Reply
Moderator
HP TouchPad (WiFi)
Ridius
Posts: 1,167
Registered: 03-21-2007

Re: Pre complains about SSL certifcate on exchange server

Also, check to make sure that your Issues To field or SAN fields match the URL of your web server as that can cause SSL errors as well.
Ridius

Please do not send me direct messages unless I ask you to. Random Direct Messages asking for support will be ignored. Please post your question/help request in an existing forum thread or create a new one so that everyone can benefit.

If you like IRC, feel free to drop by #webOShelp on Freenode. I hang out in there quite a bit.
Visitor
Treo 800w (Sprint)
kkasten1
Posts: 4
Registered: 08-12-2008
0

Re: Pre complains about SSL certifcate on exchange server

[ Edited ]

The steps posted by UDS worked great until I got the message:

 

    ERROR: The mail server requires security policies that are not supported.

 

I believe this is a PIN.   Any suggestions to get around this problem?

Message Edited by kkasten1 on 06-07-2009 09:10 AM
Contributor
Pre p100eww (Sprint)
SalladDazed
Posts: 20
Registered: 06-06-2009
0

Re: Pre complains about SSL certifcate on exchange server

Apparantly, there is currently no support for PIN or device locking; if these policies are enforced on your EAS server, the Palm Pre will not work.  I have been reading the PreCentral forums on forums.precentral.net for hours, and several people mention this (though I cannot provide any official link).

 

It seems clear, though, that EAS is not fully supported yet.

Visitor
Pre p100eww (Sprint)
further001
Posts: 2
Registered: 06-08-2009
0

Re: Pre complains about SSL certifcate on exchange server

I have tried all these methods now, the cert manager shows the cert installed, but I get the same error about date/time.

Kind of a deal breaker if they can't get it to work.

Contributor
Pre p100eww (Sprint)
Nando09
Posts: 11
Registered: 06-06-2009
0

Re: Pre complains about SSL certifcate on exchange server

I myself have the same problem, tried pretty much all i've seen in the forum except for buying a new cert and installing it on the server. At one point the phone started saying that it couldnt validate the account, but after a restart it went back to the SSL certificate error. Is the date and time correct?

 

This is very frustrating...

Contributor
Pre p100eww (Sprint)
LuckyVic
Posts: 15
Registered: 06-07-2009

Re: Pre complains about SSL certifcate on exchange server

I spent the weekend trying to test and figure out what was going on.  I found that if I named the email server (the name after HTTPS:// in the setup) the same as the certificate name shown in the certificate manager (Launcher>Device Info>More Info>Menu>Certificate Manager), that the error would go away.  The problem for me was that the cert name in the cert manager was different than the mail server address (in my case server.[domain].local instead of mail.[domainname].com).  The process that it appears to use is:

 

1) check for certificate...

2) does the CN match the HTTPS:// in setup?

3) if no, use error "Check certificate, date and time not correct " (or whatever it is) - - - if yes, then go to HTTPS://

4) does exchange require pin security?  If no, proceed to sync - - - if yes, use error "security policies not supported"

 

So, I looked closer at the cert and it held multiple common names (CN) for the cert.  It appears that EVERY OTHER DEVICE can filter through the list of common names and use the one that works.  The Pre on the other hand uses only one (whether it is the first or last, I don't know). 

 

So, there are two options to the certificate problem (i guess the 3rd is you could return the phone):

 

FIRST SOLUTION

=====================

1) Check the cert name in cert manager. 

2) If it is a DNS resolvable name (i.e.  [mail].[mywebsite].[com]) then change that setting in your exchange setup in the mail server field next to the HTTPS://

 

This will fix it only if your IT admin has you with permissions on the domain used.  It is possible that an alias is used on other domains

 

SECOND SOLUTION (what I had to do)

=================================

1)  make sure that your Certification Authority is installed.  You can do this by going to START>ADMINISTRATIVE TOOLS>CERTIFICATION AUTHORITY - OR - on a computer on your network using IE/Safari/Firefox and typing http://server/certsrv.  If the page is found, then you are installed, if not, then you will need to have it installed.

 

*****NOTE:  SBS 2003 WILL ISSUE A CERT TO THE IIS WITHOUT THE CA ROOT.  THIS APPEARS TO BE THE PROBLEM WITH THE SELF GENERATED CERTS THAT I HAD

 

2) If you don't have it installed, go to this topic, it was well written for step by step instructions of how to install, create the cert request, create the cert and install the cert (it took me about 30 min).   http://www.msexchange.org/tutorials/SSL_Enabling_OWA_2003.html

 

****NOTE:  IF YOU ALREADY HAVE A CERT ON IIS, YOU WILL NEED TO REMOVE IT AS THIS IS THE "FLAWED" CERT BEFORE YOU CAN REQUEST A NEW CERT.  YOU MAY BE ABLE TO REINSTALL IT IN ADDITION TO THE NEW CERT, BUT I DON'T KNOW

 

3) open https://mail.domain.com/exchange on your computer - view details of the cert and save the file to your desk top - if you use a laptop, you can also install it on  your laptop to use for use when out of the office (it is also a nice back-up that you can use to get it again later if necessary).

 

4) plug in your Pre in USB mode.  

