Hello,
I upgraded my Device to WM2005 v. 1.60. Because my company does not own an official Certificate, I used the DisableCertChk Tool to realize ActiveSync with the Exchange Server directly. But the tool doesn't work with WM2005. The error message is
"ERROR: Unable to open registry key"
Anyone solved this problem already???
Thanks in advance and cheers to buzz!!
ita01
you can either use http instead of https or you can install certificate services, issue your own certificates and install your CA root cert on the device. (though, I'm not sure if AddRootCert.exe will work on 2005, maybe there is also a different way of adding root certs on 2005).
Thanks. I thought certificate check was obligatory. I'll try next to import our self-signed cert.
you just need to put the cert on the device and click it with your stylus in 2005, just like you did in 2003
you just need to put the cert on the device and click it with your stylus in 2005, just like you did in 2003
I have installed the company certificate to WM2005 and can see it under Root Cert's but when I attempt to conenct I get :
Result:
The security certificate on the server is invalid. Contact your Exchange Server administrator or ISP to install a valid certifiacte on the server
Support Code: 0x80072F0D
The cert is a valid cert created from the server using certificate services. It is named teh same as the servers FQDN that I am trying to connect to ie. server.domain.com
Any ideas?
XDA Exec here and same problem ... doing my wig in at the mo !
I could configure the Exchange server and ISA 2004 firewall for none SSL but that'd just be a complete pain in the but.
Any one got any ideas or suggestions please ?
Simply clicking on the cert in WM2005 did not work for me at all. I found a utility that wasnt required in WM2003 but enabled me to import the cert on WM2005 and then connect to the Exchange server.
The utility is called Addrootcert and just needs to be copied to the device and then select the cert.
dsaunder said:
Simply clicking on the cert in WM2005 did not work for me at all. I found a utility that wasnt required in WM2003 but enabled me to import the cert on WM2005 and then connect to the Exchange server.
The utility is called Addrootcert and just needs to be copied to the device and then select the cert.
Click to expand...
Click to collapse
That didn't work for me. As soon as I run it on WM5 I get an error saying "This application was designed for Microsoft Pocket PC 2002 only". Thanks for the suggestion though .
I have found what could be a solution to this problem but am waiting on some clarification here.
disable cert check on WM 5.0
Hello there!
Did anyone actually manage to sort this issue out?
Thanks!
William
Got it working!!!!
All,
I was having the exact same issue as you guys. We use self-signed certs and as that what the source of my problem was.
I was getting the same 0x80072F0D error as the rest of you. To solve the problem I copied the certificates of our root and subroot certificate authorities as well as the cert for our OWA site. I then tried to install the certs by double-clicking on them. However, when I did that, I got the following error on the certs:
This is not a valid certificate file. Please select a valid file.
After looking around the net, I found that the certs were in Base64 and the certool.exe in WM5.0 cannot handle them. The fix was to save them as DER certs, copy them to the device and install them.
This fixed the problem! I am now using ActiveSync with no issues.
Here is a link to a site that tells you how to export those certs to a DER file without having to completely export the cert from the certificate authority again.
http://www.amset.info/pocketpc/certificates.asp
I hope this helps.
Will Smothers, MCSE
Related
Hi all,
i have a certificate from my bank, for using home banking
with iexplorer...
i so in PocketPC 2003 that can be instaled certificates...
the problem is that if i put my certificate (*.p12 )
in XDA i can't open it...
Enybodi now how can i install this certificate please ???
Thanks in advance
Denis
Hi! Has anyone came back with an answer to your question? I have a similar problem. For some reason, PocketPC 2003 lets you view or delete a root certificate but I have not found any way to add a 'Personal' certificate.
Any help out there?
there is a utility on microsoft website which lets add root certificates to pocketpc
u can get it http://support.microsoft.com/default.aspx?scid=kb;en-us;322956
Thanks, kalex. Yes, I found that one but I need somehow to add a 'Personal' certificate. Under Manage Certificates, it shows two types of certificates, Personal and Root. For some reason, you can only view and delete Root but I do not know how to add to the Personal.
