Re: Certificate Services and Synching with Exchange



Thanks, Chris.

I did get this working after all. To answer my own questions:

1. Yes, installing the cert and self-signing worked, but only because
my device allowed it. During my research, I found that a lot of
devices do not allow self-signed certs because they don't trust the
root. Luckily, the first device I had to work with doesn't have that
problem.

2. Yes, I had to manually export and install it, but it was trivially
simple. You export the cert from the MMC to a .cer file. Manually
transfer that to the device, and double-click it.

3. See #1.

Deane



Chris De Herrera wrote:
Hi,
A self signed cert will work if you want to use that. However you will have
to install it on every device. If you purchase a public cert it will work
without this requirement.

See http://www.pocketpcfaq.com/faqs/digital_certificates.htm for other
issues related to using digital certificates.

--
Chris De Herrera
http://www.pocketpcfaq.com
http://www.tabletpctalk.com
http://www.pocketpctalk.com
http://www.mobilitytalk.com

ActiveSync 4.x Troubleshooting Guide -
http://www.pocketpcfaq.com/faqs/activesync/tshoot-as4x.htm

<deane.barker@xxxxxxxxx> wrote in message
news:1155228879.021953.288710@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
On two separate client domains, I suddenly have a lot of people with
PocketPCs that want to synchronize with the Exchange server. (I
remember the good 'ol days when the network stopped at the firewall...
:-)

In most cases, the PocketPC is failing and complaining about a
certificate it needs from the server. I've seen this now with two
Motorola Qs and another Samsung device, all running the latest version
of the OS and ActiveSync.

A few questions to help me get my bearings:

Will installing Certificate Services and self-signing a certificate
solve this problem?

Will I need to manually export and install the certificate on the
handheld devices, or will the Exchange Server automatically issue /
distribute the certificate to the devices that attempt to connect?

Can I self-sign, or do I need to buy a certificate? I understand the
reasoning behind buying one, but will the handhelds care if the
certificate is purchased or self-signed?



Deane


.



Relevant Pages

  • Re: Terminal Services over a VPN
    ... Create a certificate request and submit it to godaddy in order to obtain a public cert. ... You can use the wizard in IIS Manager for this by creating a new website that matches the above name (on your TS server), right-click and choose properties, directory security tab, server certificate button. ... After the install you can stop or delete the website created above since you don't need it for anything. ...
    (microsoft.public.windows.terminal_services)
  • Re: Web Certificate for IIS Server on SBS Domain
    ... and installed the free 30-day certificate on my site. ... instructions to install Certificate Services. ... If I can find a way to issue my own cert without risking my SBS setup, ... > Server instead of the defaults from Server 2003, and when things blow up, ...
    (microsoft.public.windows.server.sbs)
  • Re: CertSrv Question
    ... In my case as posted earlier I didn't install a stand alone CA, ... In effect I want to revert everything on the domain to just before the root ... it replicated a certificate to the ... >>>The reason most likely is that the CA cert is still there in the NTAuth ...
    (microsoft.public.win2000.security)
  • Re: Require SSL certificate
    ... This will be true if running under SSL. ... Once a web cert is associated with a site, it doesn't need to be installed ... > I have a website and a security certificate, i install the security> certificate for the site. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Mobile User Wants Email downloaded to exchange while offline
    ... Getting the self signed cert on either a Treo 700w or Motorola Q from ... Verizon seems to require the specific installer MS has available for Verizon ... and on the device just launch it to install the cert. ... Thanks - I'm trying to avoid pop connector setup since everyone ...
    (microsoft.public.windows.server.sbs)