Certificates and MfE and my E71

Hello all,
There has been a lot of random posts about the E71 and Certificates. Can some one give me a bit of guidance on the replacing of Certs on the E71.
for the best part of a year I have had perfect use of MfE. Then a few weeks ago our IT team changed the security settings on the server. They offered to put on the new Cert onto the E71 (which is how they did it the last time). The Cert is .pfx. This went into the Personal Cert grouping.
MfE just fell over with an "Error on Exchange" message, after asking me for to accept "Website has sent an untrusted certificate, accept".
If I access my OWA website, the cert is untrusted but will allow me to access the site and read mails.
I have then re-formatted the phone. I have deleted all the certs and just put back the one from IT. All to no avail.
What is going wrong here?
I can not live without my sync calendar, I have already missed a meeting or two .

thepnut wrote:
Hello all,
There has been a lot of random posts about the E71 and Certificates. Can some one give me a bit of guidance on the replacing of Certs on the E71.
I think there is no offical way of doing it. I use a method where I surf to the server's address and port using Windows computer and a browser that does not get certificates via Group Policy, e.g. Firefox. If you don't have access to Firefox, Google Chrome might do the trick as installing it does not require admin rights. So grab a browser, type https://your.mailserver.address:port into its address field and hit go. The address being your company's Exchange server's address you normally enter into MfE settings. The port is usually 445.
Browser should warn you about invalid or untrusted certificate and provide you with a button to view the actual certificate. Press the button and try to locate a window from where you can save the certificate into file. If there is more than one certificate in a chain, save all of them one by one. Use DER encoded binary format with a .cer extension if prompted. After you have all the certificates saved into files, tranfer them into your phone and try to open them in File Manager to install them.
Help spreading the knowledge — If you find my answer useful, please mark your question as Solved by selecting Accept this solution from the Options menu. Thank you!

Similar Messages

  • E71 and MFE Calendar Attendees

    I sync my phone to MS Exchange via MFE and when I look at calendar meetings I cannot see who the organizer is as well as attendees. This is a big deal as I have several meetings a day and sometimes double or triple booked. I need to see which meeting I must attend or can miss so knowing the organizer is a must. Am I missing something or is this a HUGE omission for a device that is marketed and sold as a business tool?

    I'm currently evaluating the E71 for a possible rollout to 1000+ users in the UK (currently Windows Mobile users).  I have also noticed the lack of any information on organiser or attendees.  I've researched this pretty thoroughly (I think) and I'm pretty sure you haven't missed anything and I can't find a way of seeing this either.  I'm at the latest firmware (110.07.127) and latest MFE version (2.7, or 2.07 - it can't quite seem to decide).
    The closest I've managed to get was downloading a trial version of Papyrus Symbian S60 Calendar from www.sbsh.net.  This does show the attendees, although not the organiser.  Sadly, however, it also didn't work properly and resulted in loads of "memory full" errors and other issues.
    As you say, if this is being marketed as a business tool it's an absolutely crucial and basic feature without which we can't really use it. And having to buy 3rd party software to get it is not the right solution.
    I don't know if you've also noticed this issue but MFE doesn't seem to correctly or reliably synchronise all calendar items anyway.  I've had my device for 2 weeks and have missed 2 important meetings as they'd just not syncrhonised into the calendar, even though the synchs were marked as complete and successful and all the other meetings had synced.  Unless you can rely on all meetings consistently synching than you can't rely on the device at all.
    I have also tried RoadSync to try resolve the above issue, although again, very grudgingly as I don't see why you should have to pay extra to get the basics working.  Others report better experiences but I couldn't get RoadSync to work at all on my E71 / Exchange 2003 backend, so that's another idea out of the window.
    So, for me, E71 is a beautiful, generally smoothly working but fatally flawed device as it stands.
    Calling all Nokia folks - you guys really need to sort this out urgently or we'll have to keep using Windows Mobile.

