Re: Self signed certs sync issue, WM5 + SBS2003



Check out http://cert.startcom.org/. You will be able to create signed certificates for your Exchange server. The catch is that the root certificate needs to be installed onto your WM5 device. Luckily, you can download one from them to install on your device. (I found that I needed to rename the file extension from .der to .cer in order to install it.)

-jpmahala


"Rosewood" <rosewod@xxxxxxxxxxxxxxxxxxx> wrote in message news:Or54C1#NGHA.2472@xxxxxxxxxxxxxxxxxxxx:

Let me dog pile on this one too!

SBS2003 using self signed certs. WM5 device on the WLAN trying to sync with
the exchange server. Sync works fine until SSL is enabled.

1) At first I got "0x80072f17" which means it didn't like my server's
certificate. I tried to disable cert checking in the registry
(HKCU\Software\Microsoft\Activesync\Partners\Secure , DWORD value of 0) and
that didn't do it so...

2) I exported my personal cert from my PC that was issued by my sbs2003
server. (Issued to my name, Issued by my current domain, valid expieration
date, with the intended purposes of EFS, Secure Email, and Client
Authentication) and imported that into my WM5 device. It showed up in the
certs window. I did a soft reboot, removed the server from activesync, soft
reboot again, synced and this time I got a different error, 0x80072F0D,
saying that my cert is invalid.



...

So, how do I make a valid certificate and get it out there so I can sync
using SSL?

.



Relevant Pages

  • Re: Certificate Services and Synching with Exchange
    ... Yes, installing the cert and self-signing worked, but only because ... Yes, I had to manually export and install it, but it was trivially ... You export the cert from the MMC to a .cer file. ... Will installing Certificate Services and self-signing a certificate ...
    (microsoft.public.pocketpc.activesync)
  • Re: Terminal Services over a VPN
    ... Create a certificate request and submit it to godaddy in order to obtain a public cert. ... You can use the wizard in IIS Manager for this by creating a new website that matches the above name (on your TS server), right-click and choose properties, directory security tab, server certificate button. ... After the install you can stop or delete the website created above since you don't need it for anything. ...
    (microsoft.public.windows.terminal_services)
  • Re: Web Certificate for IIS Server on SBS Domain
    ... and installed the free 30-day certificate on my site. ... instructions to install Certificate Services. ... If I can find a way to issue my own cert without risking my SBS setup, ... > Server instead of the defaults from Server 2003, and when things blow up, ...
    (microsoft.public.windows.server.sbs)
  • Re: CertSrv Question
    ... In my case as posted earlier I didn't install a stand alone CA, ... In effect I want to revert everything on the domain to just before the root ... it replicated a certificate to the ... >>>The reason most likely is that the CA cert is still there in the NTAuth ...
    (microsoft.public.win2000.security)
  • Re: WM5, VPN via PPTP/MPPE, and direct connection to Exchange
    ... will be secure between the device and exchange server. ... generated/self signed cert then yes you will need to install the root cert on all the devices. ... client-end configuration option? ...
    (microsoft.public.pocketpc.phone_edition)