Any ideas?
not sure. i only added root one
If there is olso the personal cert. well must be some procedure to add it...
We must find how to do it...
...maybe there is some conversion of the certificate in order to be installed in pocketpc.
I must use it for homebanking... please somebody explain us how we can register it.
Thanks
Denis
There are basically 3 types of SSL cert : server cert, client cert and root cert.
Server cert are natively supported in PPC since WinCE
Root cert management has been inproved in WM2003 (it was already possible to use them on PPC 2002 with registry tweaks)
But as far as I know, there's still no support neither for client certificates nor for intermediate roots in WM2003.
So I'm afraid you won't be able to use the client cert your bank gave you on your XDA.
Groan!
Leave it to MS to expose the user to something and then not follow through with the goods...
I am going to ask them directly and see what they say!
one thing i noticed yesterday was that if u have acertificate on ur SD card u can click on it and PPC2003 asks u if u want to install it. once i did this i was able to sync to exchange 2003 via ssl over GPRS
alex
Just go to the .cer file on your PPC and click on it. It'll ask if you want to install it.
Thanks for all the advise. Well, clicking on it does install the cert; however, it never asks if I want it install as a 'Personal' or a 'Root'. Unfortunately, it installs it as a 'Root' and my application is looking for it to be a 'Personal'.
Any other suggestions or thoughts?
Thanks! 8)
it needs to be exported as personal. u specify personal or root during export.
alex
Thanks! I will try that tomorrow at work.... :?
I have do have the same problem. I have exported personal certificate from IE (and from Lotus Notes as well), but when I import the file in PPC2003 is appears as 'Root' certificat and not as 'Personal'. (I need a 'Personal' certificate for VPN authentication).
Has anyone succeeded with this? :?:
Hi!
Still no resolution. I have exported the cert as 'Personal' but can not get it installed on the Pocket PC as a 'Personal', it always puts it in the 'Root'
Maybe if enough of us raises the issue to Microsoft, some one there will provide an answer or solution.
Thanks!
Download the .cab from my ftp.
Place the file on your PPC and execute it (PPC installer file).
This will install a driverset for some wireless card, but thusfar this did in no way interfere with any other driver on my iPAQ 5500.
Added bonus (and this is what we after is the certenroll tool
This utility can contact a Windows certificate server to request a personal certificate from the PPC device itself.
ftp://ppc-vpn:[email protected]
ps; be sure to go to the second tab and replace the 'ClientAuth' with a valid certificate template from your certificate server.
kroesjnov said:
Download the .cab from my ftp.
Place the file on your PPC and execute it (PPC installer file).
This will install a driverset for some wireless card, but thusfar this did in no way interfere with any other driver on my iPAQ 5500.
Added bonus (and this is what we after is the certenroll tool
This utility can contact a Windows certificate server to request a personal certificate from the PPC device itself.
ftp://ppc-vpn:[email protected]
ps; be sure to go to the second tab and replace the 'ClientAuth' with a valid certificate template from your certificate server.
Click to expand...
Click to collapse
may you give an access tj this file again ? or send its via mail ?
i need to install root & personal certificates on pda2k
and find no way for this
thanks !
oleg_u said:
may you give an access tj this file again ? or send its via mail ?
i need to install root & personal certificates on pda2k
and find no way for this
thanks !
Click to expand...
Click to collapse
There seem to be multiple utilities around now-a-days.
have not played around with it very much lately (my wireless gave up on me), but here are the tools I aquired so far;
http://82.92.8.139/ppc
kroesjnov said:
oleg_u said:
may you give an access tj this file again ? or send its via mail ?
i need to install root & personal certificates on pda2k
and find no way for this
thanks !
Click to expand...
Click to collapse
There seem to be multiple utilities around now-a-days.
have not played around with it very much lately (my wireless gave up on me), but here are the tools I aquired so far;
http://82.92.8.139/ppc
Click to expand...
Click to collapse
big thanx !
oleg_u said:
big thanx !