  • BSR code on TDS Certificate for Customer and vendor in india

    Hi
    We have a requirement to print BSR code on TDS Certificates for customer and Vendor in india.
    Currently the BSR code for Customer TDS certificates picked up from Bank branch ( BNKA-BRNCH ) field and
    for vendor TDS certificates picked up from Bank Key field.
    There is a 3rd party sowtware running monthly to update the BNKA table. so we are not following the standard process and we are implemented another options to picked up the BSR code for TDS certificate printing on Vendor/Customers.
    For Vendor TDS certificate, we implemented SAP notes 1299729 & 1338645
    to print the BSR code from Tax Number1 (T012-STCD1) field and it is working fine.
    For customer TDS certificate also we want program to pickup BSR code
    from Tax Number1 (T012-STCD1) field
    Please let me know is there any other SAP correction Notes avalible to print the BSR code on Customer TDS certificates from  Tax Number1 (T012-STCD1) field.
    Thanks
    Risha

    answews

  • Certificate for Portal and BackendSystems. What do I have to take careAbout

    Hello,
    I would like to buy a certificate for the secured HTTP but I don't know what I have to take care about?
    Where do you buy your certificates? Can I use "wildcards"-certificates for the portal and the backend-systems.
    Is there a good shop for buying a certificate in Germany?
    Thanks, Vanessa

    Vanessa,
    You can approach both Verisign and Thawte and collect information.
    In case of Thawte, you can just go their site and there is an option for an online free chat with a Thawte associate. He/she will then guide you further.
    They will also share the details required for the certificate to get authorized.
    Plus before ordering, you can also check the correctness of ur certificate for free on their site.
    Hope this helps.
    Regards,
    Ritu

  • Problem: Mixed Exchange 2007 / 2013 CAS Servers with wildcard certificates in Europe and non-wildcard Certficate in China

    Hi,
    we have following problem. We have a mixed multi-domain one-forest AD environment. We also have still a mixed exchange 2007 / 2013 environment. We also have different CAS Servers for 2007 SP3 (RU15) and 2013 (CU8) in europe and one 2007 SP3 (RU15) CAS Server
    in China, because of bad connection to Europe. For the Migration to 2013 in Europe we installed a wildcard-certificate *.xyz.com and used the Set-OutlookProvider EXPR -CertPrincipalName msstd:*.xyz.com, so the wildcard certificate is accepted. Everything in
    Europe works fine, inside and outside also between exchange 2007 and 2013 (both CAS Server 2013 and 2007 use the same wildcard certificate). But since the change of the Set-OutlookProvider EXPR we are facing problems with our CAS Server in China, because this
    server has a different non-wildcard certificate and a different domain name (cas-server.xyz-china.com instead xyz.com). Now we have the problem that this Chinese CAS server the Outlook Anywhere does not work anymore and prompts always for the username. As
    I see it is because of the EXPR change. Is it possible to set the the Outlook-Provider EXPR per Cas-Server ? (They also have their own Autodiscover on this front-end server). Because I see that the Outlook-Provider can only be stored forest-wide.
    If not the other solution would be to register the chinese cas server in our xyz.com domain and use the same wildcard certificate on this system right ?
    Any help would be appreciate….

    Yes setting the EXPR value is most likely the cause of your issue.  When you set this value you are telling Outlook to only accept connections from connections that have the cert with the subject name you specify here.
    Unfortunately, based on my experience I believe this is an organization wide setting and cannot be configured on a CAS by CAS basis (If I'm wrong someone please keep me honest :)).  
    So the only option would you have is to change all the URLs to be on *.xyz.com domain.  There's no need to change the domain the server actually resides on.  The other option would be to purchase a UCC Cert with all the names you need and apply
    to all your CAS servers and reset the EXPR value. 
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread

  • Certificate Based Authentication and SSL

    To whom it may concern,
    I have installed SJES on Solaris 9 x386 (intel version). Everything is running fine, the mails are also coming and going.
    Now, I need Certificate based authentication and SSL. I have downloaded versign.com trial certificate and have install it succesfully in the Messaging Server Console -- > Manage Certificates. The certificate is also visible in its tab.
    Next, I followed the documentation and enable ssl by using ./configutil utility. And also restarted the server.
    I am running my Messenger express (http) like this :
    http://testing.xyz.com:8100
    (I am using port 8100 for http access to mails). After restarting the mail server, I tried :
    https://testing.xyz.com:8100 also,
    http://testing.xyz.com:443 also,
    https://testing.xyz.com:443 also,
    but I cannot see the login page of the mail server. All the above mention url i tried and just given error "the connection was refused when attempting to contact testing.xyz.com. I CAN ONLY SEE THE LOGIN PAGE WHEN I WRITE THE OLD HTTP ADDRESS: i.e. http://testing.xyz.com:8100
    And I also checked the logs and the server is having no problem in starting and there is not a single word regarding SSL enabling in the logs.
    Please help me out, it's really a strange behaviour. I am using SunONE Messaging Server 6.0.
    Thanking you,
    Farhan Ahmed,
    System Engineer
    Dubai, UAE.

