Question

How to install certificate on iPhone 3G?

Asked by: slarge

Hi all,

I just recently purchased an iPhone 3G and I'm working to get it sync'd with Exchange, but I'm having problems figuring out how to install the certificate.

On a normal PC, what I have to do is navigate to our OWA (owa.xxxxx.com) and then it will tell me the certificate is untrusted. It then gives me the option to Accept/Decline/View Certificate. I then click View Certificate, navigate through the next menu and select "Install Certificate". I'm then able connect to our mail server using Outlook.

Unfortunately, on the iPhone it only gives you the option to Accept/Decline. So how do I install this certificate on the iPhone?

I'm the IT guy for our company, so I have full access to the Exchange server, but I've only been here for 4 months so I don't know how the exchange server was setup originally.

Thanks and if any further information on my end would be helpful, just let me know!

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2008-07-15 at 17:19:06ID23568111
Tags

Microsoft

,

Exchange Server

,

Server 2003

,

Apple

,

iPhone 3G

Topics

iPhone

,

Exchange Email Server

Participating Experts
9
Points
500
Comments
34

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Iphone working with OWA
    Anyone have success, tricks tips getting iphone to work with OWA with SSL. It has connected a couple times and works, but usually user never gets login screen. going to https://mail.ourco.com/exchange User does not recall getting message to accept certificate and we have not ...
  2. Installing an SSl certificate to work with the Apple IPhone
    I need to setup my exchange 2007 server to allow secure IMAP connect for the Apple IPhone. The main issue that I am having is with the certificate. The IPhone does not like the certificate that I installed. I bought a certificate from GoDaddy and installed in on the defaul...
  3. Citrix XenApp - Untrusted certificate
    We are testing a new xenapp farm, and are getting messages that the certificate is untrusted. We are using a star cert from godaddy. The web interface works fine, but when trying to use Citrix Dazzle for Mac or the iPhone citrix application we are getting an error that the ...
  4. Citrix Receiver on iPhone - untrusted server certificate
    I try to use Citrix receiver on my iPhone. I have installed the App, and the certificate (via iPhone Configuration Utility). When I try to connet, i get "untrusted server certificate". I can see, that many people has this problem, but I cannot find a solution.

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: mass2612Posted on 2008-07-15 at 18:09:37ID: 22012530

Hi,

This thread might also help you: -

http://www.experts-exchange.com/Apple/Hardware/iPhone/Q_23403813.html

iPhone and iPod touch: Email account setup  

http://support.apple.com/kb/HT1385

 

 

by: slargePosted on 2008-07-15 at 19:37:41ID: 22012894

Thanks, but setting up IMAP e-mail isn't the problem, I can do that just fine.

The problem is that I can't get the exchange mail setup so I can get my contacts, calendar, mail, etc. pushed to my iphone.

Keep in mind that this is for the 3G iPhone with exchange support, not the old iphone mail setup.

 

by: j_crow1Posted on 2008-07-17 at 06:41:52ID: 22025314

I need to know the same thing - you would think Apple would of released something for this by now.

 

by: choldsworthPosted on 2008-07-17 at 08:58:17ID: 22026919

Also looking for this... anyone have any insights?

 

by: wv-rogPosted on 2008-07-17 at 10:37:53ID: 22027889

I just successfully connected an iphone to my exchange 2003 environment.  The only thing that might be different for me is that I have a purchased (trusted) certificate installed on my OWA site.  When configuring the iphone i put down the owa site as the server and it connected fine.  We do need to know what your Exchange environment is like though.  Do you have a front end/back end server scenario or are you just running one Exchange server that hosts the mailboxes and OWA?  

My suggestion is to buy a trusted cert from a public CA like Network Solutions (There are other cheaper ones out there); but there are other considerations to take into account depending on whether or not you're running 1 or 2 servers, so let us know.  

 

by: j_crow1Posted on 2008-07-17 at 11:48:58ID: 22028733

I have a trusted cert from verisign, my question is, do you enable SSL on the microsoft-active-sync virtual directory in IIS or do you enable SSL on the OMA virtual directory? You cannot enable it on the exchange virtual directory because microsoft active sync has to communicate with the exchange virtual directory over port 80, 443 will not work. I installed the cert on my iphone, I just added my personal yahoo e-mail address, then e-mailed the cert to myself and installed it that way.