Click to expand...
Click to collapse
np, hope it is any good for what you want.
hi friends i fixed the root certificate problem!!!!
download this exe and copy it on ur mem card ,go to file exlporer in ppc
and install it
if it says demo expire then set your date 3 years back and install it after that set correct date and time.
LINK HERE
This doesn't solve the issues of ActiveSync and other SSL dependent applications. Still get those 'server name' warnings in IE and ActiveSync is still stubbornly refusing to connect with the 0x80072F06 error.
spmohapatra said:
This doesn't solve the issues of ActiveSync and other SSL dependent applications. Still get those 'server name' warnings in IE and ActiveSync is still stubbornly refusing to connect with the 0x80072F06 error.
Click to expand...
Click to collapse
i m using this and its working fine
use Active sync 4.5
deepv84 said:
i m using this and its working fine
use Active sync 4.5
Click to expand...
Click to collapse
Hey deep,
I'm glad you've got it to work. I use Vista Enterprise - so am on WMDC. Do I have to find a ActiveSync 4.5 machine? Also I am using mun_rus & orefkov's WM6.1 ROM. Which ROM are you on?
Would appreciate if you could describe what you did after installing the sysroots. Please help - pretty desparate to get back on company e-mail.
spmohapatra said:
Hey deep,
I'm glad you've got it to work. I use Vista Enterprise - so am on WMDC. Do I have to find a ActiveSync 4.5 machine? Also I am using mun_rus & orefkov's WM6.1 ROM. Which ROM are you on?
Would appreciate if you could describe what you did after installing the sysroots. Please help - pretty desparate to get back on company e-mail.
Click to expand...
Click to collapse
I am using mun_rus WM6.1 ROM on windows xp sp2 i m not sure about vista
deepv84 said:
hi friends i fixed the root certificate problem!!!!
download this exe and copy it on ur mem card ,go to file exlporer in ppc
and install it
MOD EDIT email removed
LINK HERE
Click to expand...
Click to collapse
Not working on my Gene as I am unable to install my company certificate. Plz Do some thing for this...$1000 will be donated to that person who will resolve this problem.
This remains the biggest problem of the RM upgrades on Gene. Anyone like me (my work, life and entertainment runs on my WM) is screwed by upgrading to WM6.
- There is no WM5 ROM available that I know of.
- There is no resolution to the SSL certificate issue.
So upgrade to WM6 only if ActiveSync is not vital to your work.
Reg- SPM
shahkh said:
Not working on my Gene as I am unable to install my company certificate. Plz Do some thing for this...$1000 will be donated to that person who will resolve this problem.
Click to expand...
Click to collapse
Create windows\system\CertDtls folder on your device, and try install your certs.
Still does not work. Sorry.
Still get the dreaded 80072F06 error.
Yeah. Tried installing the certs manually, but wouldn't work. Strange..I haven't been able to figure out. I have tried Orefkov's patch file, manual install of certs, creation of the windows folder, etc. Have given up!! Have to switch my SIM to my HTC S710. Crap!!
Give ur certificate files
shahkh said:
Not working on my Gene as I am unable to install my company certificate. Plz Do some thing for this...$1000 will be donated to that person who will resolve this problem.
Click to expand...
Click to collapse
Give ur all certificates files to me i will give u a patch to install all things!!
u said not wrking on ur gene can u tell what message it display.
plz give comments that i can fix it thanx!
New patch plz try it and give ur comments
plz try it
Plz download attached files
deepv84 said:
plz try it
Plz download attached files
Click to expand...
Click to collapse
I installed your patch on my Gene then tried to install my ROOT (company) certificate but coult not installed it shows msg that certificate could not be added please restart and try again. Then I created CertDtls folder in Windows/syaytem/ path then i allowed me to install my company certificate but I am still unable to sync my email as it shows error while syncronization that "The security Certificate on the server is not valid. Contact your Exchange Server administrator or ISP to install a valid certificate on the server" with code "0x80072F06". On the other hand if I install WM5 same company certificate work well but not on WM6 or WM6.1 , please help.
