How to configure Active Sync in HTC HD mini if the SSL certificate has problems - General Questions and Answers

Hi Admins,
I regret if i have repeated this, but i am not able to you my phone with my office outlook until this is resolved, appreciate any help.
Prob Details:
We use a web based outlook at work, problem is the security certificate of the site has expired and our org has issued a customized certificate on its own, which is by default not recognized by any root CA.
Problem when i key in the configuration and try to sync.. i get an error like " server certificate error / expired contact administrator "
Is there a way of by passing this and configuring the active sync to work.
PLEASE HELP.....
Thanks and regards,
Anurag Mitra

Anyone there. Please some help

Related

Problems to syncronize contact with active sync

I can't be able to syncronize the outlook contact through active sync. Nobody can help me ? Thanks
I think you need to give a lot more information for anyone to even begin to suggest anything.
Have you searched these forums for "activesync" to find similar errors.
If so, then give the following information
1. What version of Activesync
2. What version of Outlook
3. Do you get an error message. If so what
4. Can you browse the device through Activesync
5. Did it used to work with this PC or has it never worked.
6. Do you/can you sync with another PC
The versione of active sync is 4.2 ;
Microsoft outlook (Not outlook express)
I don't receive an error message ;
Yes i can browse the device and i can sybcronize the calendar ;
It work with another pc but don't syncronize only the contact with my office pc.
Thanks
I think this is the same problem that i'm looking the solution for. You want to synchronize contacts with two PCs? one in your home and 2nd in your office? I would also want to do that. Can someone give more information on this one? If someone can help please send PM to me, I'm TyTN user so I don't often check this area of forum.
Thanks in advance for any help

Synchronizing error when retrieving from Exchange 2003 SP2 - error: 0x85010004

Currently using exchange 2003 SP2. My s710 will not retrieve mail for my account or any new account created. Funny thing is it retrieves for another user he currently uses a wm5 device.
I have checked the global setting on exchange server and all necessary sychronizing options are on
Does anyone know how to fix this error: 0x85010004
Your Account does not have permissions to sync with your current settings. Contact your Microsoft Exchange administrator.
Thanks
Hi !
Your Exchange Server Use Https ¿?
I Live This Problem And The Solution Is Install The Secure Certificated On The Pda...
Sorry For My English I Live In Mexico...
Or try, when connected to your PC to open Internet Explorer (on your mobile). You'll have to give a username, password and domain (don't forget to check the remember password checkbox).
Then, it should work without problems.

Enforce Security Poilcy (Email Synchronization Problem)

Dear XDA Developers,
At last the company where I am working decided to use mobile email. All my colleagues with different brands of PPC are able to synchronize except me. I tried to synchronize my email from the another PPC then the PPC pops out with xchange server xxx.xxxxxxx.xxx must enforce security policies on your device to continue synchronizing. Do you want to continue? then I click OK and I am able to synchronize. But, with my P535 it is not poping out anything, it only pops out error code 85010004. I tried everything but no use. Since we are a global company, it is not allowed to make any setting changes in the exhange server because I am the only one having this problem.
Thanks alot in advance,
OmaricO
This is a warning that to use the facilities on Exchange you need security policies on your device enforced.
What this means in English is that you are forced to have PIN code protection on your device - ie enter a password/PIN number to be able to use your device.
I use a simple PIN and once this is set, you should be able to sync with exchange ok.
Hope this helps.
I tried doing that. The problem that my ASUS P535 is not giving me the prompt xchange server xxx.xxxxxxx.xxx must enforce security policies on your device to continue synchronizing. Do you want to continue? it giving me the error code 85010004. But when I try to synchronize with my JAMIN (Prophet), it pops with the prompt and I click OK and I am able to synchronize. Both PPC are running WM5.
Thanks for your replies in advance
I managed to solve the problem by upgrading to WM6. Thanks alot.
hi, everybody!
dears, I have asus p750 and the same problem persists on wm6, wm6.1...
so, if somebody could solve the problem, it would be great.
maybe, there is some possibilty to export registry keys from
525 asus to 750? they have similar roms
thanks!