    Dear jay,
    I am pasting a line from imap and http logs ... i don't know what this error means and how to resolve it.
    [29/Dec/2004:14:42:45 +0100] testing imapd[888]: General Error: SSL initialization error: ASockSSL_Init: couldn't find cert Server-Cert (-8183)
    strange thing is that my certificate name is lowercase server-cert and also i can see in the GUI console the certificate name as lowercase and I have also set this parameter encryption.rsa.nssslpersonalityssl = server-cert (all lowercase), but the error in the log tells it as "Server-Cert" !!!! though it is "server-cert"
    i got this line from the http log:
    [29/Dec/2004:14:42:47 +0100] testing httpd[894]: General Error: SSL initialization error: ASockSSL_Init: couldn't find cert Server-Cert (-8183)
    I haven't missed the sslpassword.conf file step. I have placed the same password which i provided while generating the certificate request in the GUI.
    Help me out what this errors means and how to resolve them. I have also copied the cert7.db and key3.db to /opt/SUNWms*/config directory from the /var/opt/mps/serverroot/alias
    Thanking you,
    Farhan Ahmed,
    System Engineer,
    Dubai Internet City, Dubai, UAE.

  • Cisco ISE User Authentication Certificates for Wired and Wirless Users (BYOD)

    Can any one tell me from where we can purchase User Authentication Certificates for Wired and Wireless Users (BYOD) for Cisco ISE. Also Confirm what certificates we required for the purpose.
    Please suggest the Website form where we can purchase and ipmort in Cisco ISE certificate Section.
    Thanks.

    Dear Mohana,
    Thanks for your reply, Can you please confirm me in regards EAP-TLS certificate, which authorities you recomend if i go to Go dadday or very Sign to buy it and then import in ISE.
    Looking forward for your reply.
    Regards,
    Muhammad Imran Shaikh
    Resident Engineer, IT Network Section - PPL
    Mobile : 0092-312-288-1010
    LinkedIn : pk.linkedin.com/pub/muhammad-imran-shaikh/10/471/b47/

  • Policy in domai server2008 for remove tick Validate Server Certificate in win7 and xp

    hi
    i have a domain server 2008
    i need create a policy to remove tick Validate Server Certificate in win7 and xp
    please help me

    > i need create a policy to remove tick Validate Server Certificate in
    > win7 and xp
    Deploy your WLAN settings through Group Policy - this will allow you to
    create a WIFI for Vista and above, and another one for XP. Both offer
    you to untick this check box.
    Greetings/Grüße,
    Martin
    Mal ein
    gutes Buch über GPOs lesen?
    Good or bad GPOs? - my blog…
    And if IT bothers me -
    coke bottle design refreshment (-:

  • ForbiddenError: The server failed to authenticate the request. Verify that the certificate is valid and is associated with this subscription.