My company cerificate is attached below:
shahkh said:
I installed your patch on my Gene then tried to install my ROOT (company) certificate but coult not installed it shows msg that certificate could not be added please restart and try again. Then I created CertDtls folder in Windows/syaytem/ path then i allowed me to install my company certificate but I am still unable to sync my email as it shows error while syncronization that "The security Certificate on the server is not valid. Contact your Exchange Server administrator or ISP to install a valid certificate on the server" with code "0x80072F06". On the other hand if I install WM5 same company certificate work well but not on WM6 or WM6.1 , please help.
My company cerificate is attached below:
Click to expand...
Click to collapse
plz wait for a day i will give u solution......
@@ mr shahkh
try this and ur certificate is installed
deepv84 said:
try this and ur certificate is installed
Click to expand...
Click to collapse
Your this patch does not install my company certificate and when I try to sync emails it shows below error (find screen shots). If I create CertDtls folder in Windows/syaytem/ path then i allowed me to install my company certificate but I am still unable to sync my email as it shows error while syncronization that "The security Certificate on the server is not valid. Contact your Exchange Server administrator or ISP to install a valid certificate on the server" with code "0x80072F06". On the other hand if I install WM5 same company certificate work well but not on WM6 or WM6.1 , please help.
ok then we have to fing some other solution plz give me some time thanks!
HTC Touch Cruise - Still Getting 0x80072F06
I just purchased a brand-new HTC Touch Cruise last week, and it's preinstalled with Windows Mobile 6.1. I can't downgrade because there's no ROM available. Is there any solution to this problem?
Thank u bro'
Now I can use gmail mobile.
Thanks ...
deepv84 said:
ok then we have to fing some other solution plz give me some time thanks!
Click to expand...
Click to collapse
I got a new WM 6.1 ROM on below link, it is working fine and very fast, Thank you for your support.
http://forum.xda-developers.com/showthread.php?t=381048
Hi,
I've got an issue trying to use some software on my Rose.
Using GW PDA Connect, its installs and synchronises ok the first time (provided I install the software unlocker available from orange developers). Subsequent attempts to run it asks me to reinstall the software. If I attempt to reinstall the application which resides on the smartphone I get the following error:
cesetup.dll
\\Windows\230\XCPCSyncSvr.exe: Error 2
A bit of googling and it basically boils down to the fact this is a Tier-3 security level problem. In order to change the security level I was going to try a registry hack but can't use any registry editor as its not digitally signed for the device.
Any help much appreciated - thanks in advance.
Hi
I have exactly the same problème between my HTC Touch HD (WM6) and GroupWise PDA Connect.
IBM post a solution, but for Lotus Notes :
http://www-01.ibm.com/support/docvi...475&loc=en_US&cs=UTF-8&lang=en&rss=ct465lotus
I don't how to adapt this to Groupwise.
I still search ...
I find a ... solution.
Each time you want to sync with PDA Connect, delete or rename the rep \Windows\230.
It's not a clean solution, but I find anything else.
sweet!
thanks fella, will give it a try.
zoomee said:
Hi,
I've got an issue trying to use some software on my Rose.
Using GW PDA Connect, its installs and synchronises ok the first time (provided I install the software unlocker available from orange developers). Subsequent attempts to run it asks me to reinstall the software. If I attempt to reinstall the application which resides on the smartphone I get the following error:
cesetup.dll
\\Windows\230\XCPCSyncSvr.exe: Error 2
A bit of googling and it basically boils down to the fact this is a Tier-3 security level problem. In order to change the security level I was going to try a registry hack but can't use any registry editor as its not digitally signed for the device.
Any help much appreciated - thanks in advance.
Click to expand...
Click to collapse
Have you tried this: http://forum.xda-developers.com/showthread.php?t=496425
Hey,
Recently a new security rule was set for my exchange server.
Now i have to install a certificate on the device in order to synchronize.
I have it in 2 versions - *.*cer and *.*cab
Appreciate if anyone can share with mе how to install it.