5) drag and drop the cert then disconnect the USB cable

6) go to cert manager

7) tap the "sun" icon at bottom left corner

8) tap the new cert file you saved in USB mode

9) confirm that the new cert shows up with the correct mail server name

10) go to the mail program and set up the exchange account

 

The above will create a TRUE root cert (not IIS Domain Root Cert) that the Pre can work with.

 

Really, I am not sure how/why Palm overlooked this possibility as they supposedly claimed to not want to sell to companies that need strict security requirements.  To me, that means a small / medium business that has limited IT support (either as-needed, pay as you or green IT guys with limited knowledge).  So, why they wouldn't test the Pre's in that environment, I am not sure.  I bet that they tested it on their own network that has all the correct, best practice methods in use for cert management.  I guess it is just like the developers that they offended and almost lost their support until the went back and said, "sorry, we really want you to make programs for our WebOS platform.  We have just been paranoid for so long we salivate when the bell chimes."  They just didn't beta test this well enough.  The sad outcome of this is that Sprint will have to deal with all the returns because this simple certificate reading process was only given minimum recognition abilities.

 

But with that said - I am now thoroughly in love with my Pre!!!    :smileyhappy:

 

I am happy to try and help if you need it.  I found a lot of the forum solutions weren't detailed enough, so feel free to  contact.

Contributor
Pre p100eww (Sprint)
SalladDazed
Posts: 20
Registered: 06-06-2009
0

Re: Pre complains about SSL certificate on exchange server

LuckyVic, this is a very good, well-written, and thorough post.  I am familiar with these procedures, and have been through this many times in the past (on different hardware--most notably Palm Treo's running the Palm OS) as well as this past weekend and today without success.

 

Despite having a cert that resolves to a public IP address, works in IE6, IE7, IE8 and webOS 1.0.1 and 1.0.2 (i.e., the site/OWA can be browsed, the prompts for a cert install are acknowledged, then all is happy) it does not work on the Pre.  The cert can be manually copied over USB as you suggest, then installed and trusted via the Certificate Manager, or browsed via OWA using the webOS browser. I cannot get contacts, calendar, or e-mail to flow.  Incidentally, all works flawlessly via the browser and OWA, just not EAS.

 

But--to be clear--have you successfully configured EAS to work with all three apps and synch seamlessly, all while using a self-signed cert?  Are you sure things are synching, and not simply copying one time and one time only (this has been reported by a number of people)?

 

Just curious--there may be more to this story certs alone. The error messages are so general it's quite difficult to troubleshoot.

Contributor
Pre p100eww (Sprint)
LuckyVic
Posts: 15
Registered: 06-07-2009
0

Re: Pre complains about SSL certificate on exchange server

SalladDazed - Yes!  Everything syncs back and forth.  Both email and calendars were automatically set up when I moved to set them up.  No extra info was needed.

 

I have also read the other posts, so I was nervous and checked both contacts and calendars.  Although in my contact testing, I had to initiate a sync for it go through - that is, it didn't go through after I left the contact with in 1-2 minutes.  I got nervous and hit sync to make sure that it went both ways.  I am sure that if I waited a little while it would have done it.  BUT THEN AGAIN, IT COULD HAVE BEEN ENTOURAGE. I say that because it is not real "push" on some things, i don't know why, but it works well enough that i only force sync Entourage when I am anticipating something important.

 

Check your cert on your desktop/laptop and see if there are multiple CN's.  If there are, it is my opinion that is most of the EAS problems (except teh PIN issue for some) people are having.  The reason i suggest this is that we have used the cert we dumped today for about 5 years for OWA and 2-3 for EAS on our MS based phones without a hitch - no web issues, until now.  For some reason the Pre can only read/accept one CN on a certificate and for EAS to work it needs to match the HTTPS:// address.  Does your cert CN in your cert mgr match the HTTPS address you are using in EAS sync?  If it is, then man there are a lot of kinks...

 

Good luck.  Let me know if you have any clarifying questions. 

Visitor
Pre p100eww (Sprint)
melee70
Posts: 2
Registered: 06-08-2009
0

Re: Pre complains about SSL certifcate on exchange server

I also have installed the cert and successfully viewed OWA via the web browser but have no luck getting the email account setup.  I continue to get the "unable to validate account settings" error.  I dont even know what this means as far of diagnosing the problem.  

 

Help! 

Visitor
Pre p100eww (Sprint)
Tim2
Posts: 4
Registered: 06-07-2009

Re: Pre complains about SSL certifcate on exchange server

Hey guys, I decided to invest in a godaddy ssl cert and apllied and received from godaddy a real, not self signed, ssl certificate. I set it up to have the same common name (CN) as I am using for my exchange server.  This is key!  (www.mydomain.com)  The https://   was left out in the CSR when requesting from godaddy. When all was said and done with that process following luckyvics above proceedure I am know connected and syncing with my sbs2003 exchange server using https://www.mydomain.com  Godaddy has ssl certs starting at $24.99 yr for 3 years. Thought it was a worthy investment.  As said in other threads, I believe the problem the pre is having is with self signed certs. Please correct if wrong.  Thanks all for all your help.  If it wasn't for this forum, I would have not received any help. Called palm and sprint several times with no help or call backs.