    Im trying to connect to my azure subscription via powershell on my machine but keep getting the following error when i run a command:
    ForbiddenError: The server failed to authenticate the request. Verify that the certificate is valid and is associated  with this subscription.
    The steps i have taken so far are:
    1. get settings file
    Get-AzurePublishSettingsFile
    2. Import settings file
    Import-AzurePublishSettingsFile -PublishSettingsFile "C:\Users\me\Downloads\credentials.publishsettings"
    3. I then run Get-Azuresubscription with the following output:
    SubscriptionId : 699385c3-b83a-44af-a651-bxxxxxxxxx
    SubscriptionName : Windows Azure MSDN - Visual Studio Premium
    Environment : AzureCloud
    SupportedModes : AzureServiceManagement
    DefaultAccount : 3B68902B5170D5EC91BFCBE4CC27E2A8838F61C4
    Accounts : {3B68902B5170D5EC91BFCBE4CC27E2A8838F61C4, 26B118D7F3C598FB8FE9CDC49AB5DE5E450C967C,
    03E1E1F0B8C7717F11FB58A14138C35524AB3F8D, 9A2E1FD267ECCC0E9B8C151BD931FC4824E89184...}
    IsDefault : True
    IsCurrent : True
    CurrentStorageAccountName :
    TenantId :
    I run Get-AzureAccount and get the following:
    Id Type Subscriptions Tenants
    3B68902B5170D5EC91BFCBE4CC27E2 Certificate 699385c3-b83a-44af-a651-xxxxxxxxx
    A8838F61C4
    26B118D7F3C598FB8FE9CDC49AB5DE Certificate 699385c3-b83a-44af-a651-xxxxxxxxx
    5E450C967C
    03E1E1F0B8C7717F11FB58A14138C3 Certificate 699385c3-b83a-44af-a651-xxxxxxxxx
    5524AB3F8D
    9A2E1FD267ECCC0E9B8C151BD931FC Certificate 699385c3-b83a-44af-a651-xxxxxxxxx
    4824E89184
    85AD02CB8EB8AB20CF2C44FD9D19F2 Certificate 699385c3-b83a-44af-a651-xxxxxxxxx
    9B6BB2FCD2
    Finally, when i try to run Get-AzureSQLDatabaseServer, to list my databases, i get this error:
    WARNING: Client Session Id: '5911f288-7b02-4c94-bb9d-37b9ea5fc187-2015-01-13 11:47:54Z'
    WARNING: Client Request Id: '3e5f7ea9-092a-46fd-a6a6-6916b9161b77-2015-01-13 15:25:41Z'
    Get-AzureSqlDatabaseServer : ForbiddenError: The server failed to authenticate the request. Verify that the certificate is valid and is associated
    with this subscription.
    At line:2 char:1
    + Get-AzureSqlDatabaseServer
    + ~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo : NotSpecified: (:) [Get-AzureSqlDatabaseServer], CloudException
    + FullyQualifiedErrorId : Microsoft.WindowsAzure.Commands.SqlDatabase.Server.Cmdlet.GetAzureSqlDatabaseServer
    I would appreciate any help in figuring out what i am doing wrong here.
    Thanks,

    OK. That won't work in Azure Automation though, as mentioned above. OrgID (recommended) or cert-based auth will need to be used. PublishSettings file won't work.
    Correct, but the original question was:
    <Quote>
    Im trying to connect to my azure subscription
    via powershell on my machine 
    </Quote>
    I wanted to test automation script's core functionality without having to wait for the very very long time taken for an automation runbook
    to spin up, actually run and provide output (can often take 2+ minutes for a trivial script). Although i cant run Workbooks on my pc, i can run the core modules (view virtual machines, databases etc) to ensure my logic is sound.

  • MfE and battery performance

    We change our server and we start using exchange four our emails.
    Before I tested the service with m2web.com and my E61 and everything was ok.
    When I start using E61 with the new server the mobile discharge the battery in 9/12 hours.
    Is any particular configuration that I've to suggest to our IT department?
    Thanks, Marcello

    I have been running the latest version of MfE and found the battery performance degraded badly.
    After some investigation I found that this was caused by the new feature automatic heartbeat interval adjustment. Since I perform quite a lot of roaming and travel through areas with low coverage the heart beat interval was automatically adjusted to 1 minute. My battery only lasted for a day.
    I reinstalled the previous version (MfE 2.0) and set the heartbeat manually to 10 minutes. All is OK and battery life is now again several days.

  • Can't get Mail to recognize Thawte certificate for signing and encrypting

    I got a certificate from Thawte and double clicked on the p12 file. This installed the certificate in the login section of the Keychain. I read in several places that it must be in the X509Anchors chain in order to work. However, whenever I try to import it or copy it there I can't get past the authentication screen. I give it the password to decrypt the p12 file and that works, but then it asks for a password for the X509Anchors keychain. I'm giving it my login password, but that doesn't work. What am I doing wrong?

    You shouldn't have to do anything with the X509Anchors keychain. The X509Anchors keychain contains certificate authority (CA) certificates, i.e., certificates associated with CA's that sign certificates. In it you'll find various CA certificates for thawte among others.
    After you've successfully imported your thawte cert into your login chain, restart mail (I don't think you need to restart keychain access, but it wouldn't hurt).
    Now when you compose a message, you should see encrypt and sign buttons to the right and below the subject line. This of course assumes the email address configured in mail is the same as the one in the thawte certificate.

  • On some sites we get sec_error_unknown_issuer SSL error due to missing root certificate TC TrustCenter Class 2 L1 CA XI. Firefox is the only browser having this issue. Why is that certificate not preinstalled and shipped with Firefox?