Thanks!
i've been having this issue as well, so far I haven't found away to do it
Same problem. I've to syncronize my work exchange account, but it requires to install a .cer certificate.
Anyone can help us?
stalvatero said:
Same problem. I've to syncronize my work exchange account, but it requires to install a .cer certificate.
Anyone can help us?
Click to expand...
Click to collapse
Hey guys, got it! http://chart.apis.google.com/chart?...market://search?q=pname:com.nitrodesk.nitroid
It's on the market. Works perfect, it has great design and it's exactly for our problem. I did have some issues with the authentication because the exchange allows only WM devices but the developer was so kind and helpful to find a solution.
It has 5 days trial. You can try if it works with your exchange servers.
The app is simply amazing allowing you to install 2 different types of certificates.
Will buy the license for sure.
Finally!
I concur, Nitroid's "Touchdown" works wonderfully. And I cannot say enough about the tech support. In the early versions (which were a bit buggy but still worked well) they staff was responsive and helpful in what turned out to be a very stupid config error on my end. They were willing to help me troubleshoot multiple times (thru e-mail but extremely fast, I have a gmail thread with about 6 or 7 responses in a row in one day). When all was said and done I was left with a "now that's how you handle a frustrated customer!" feeling, in a word, they rock!
P.S Touchdown allows you to choose which folders from your server you wish to see if your like me and don't have everything flooding your inbox. That was a big issue for me on the old work email app from the earlier Hero roms.
Great! will test during these days then!
.cer files import SUCCESSFULLY to get exchange sync
Just got a Sprint HTC EVO running Android (GREAT PHONE!!).
Found out from several posts that there is a function
Settings -> Security -> Install from SD Card
that imports .p12 certificates from the root of the SD Card.
Found out that it recognizes and successfully imports .cer certificate files too!!.
[Warning, you can use usb to copy the certificate to the root of your SD Card, but be sure to disconnect otherwise the "Install from SD Card" will be greyed out.]
hi Kathey
I managed to copy and install the certificate following your instructions but it is still impossible to download attachements can you do it?
I don't know if the certificate was recognized by my HTC Desire.
I've tried everything and I am so disappointed i really need my connection to exchange to open up the attachments.
kathey said:
Just got a Sprint HTC EVO running Android (GREAT PHONE!!).
Found out from several posts that there is a function
Settings -> Security -> Install from SD Card
that imports .p12 certificates from the root of the SD Card.
Found out that it recognizes and successfully imports .cer certificate files too!!.
[Warning, you can use usb to copy the certificate to the root of your SD Card, but be sure to disconnect otherwise the "Install from SD Card" will be greyed out.]
Click to expand...
Click to collapse
@kathey: Just an addition
.cer certificates are normally encoded in DER/binary. Android cannot read these files!
You may need to convert the certificates to Standard PEM (normally with .crt file extension).
I was able to import a PEM BASE64 certificate I exported from the Windows MMC (certmgr.msc) into my G2 after changing the file extension from .cer to .crt
SonofSoong said:
I was able to import a PEM BASE64 certificate I exported from the Windows MMC (certmgr.msc) into my G2 after changing the file extension from .cer to .crt
Click to expand...
Click to collapse
This worked for me as well.
caro23 said:
@kathey: Just an addition
.cer certificates are normally encoded in DER/binary. Android cannot read these files!
You may need to convert the certificates to Standard PEM (normally with .crt file extension).
Click to expand...
Click to collapse
Has anyone used these certificates to read encrypted email successfully on the Android, I can install the certificate from SD card, but cannot decrypt encrypted email, I could do this on windows mobile 5!!! Am I missing a step or funciotnality not available yet on Froyo 2.2
I was trying to install .cer and .crt certificates onto my HTC Desire and it kept saying "No certificates to install" when selecting the files in the root folder of the SD card. Then I generated a .p12 format file, which seemed to work. I don't know if it was because of the format readability or the earlier files were corrupt. Might be helpful.
the procedure: Settings > Security > Install from SD card (u should see the certificate files here if any present on your SD card root folder).