Issues with OTA sync; AT&T Kaiser just recently purchased and rom upgraded

Ok I have wrestled with this for 2 days straight.
I had issues with this with my CFO's windows mobile device but at least his was giving me a specific error message.
My Tilt has the latest Dutty ROM upgrade (Dual Touch), I haven't been able to get my exchange server synced OTA.
I run a Exchange 2007 Enterprise environment. Everything on the server side is fine. My OWA url is https://webmail.firethornmobile.net. All I get is waiting on network after 2-15 minutes.
I have soft reset, deleted the PC partnership, taken my connection off of auto and tried both my work connection and isp.
I'm starting to suspect it maybe the ROM upgrade but it was doing the same thing when I first started the phone.
Please help.
OMA enabled?
Do you have the OMA enabled? Do you have the server root CA installed in the tilt (I am assuming you are using secure method for OMA)?
I have flashed Dutty's dual touch v2 and I don't have problem to get emails through OMA services.
Do you ever get the other PDA sync with email before? From the error message, it seems the Activesync in the Tilt can't talk to the exchange (front end) server at all.
Yes on Exchange 2007 OMA is enabled natively. In the middle of seperating data centres from our sister company.
We just got bought by Qualcomm so we never bought a cert from Verisign. I am using a self sign cert from our exchange server ( I have to turn SSL off on the pda side.
This has never worked, I already called Cingular and they said if I can get webmail from gmail and hotmail then it isn't their problem.
I have installed the self signed cert on the handset.
OK, you don't need to install the self-signing cert in the PDA, but you need to install the root cert of the self-signing cert in the PDA.
Usually, a server cert or user cert has a root authority (CA), you need to install the CA cert in the PDA, not the server cert.
If you can install a window server (2000 or 2003), you can enable the certificate authority server and issue your exchange server a server certificate. In this case, you will have your own root certificate. I don't suggest you to use Verisign's certificate because everyone has Verisign's root certificate can try to "play" with your OMA server.
However, the error message is still showing that the Activesync in PDA can't reach to the OMA at all.
BTW, the push email doens't work if it's not on the SSL connection.
I apologize that I wasn't clear. Its is the root cert from the CA (Which is our DNS server).
I realize the message means that it isn't getting to OMA. I have been on the phone with AT&T and HTC aboutthis and no one can tell me why it can't connect. I have been given tons of different network settings by AT&T and HTC and nothing changes. I get different error messages but when i put everything back to the way it should be it still gives me this generic message.
I have configured my CFO's handset to get email (Its Palm Treo with WM 6.0) and even though that was a pain in ass it still works (just as good as his Blackberry) and he has SSL unchecked as well.
In that case, you can try to see if you can reach to the OWA from your PDA, if it can, you shall not have network issue.
BTW: the connon name of the server cert must be the same as your public domain name, otherwise, the Activesync will still reject the connection.
Apex i ITR said:
I apologize that I wasn't clear. Its is the root cert from the CA (Which is our DNS server).
I realize the message means that it isn't getting to OMA. I have been on the phone with AT&T and HTC aboutthis and no one can tell me why it can't connect. I have been given tons of different network settings by AT&T and HTC and nothing changes. I get different error messages but when i put everything back to the way it should be it still gives me this generic message.
I have configured my CFO's handset to get email (Its Palm Treo with WM 6.0) and even though that was a pain in ass it still works (just as good as his Blackberry) and he has SSL unchecked as well.
Click to expand...
Click to collapse
I agree with the poster above. I have this exact same set up at my company and it does work. The certificate has to be the external name of the exchange server. If this does not match the PDA will never sync. Check your certificate and make sure the FQDN is correct.
I just check your exchange server from the URL you posted above, your OMA and OWA are working, but the certificate's common name is not the same as the public domain name.
Try to re-issue the certificate, it may just work.
Thanks guys. I'll try that.
Webmail does work from the handset. I don't know how I got my CFo's working to be honest if its flaking on the name of the cert but I'll try that and let you know. I was about to hard reset this thing and leave the cooked ROM's alone for a while. Hopefully this resolves it.
From my experience dealing with Acticesync in the PDA, it's very picky of the name of the certificate. I think that's security reason. The Activesync doens't accept certificate that common name doesn't match the public domain name.
When I use the IP address for test, I have to get a certifiate with the IP address as its common. So I believe that's the certificate's problem, not the cooked rom.
I still suggest you to get your own CA and certificate, in that way, you have more control even debugging this problem.
I feel like a moron asking but how the hell do I change the common name.
You can't change an existing certificate, you have to re-issue a new certificate.
I guest you can't do it by the self-siging certificate, but I am not fimiliar with the self-signing certificate. Get a WIN server machine and install the CA server, after that, you can issue a certificate.
Assumeing you have a CA server ready:
1. Request the certificate from exchange server: you will have a chance to enter the common name of this certificate.
2. Generate a certificate from this certificate request from CA server
3. Import the certificate back to the exchange server.
If you can't get a WIN server as CA server, I will need to ask my colleagues about the free CA server he used from the Internet.
My DNS box is a CA server (started the service on that).
I'll try that then (I hard reset and I now I have an error stating I'm not authorized).
I'll let you know if it works. Thanks.
Ok I believe I did it right but I still get tha error (When connect via usb cable) and I still get the waiting for network message.
When you connect to the USB cable, you have to "allow" the Internet access pass through from the Activesync in the PC, otherwise, it won't reach out to the Internet at all.
Try to connect to other web site to see if you have a good internet connection or not.
Some updates. I made sure the cert is the right common name. I noticed that after I install it on the handset it doesn't put the cert in the root tab...only intermediate. I installed the ca server's cert as well (That went into the root tab).
Im leaving ssl checked and now I get 0X80072F17.
incorrect common name
Your common name is still not correct, it shall be "webmail.firethornmobile.net" only, but you put "http://" at the begining and "/owa" at the end, it not correct.
You have to issue the server certificate one more time with "webmail.firethornmobile.net" (without quotes) as the common name.
Also, when I check the Certification path of your certificate, I don't see this certificate is under any root certificate. Properly you need to check your CA (DNS) to see if it's setup properly.
Hey,
Use this site to figure out the errors you are getting on your phone. http://www.pocketpcfaq.com/faqs/activesync/exchange_errors.php
Also are you the Exchange Admin? If so enable verbose logging so that you can see what is going on with exchange as the connection comes in.
Also if you want to make sure it is not the cert you can "Enable" SSL on the phone and then reg hack it so that it doesn't check for the cert. this will allow you to see if it is a cert problem.
Let me know if you need any help with that. I"m an Exchange Admin and i work with Active Sync day in and day out.
Tried Fix Suggested on Pocket PC FAQ Site
I think this is ON TOPIC. If not, please advise and I will repost elsewhere.
I flashed my phone with the Dutty Beta 2 Touchflow ROM for Tilt. I am getting the following error and have tried the matched solution from Pocket PC FAQ:
0x80830003 N/A Synchronization failed. If the problem continues, contact your network administrator.
1. The Exchange server is configured to require client certificates.
1. On the Exchange server, launch Internet Services Manager. Right click on the Microsoft-Server-ActiveSync virtual directory and choose Properties. Select the Directory Security tab. Click the Edit button in the Secure Communications section and select the option to “Ignore client certificates.”
I continue to get the same error even after dumping the device through the exchange server.
My System Admin thinks that there is something wrong with the version of ACTIVE SYNC provided in the ROM used to flash the device.
Any thoughts/direction you could point me in or is there any other info you need?? Is th