    On some sites we get sec_error_unknown_issuer SSL error due to missing root certificate TC TrustCenter Class 2 L1 CA XI. Firefox is the only browser having this issue. Why is that certificate not preinstalled and shipped with Firefox?
    Check sales.sauer-danfoss.com for details with Firefox 7.
    Thanks
    Stefan

    You are not sending the TC TrustCenter Class 2 L1 CA XI intermediate certificate
    *http://sales.sauer-danfoss.com/
    Web servers need to send all required intermediate certificates to build the chain to build-in root certificates.
    You need to install that intermediate certificate on your server.
    *http://www.trustcenter.de/en/infocenter/root_certificates.htm#3479
    You can test the certificate chain via a site like this:
    *http://www.networking4all.com/en/support/tools/site+check/

  • Why are fraudulent/fake certificates from DIGINOTAR and USERTRUST are still there in Firefox?

    While going through the certificates install in my firefox browser, it was observed that in the section servers fake certificates from Diginotar and other authorities are still active. Does not firefox update certificate revocation lists.

    https://support.mozilla.org/en-US/questions/975404
    ''Those are permanent block exceptions and shouldn't be removed. You can see that if you click the Edit button, so just leave them''.
    https://support.mozilla.org/en-US/questions/961004
    ''There shouldn't be any DigiNotar certificates present under the Authorities tab in the Certificate Manager, but there should be permanent block entries under the Servers tab''.

  • How do i set up MFE and calender on E66 homescreen...

    I have the newest version of the E66 and am trying to set up the mail for exchange and exchange calander on the homescreen.
    How do I do this? the Mail and Calendar is working perfectly, I just need the homescreen gadgets that shows newest mail and next calendar appointment on the front-page (homescreen)
    Tanks.
    Replaced my buggy Nokia N97 with a HTC Hero.
    Besides the camera and the real keyboard the HTC Hero pawned the N97 on every level.

    Go to Settings > General > About > Name and type in a new name
    If a Passcode lock has been set, Settings > General > Passcode Lock > and delete and enter new or set to OFF

  • Wildcard SSL Certificates with MFE?

    Is anyone using a wildcard SSL certificate on their mail server when using Mail for Exchange on assorted Nokia E Series mobiles please?
    We currently use a straight SSL cert and MFE works with no problem, however I've been looking into getting a single wildcard SSL certificate for our domain.
    Before doing anything I figured I'd try a website that used a wildcard certificate.
    When I did this (using an E51) I got the message "Website has sent a certificate with a different website name than requested" and was prompted to accept once, permanently, or don't accept.
    My question is whether this message would come up in a clear/obvious manner when using Mail For Exchange on a Nokia (so I can tell our users what to do when it does), and whether anyone has encountered issues using a wildcard with Nokias when using Mail for Exchange.
    If anyone has an E-Series and is using a Wildcard cert can you let me know if you've encountered any issues please?
    Thanks.

    This is interesting question. I look forward testing this myself
    What kind of cert & website you used on your own tests? Was the cert something like *.example.com? And the domain, was it https://something.example.com or https://example.com ? AFAIK wildcard doesn't match addresses consisting domain part only, so the latter one might not work.
    Help spreading the knowledge — If you find my answer useful, please mark your question as Solved by selecting Accept this solution from the Options menu. Thank you!

Maybe you are looking for

  • Complete My Album isn't showing up as an option?

    I purchased five songs off of an album because I didn't have the funds to buy the full album but now I do and iTunes isn't showing the option to complete my album. Help?

  • Signal express tektronix

    I'm using Labview signal express tektronix edition and connecting my tektronix tds3054B to it by ethernet. When I typed in my oscilloscope ip address to the program, it can't acquire for the signal. I think I have all the required driver and VISA. He

  • USB flash drive 5times faster with ntfs filesystem?

    Hello, I have a weird problem with my USB Voyager GT 16GB flash drive.  I formated it in ext2/ext3/xfs/fat32 and then start copying a file >1GB in size. The speed of transfer very quickly drops to 2-4MB/s. That is very slow. And if I format it in ntf

  • Will 64-bit office fix out of memory error?

    I've been troubleshooting an out of memory error in Excel 2010 for some time. I've read quite a few articles on forums and on MS sites (including here.) I find many hits but none seems to offer a solution that works. One idea that seems to show up of

  • Compact and Repair Encrpyted Database Problem

    I have an MS Access 2007 accdb file that I no problems with when it is not encrypted.  I can compact and repair with no problems.  However, when I encrypt the database and try to compact and repair the file, I get 'invalid argument'. The file is 101