PDA

View Full Version : WM6 and Personal Exchange certificates


pkley
27th March 2007, 01:30 AM
Anyone know if personal exchange certificates are now working in WM6? I'd rather not pay $100/yr if I don't have to...

DeniaL
27th March 2007, 03:21 AM
I believe so, I use a personal exchange certificate and never had a problem with it in WM6...

pkley
27th March 2007, 04:47 PM
Hmm, well I wasted last night trying to get ours to work. I was able to export the .cer and install it, but it kept saying "invalid security certificate".
One other item to note, our webmail address is as follows blahblah.wahwah.com/exchange.
Is that causing the problem?

ibanyard
27th March 2007, 05:01 PM
Hmm, well I wasted last night trying to get ours to work. I was able to export the .cer and install it, but it kept saying "invalid security certificate".
One other item to note, our webmail address is as follows blahblah.wahwah.com/exchange.
Is that causing the problem?

I doubt it..

Are you sure the backend (exchange/isa publishing) is all correct?
Next up, you'll probably need to export the root certificate and import that on to your device as well as the cert thats been used to publish exchange. You can use owa to test all this... If you browse to https owa url you need to see all green (eg name matches, certificate valid (eg not expired), and trusted (including any root certs)). Ensure root certs are in the correct store when you import (I usually deselect the place certs automatically option).

The other thing is to check on how the cert was exported... I dont have the process to hand, but its on isaserver.org and MS....

randomelements
27th March 2007, 05:20 PM
All I've ever done is install the root certificate on the phone and everything works fine WM5/WM6.

randomelements
27th March 2007, 05:22 PM
All I've ever done is install the root certificate on the phone and everything is ok (WM5/WM6) although I'm not behind ISA

eagle 1
27th March 2007, 06:00 PM
Your certificate name would have to match exactly what you have set up on exchange/server. In your example, certificate is named blahblah.wahwah.com... it has to be exactly the same name. So in your PDA the server name would be blahblah.wahwah.com. not blahblah.wahwah.com/exchange

Good luck.

adebilloez
27th March 2007, 08:04 PM
Personal certificate you mean : Client certificate ?

-> work fine with YES an easy install (no need anymore complicate activesync process or Jacco dds....)

Woldcard certificate (*.toto.com also working fine!)

-> yes after a missing feature in WM5!

pkley
29th March 2007, 01:26 AM
Ok, here's what I did.
Opened up my webmail page which is abc.defg.com\exchange
Clicked on the Lock and opened up the certificate. Under Certification Path it says abc.defg.com - no \exchange
Under Details I clicked on Thumbprint and Copy to File as a .cer
I named that file root.cer and put it in the directory on my 8525 and ran it, it installed.
I'm sure I'm missing several steps, but a lot of the threads are way over my head or not applicable to my situation. Any advice, or step by step would be greatly appreciated.