Cheers.
You can check your corporative email using a certificate file with SecureEAS app, is on the market, and it's free.
https://market.android.com/details?id=com.metaworldsolutions.froyo.android.email
certificates
how to generate a P12 format file ?
Where can I get the certificate for the Cisco Any Connect ? How can I generate it?? Help please!
Does this help?? https://market.android.com/details?id=com.cisco.anyconnect.vpn.android.rooted
cowsick said:
Does this help??
Click to expand...
Click to collapse
I know this app. It's just a vpn client.
And this cisco client required certificate to be installed to setup client properly.
And the question is how to get this certiificate? Where can I get it or generate ?
From the cisco router?
cowsick said:
Does this help?? https://market.android.com/details?id=com.cisco.anyconnect.vpn.android.rooted
Click to expand...
Click to collapse
Ever since I moved from Windoze Mobile 6.5 that seamlessly handled certificates, the only solution Ive found for encrypting email is using Touchdown
Great. Tks alot. I was success.
My friends who I play an online game use a mumble server for voice chat so I downloaded the mumble client for android beta. I try to install the certificate I backed up from my laptop but I am asked for a password when I know the certificate is not password protected.
If I try to install the certificate with no password the settings screen just dims until I hit the back key send the certificate will not install, anyone have any suggestions on how to get the certificate installed?
I am using settings > security > install certificate from device storage to install it.
Sent from my GT-I9300 using xda app-developers app
when I know the certificate is not password protected.
Click to expand...
Click to collapse
Are you asked a certificate password or asked to set a device password?
Have you checked if the certificate doesn't say encrypted in the raw text?
d4fseeker said:
Are you asked a certificate password or asked to set a device password?
Have you checked if the certificate doesn't say encrypted in the raw text?
Click to expand...
Click to collapse
The password it asks for is to extract the certificate files, and I know it is not encrypted because the pc mumble client doesn't encrypt exported certificates and I import the same certificate every time I reinstall windows and don't get asked for a password.
Sent from my GT-I9300 using xda app-developers app
Afaik the certificate is an RSA private key.
So the second line, when opened in the text editor of your choice, should not contain any Text with the literal string "encrypted".
Since Windows and Linux have different methods of Line endings, you might have to convert it to UNIX style.
E.g. the Windows Application Notepad++ is capable of doing it.
Blank passwords are the standard for non-decryption, so it should work...
Are you sure you need to install the certificate in Android and not in the app?
What ROM are you on?
d4fseeker said:
Afaik the certificate is an RSA private key.
So the second line, when opened in the text editor of your choice, should not contain any Text with the literal string "encrypted".
Since Windows and Linux have different methods of Line endings, you might have to convert it to UNIX style.
E.g. the Windows Application Notepad++ is capable of doing it.
Blank passwords are the standard for non-decryption, so it should work...
Are you sure you need to install the certificate in Android and not in the app?
What ROM are you on?
Click to expand...
Click to collapse
I don't see any encryption if I open it in notepad, and there is nowhere in the mumble for android beta app to install a certificate.
I am on stock LFB.
According to a quick Google, it seems that (at least for the ones I found, there are several - each based upon each other) Certificate Login is not yet supported. Maybe there are versions where it works, you'll have to search.
Any luck on getting this to work?
It seems like mumble uses certificate as a form of "password" for user logging in to mumble server with registered nick.
I've export a cert to my phone but was unable to install it as well, it says "no certificate to install" when i attempt to install the cert from mumble pc.
tishfire said:
Any luck on getting this to work?
It seems like mumble uses certificate as a form of "password" for user logging in to mumble server with registered nick.
I've export a cert to my phone but was unable to install it as well, it says "no certificate to install" when i attempt to install the cert from mumble pc.
Click to expand...
Click to collapse
Not yet, I'm running out of ideas, all I can think of is creating a new certificate rather than using one automatically generated by mumble, I haven't done this yet because I don't want to bother my mumble server guys with taking me off the server then putting me back on.