Cannot get a working certificate on the iPhone to get the iPhone working

Hi, We've tried just about everything to get the iPhone working with our Exchange server to push email via active sync. We are using our own self signed certificates, not ones from Verisign for example, and we are using the IP Config Utility 2.0 on Windows XP PC to import the certificates. We have EAS setup on Exchange 2007. We generated the config for the user and emailed the config to a personal user account which we are able to access via the iPhone. We opened the email and double clicked the config file which then installs the profile to the iPhone but we get error 403 when we try and sync email. The iPhone doesn't appear to be presenting the personal certificate to the excchange server correctly which is causing the 403 error.
Has anyone else experienced this and if so do you have a workaround or public fix for it. We are trying to avoid having to go to a certificate authority.
Appreciate any feedback.

Objective: Get a **** personal certificate working on the stupid iPhone
Update: Settings
1). Exchange Management Console - Under client access role - Exchange Active Sync - Authentication - basic authentication is checked, ignore client certificates is checked
2). Under IIS Manager - Default Web Site - Microsoft Server Active Sync - Directory Security - Secure Comms - Require Secure cannel is checked, ignore client certificates is checked
3. Server certificate is installed onto the exchange server - issued by our own certificate authority/server
4). iPhone installed with root certifcate from the certificate server and the exchange certificate which was issued by the certificate server.
Under the above configuration we can get email working fine on the iPhone. Its synced correctly with exchange and able to receive and send email. Both the root and server certificates were installed to the iPhone using the iPCU.
Ok then, second test
Settings:
2 setting changes only applied:
1). Under IIS Manager - set it to require client certificates
2). On the iPhone removed the old profile - updated the profile to include a client certificate issued from the same certificate server that the exhcnage server certificate was issued from. So now there are 3 certificates on the iPhone (the root cert, the exchange server cert and the client cert). NOTE: When viewing the profile certificates on the iPhone the issued by field on the personal certificate is blank, opening it up shows no details. The certificate is a .pfx certificate so this explains why the details cant be viewed.
On re-attempting to sync email we get the 403.7.5 error (client requires a certificate) even though we put one on the phone. It looks like the client certificate either is not being passed through. I've read many forums indicating this issue in that Safari on the iPhone doesn't support client certificates. I've also read that a reverse proxy might be a work around - has anyone tried this?
It doesn't matter whether we use our own client certificate or a client certificate signed by Verisign, both end up with the same result.
Does anyone have an answer yet - has Apple got their act together yet and provided a resolution to this problem?
Can anyone explain to me exactly how the certificate authentication process works. For example we couldn't get it working with "ignore Client Certificates" at first when we just put the exchange server certificate on the iPhone. We had to put the Root CA certificate on the iPhone also???
If anyone can help that'd be great, any help at all at this stage would be good.
Cheers.

Similar Messages

Maybe you are looking for

  • PlayMemories Crashes on Windows 8.1 64 Bit

     PlayMemories is crashing on Windows 8.1 64 Bit. It crashes as soon as I start it up, with "Browser Stopped Wiorking". From Windows Event Log: Faulting application name: PMBBrowser.exe, version: 9.2.0.2052, time stamp: 0x54d349d3 Faulting module name

  • Is it possible to change the default border on a JMenu?

    Hello, I'm working on an application that has a simple menu system. Clicking a button opens a JPopupMenu, which contains JMenu and JMenuItem objects. I want to change the border on the JPopupMenu and its JMenu submenus to a simple line border. Callin

  • My old eMac doesn´t find the hardrive

    After restart my eMac it appeared a folder with a question mark. I think my eMac doesn´t find the hardrive. I have tried to reinstall the system but of course it happens the same, it doesn´t find the disc where to install. I restarted pressing ALT an

  • Photoshop 7.4 Update

    What needs to be done to resolve Photoshop Camera Raw 7.4 update error message U43M1D207

  • Install MAC OS 10.4 (Tiger) on Power MAC G4

    I have a power MAC G4 and I've installed MAC OS 10.1 and it's working properly. I'm trying to install the MAC OS 10.4 (Tiger) but I'm getting during the installation an alert "this software can't be installed on this machine". Please advise if I need