[Q]Lumia 820 Exchange Problem [solved]

Hey guys,
i am new here, but i've been watching this forum a long time for now on.
At this moment I have a problem with setting up an Exchange for my mail acc (university).
Setup going fine and it can be completed, but after some time (30-40min), windows asked me for password because of my
password that i typed in is wrong.
The curious things are, I can read my mails after retyping the password or when I hit the return key.
Does anyone have the same problem?
Thanks in advance
For me there is no problem, I setup my private Exchange (2010) Account and everything work well.
On WP8 with my Lumia 820, I received only a warning regarding the certificate like on other OS's and that was it.
Oh really?
I have installed the certificate from my university but i didnt change anything .
Is there a option that an administrator should do to allow WP8?
I tried to search on my Exchange (2010) for an option for WP8, but cant find one.
Microsoft said that WP8 will be supported by every Exchange Server, I found this by Google.
Which Version of Exchange Server do you have on your University?
We have Exchange 2003.
Okay, I tried Google and found that it must work.
From Windows Phone 8 Security Overview:
Windows Phone 8 is compatible with version 14.1 of the Exchange ActiveSync protocol and supports synchronizing email, calendar, task, and contact information with Exchange Server 2003 SP2 and subsequent releases or with Microsoft Office 365.
One post on XDA, but another problem:
http://forum.xda-developers.com/showthread.php?t=1912071
The only thing maybe, if you have self signed certificates at your university, you have also to install the Root-CA certificate!
And maybe is the Exchange 2003 not up to date, SP2 installed?
Thanks for your help and replies.
I don't know which SP is installed :-/
I checked the homepage of my university and i found a root CA, that i've installed on my phone.
At the Homepage I also found that Windows Phone is supported.
After round about 40min, the ask for retyping the password appears .
It's really strange.
EDIT:
I found this page: http:**social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/6999b88e-ada4-45c5-ad33-55905db0f0df/#a1bacca1-40ac-4e09-af79-1178fad860b5
And finally i wrote an email to our support with this link.
EDIT 2:
I've got an email from our support, they have changed the settings (settings can be found in that link above).
Until yet it worked perfect.
Thanks for Help!
el-bart said:
EDIT 2:
I've got an email from our support, they have changed the settings (settings can be found in that link above).
Until yet it worked perfect.
Thanks for Help!
Click to expand...
Click to collapse
Glad to hear you solved it!!

Categories

Resources