importing Outside SSL Certificates

Can you help me direct my IT manager to another certificate we can purchase that will work, since GO Daddy doesn't any more.

 

 


Post relates to: Centro (Sprint)

Tech Support
Pre 2 p102una (Unlocked NA)
thetreoguy
Posts: 1,605
Registered: 12-22-2006
0

Re: Palm OS EAS importing Outside SSL Certificates

A good question.

 

With the available information.  As long as the certificate authority is not locked into making certs under the RFC 5280 compliance should be fine.  Those made under the RFC 3280 using the CER format should be fine.  We have provided a PDF listing the CAs that can be used that the PalmOS supports, here is a clicky to that PDF.


Post relates to: Treo 650 (Unlocked GSM)

=========================
http://www.hpwebos.com
HP webOS is on Twitter and Facebook too, http://www.twitter.com/palm
http://www.facebook.com/palm


HP LOVES to hear feedback. Drop us your ideas at
http://www.hpwebos.com/feedback

6Ts: Six ways to get your HP webOS phone working again: www.hpwebos.com/6Ts
Newbie
Centro (Verizon)
kazooless
Posts: 1
Registered: 11-23-2008
0

Re: Palm OS EAS importing Outside SSL Certificates

Any word on getting an update to the Centro so that it will work with the newer RFC for SSL that GoDaddy uses? I have been trying REAL hard to stay loyal to the Palm OS, holding out for that elusive new Linux based baby. But, there have been so many sacrifices we have had to deal with. I just today bought my wife a new Centro (upgraded from Treo 650) and decided to set her up with our Exchange Server that I just renewed the certificate for.

 

I have 30 days to return it to Verizon and choose a different phone. I would hate to do it, but it might be that she'll have to learn to use the BlackBerry.

 

Thanks,

 

kazooless


Post relates to: Centro (Verizon)

Newbie
Centro (Verizon)
Ceoltori
Posts: 1
Registered: 12-18-2008

Re: Palm OS EAS importing Outside SSL Certificates

The PDF file you referenced contains the verbiage for Go Daddy Class 2 Certification Authority (GoDaddyClass2.cer) with an expiration of 6/29/34.  If Palm OS is not supporting Go Daddy Class 2 certificates, why are they listed on the PalmCertModTool Certificate List?

 

I have not personally tried it yet, and all I've read indicate that it's not possible, but I have one reputable person that reports they did it and it worked.   There doesn't seem to be an absolute consensus of information.


Post relates to: Centro (Verizon)


Post relates to: Centro (Verizon)

Visitor
Centro (Sprint)
ccarbaugh
Posts: 2
Registered: 12-30-2008
0

Re: Palm OS EAS importing Outside SSL Certificates

I'm currently using a Go Daddy Class 2 Certification with an expiration of 6/29/34 on Exchange 2003 SP2 with out any SSL issues.

 

My cert was issued on 3/27/2008 from Go Daddy.


Post relates to: Centro (Sprint)

Visitor
Centro (Sprint)
cooljet69
Posts: 1
Registered: 12-30-2008
0

Re: Palm OS EAS importing Outside SSL Certificates

I've been having issues getting my sprint centro (palm os) to work with the EAS function of Versamail. I had the same issue with my sprint 755p I've identified that my employer uses a self signed cert so I've done the certmod per Palm's website and gone from the following error:

 

SSL Error: No trusted root. Update CA list. Contact your administrator if this error persists.

 

Now to one of these errors below: ( Note: it takes a long time to get these errors seems to sit at "Forming Secure Connection" for some time )

 

SSL certificate not accepted due to possible expiration. Check device date & time and re-sync.

 

-or-

 

Error connecting to server. Please check your network or server settings and re-sync.

 

Any help you could provide would be greatly appriciated.


Post relates to: Centro (Sprint)

Contributor
Centro (Verizon)
gmkid
Posts: 14
Registered: 01-08-2009
0

Re: Palm OS EAS importing Outside SSL Certificates

I can't get the link to work that "thetreoguy" refers to in the original post.  It gives me page not found.  I have been having problems with my Centro ever since my company converted to 07 Exchange.  I was told by someone else that looked at my problem that Versamail does not know how to look at other server cert names other than the first one on the list when it goes to search.  I was hoping this modification tool would fix my problem if I could put the server cert from the server right to my Centro.

