Re: Treo 700w and SSL Exchange access




<deja3-user@xxxxxxxxxxxx> wrote in message
news:1144350125.682912.28560@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
I have OWA running on a front end exchange server connecting to a back
end server running 2003 (both windows and exchange). I have users
doing client certs over ssl. I installed the root and client cert on
the Treo 700w. Using IE on the treo, I am prompted for my personal
cert, I choose it, then I log in. It all works great.

Trying to configure Active Sync results in the dreaded 0x85010004 code
with "Require Client Certificates". If I turn off "Require Client
Certificates" in the IIS configuration and still use SSL, the Treo can
sync. Does the windows 5.0 software not support email using a personal
certificate?

Does anybody have this configuration working? I'd really rather not
have OWA running to the outside world without a client certificate
issued by me. I've read through the MS whitepaper regarding this, but
it doesn't mention how to do client certificates. The only option in
the Account Setup on the Treo is a Require SSL checkbox, but no way to
choose which one.


Hi - since you're using a FE/BE config, I suspect you aren't using SBS,
which is what this newsgroup is for. I suggest you post this in
microsoft.public.exchange.admin for help.



.



Relevant Pages

  • Re: IIS6.0 + SSL Breaks down!
    ... Well, about me saying I was using client certificates, I did it in the first ... me question now seems to be: how can I increase the "SSL ReadAhead" ... IIS needs to complete SSL ...
    (microsoft.public.inetserver.iis)
  • SSL and IPS (was RE: ssh and ids)
    ... How many simultaneous SSL sessions can be tracked?" ... I assume you're talking about a case in which the client constantly ... If you walk the possible session id space and ... The server chooses the session ID, ...
    (Focus-IDS)
  • Re: IIS6.0 + SSL Breaks down!
    ... Ok, I asked the IIS SSL developer, and he gave me the details. ... bad public specification on SSL make SSL Client Certificates ...
    (microsoft.public.inetserver.iis)
  • Re: Can SSL sessions be compromised?
    ... etc) attachments using webmail during these SSL sessions. ... who the client thinks the server is ... ... part of this has to do with the fundamental digital certificate and PKI ...
    (comp.security.misc)
  • Re: OpenSSL read/write timeouts
    ... This is an example of a SSL client with minimum functionality. ... This SSL client verifies the server's certificate against the ... the SSL server does not request & verify the client ...
    (comp.os.vms)