 

I am not the most technical person around so I'm afraid to do this by myself for fear of messing up my phone.  My problem is, out mail admin are at corporate and I am remote. 

 

I need to get the link that "thetreoguy" gave to work and I need to see if this is something I should try on my own, if I can get the server cert from the mail admin.

 

thanks,

 

Jeremy


Post relates to: Centro (Verizon)

Super Contributor
Treo 800w (Sprint)
Jeffro
Posts: 1,264
Registered: 11-28-2008
0

Re: Palm OS EAS importing Outside SSL Certificates


gmkid wrote:

I can't get the link to work that "thetreoguy" refers to in the original post.  It gives me page not found.


Palm reorganized its web site a couple days ago. Please see this thread for more information on the Certificate Modification Tool: http://forums.palm.com/palm/board/message?board.id=activesync&message.id=5086#M5086


Post relates to: Treo 800w (Sprint)

Regular Visitor
Pre p100eww (Sprint)
realmaven
Posts: 8
Registered: 01-17-2008
0

Re: Palm OS EAS importing Outside SSL Certificates

I am having same problem.  Godaddyclass2 cert. Problem was with the renewal. We worked fine (Centros and I have 755P) in the office for just over a year with Godaddy cert, but our office just renewed the cert last week and when they did, Godaddy updated to the new UTF-8 encoding format.  My guess is those who posted continued success with Godaddy certs will have the same drama upon renewal.  We contacted Godaddy and Palm (level 3 tech support AND Corporate) with no avail.  Palm basically says there is no fix, and Godaddy says it the cert can be rekeyed. HEre is what they sent:

 

"Thank you for contacting SSL Support regarding your issue with your Palm.  The RFC industry standard requires that secure certificates be issued using the UTF-8 encoding format. The Palm Operating System is using the "printstring" encoding format that preceded the current UTF-8 industry standard. Most new servers use UTF-8 encoding, however, Palm devices are still requiring printstring encoding. Palm devices cannot communicate with servers that have SSL certificates installed that use the new UTF-8 industry standard.
If you require a printstring encoded certificate to be issued so that your Palm device can communicate with the server, you will need to arrange to have the SSL certificate signing request (CSR) generated with software that defaults to printstring encoding. Our issuing system will issue a printstring encoded certificate if the CSR was already printstring encoded. 
Microsoft 2003 servers are known to default to printstring encoding.
Once you have generated a new CSR on a server that has printstring encoding, rekey your certificate, install it on the older server, and then export the certificate. This will give you a PFX file. You can them import this file to your new server or convert the PFX file into its separate parts (Private key and Public Certificate) for installation on non-windows servers.
We have provided re-key instructions with appropriate links to CSR generation instructions and our Installation Instructions in our Help Center article located here:
http://help.godaddy.com/article/4976 "

 

Our IT guy received this info.  It appears as if this will not work and I am being told that I need to find a cert that is compatible with the 755P and Centros so that myself and all of the other loyal PALM users in the office can get back to our prior level of functioning. The thing that stinks is we were doing just fine until the renewal and Godaddy will not reissue the old certs.  My office does not want to buy another cert until we can gaurantee that it will work. All I got from Palm was the PDF mentioned in this thread earlier.  That does not help since there is no gaurantee that these other companies have not upgraded in 2009 and will have the same problem.  Palm says their engineers are aware of the problem and are at work on it, but have no idea of a time frame and can not name ONE SSL cert we can use that is guaranteed to be compatible right now!!  I have spent countless hours this last week on this thus far and am no where it feels like!

 

Has anyone recently (THIS YEAR- 2009....not last year with a prolonged expiration date) added a SSL cert to a 2003 windows server and has had success with Palm OS smart phones being able to do exchange active sync?  If so PLEASE share the cert name your purchased this year so that we all can get back to work.

 

I do not understand how a product can be sold advertising it's ability to do something it no longer can do.  Apparently WM 6.-- is having it's own issues with the new certs too.

 

Help!!!   Palm where is your support???

 

Thanks!


Post relates to: Treo 755p (Sprint)


Post relates to: Treo 755p (Sprint)