 

by: wv-rogPosted on 2008-07-17 at 15:24:46ID: 22030988

j_crow1/slarge:  single server or front end/back end, and are you also using forms based authentication?  

 

by: wv-rogPosted on 2008-07-17 at 16:02:27ID: 22031191

 

by: slargePosted on 2008-07-18 at 18:09:16ID: 22041003

wv-rog,

We run just a single exchange server. We are also using an untrusted certificate that I believe the consulting group that helps with IT support originally setup. How much does it cost to get a trusted cert from Network Solutions? (They house all of our domains as it is anyways)

I figured out how to get the certificate installed, but still no luck. (For those that don't know, you just need to install the cert on a PC. Then open up MMC and add the certificates snap-in. Do a search for the certificate and then export it to your desktop. E-mail it to yourself and install it that way)

The problem I am having now is that I have the certificate installed and it shows up when I go to Settings on my iPhone.

What happens now is when I browse to OWA using Safari it tells me the certificate is invalid and when I try to sync the mail it tells me it cannot verify the certificate. I have removed the Exchange account on the phone and removed the cert and reinstalled/reconfigured multiple times with the same result.

Also as a tidbit, I can browse to OWA, it tells me the certificate is invalid, but I just hit accept and I can still login and browse my mail through OWA, which is strange.

Also, when you say forms based authentication, what does that mean?

 

by: slargePosted on 2008-07-19 at 22:45:50ID: 22044680

OK,

Another update. I tested sending a message using my current setup and I can send outgoing e-mail using the Exchange setup on the iphone, it's just not syncing anything to the phone.

Any thoughts on what might be causing this?

 

by: asllinPosted on 2008-07-20 at 03:16:19ID: 22045163

You have to turn on contacts and calendars sync in mail setup.  Otherwise it'll just sync mail.

 

by: asllinPosted on 2008-07-20 at 03:18:54ID: 22045168

Here is where you can turn them on.  "Settings", "Mail, Contacts, Calendars", select the exchange account you created.  Turn on both contacts and calendars and it'll start sync your phone numbers and appointments.

 

by: wv-rogPosted on 2008-07-20 at 13:35:34ID: 22046839

single server... OK.  I'm also assuming you're all patched and service packed on your Exchange server.  If not, do that.  

SSL cert from netsol is about $89/year for just your owa site which is probably sufficient. Compare that with the time you've already spent on this.  I'm not saying it will completely solve your problems but will help a great deal.  You actually won't have to deal w/ getting the cert on the iphone at all after that becuase it's trusted already.  I highly recommend it, also folks won't have to click "proceed to site" when they get that untrusted cert error, which won't happen anymore.  

Forms based auth:  When you go to your owa site, does it prompt you to log in via a dialog box (pop up) or does it go to a login page.  you can also find out if you have it enabled here: rt click the exchange virtual server in ESM (admin group - servers - your server - protocols - http) and see the settings tab.  See this link for details also: http://www.petri.co.il/configuring_forms_based_authentication_in_exchange_2003.htm

Single server WITH FBA turned on, presents a couple other challenges (this is how I have it set up) but it definitely can be done.  This link is how you'd set it up, it refers only to activesync but that's what we're doing on the iphone 3gs.  (Usual caveats/warnings: backup registry, backup system, be careful, don't drink and edit registry, look both ways before crossing, etc. etc.)

http://www.petri.co.il/problems_with_forms_based_authentication_and_ssl_in_activesync.htm

In your scenario, I really think getting that public cert will save you a headache and a ton of time and effort.

 

by: asllinPosted on 2008-07-20 at 19:15:05ID: 22047725

It looks like slarge's cert problem is resolved.  I am using a server generated cert (free, not commercial) with iPhone.  No problem with sending, receiving, calanders and contacts.

 

by: exexTWIPosted on 2008-07-21 at 05:12:27ID: 22049698

You wrote that you succeeded to install the certificate on the iphone but it is claimed to be invalid. Did you really install the CA Root Certificate or did you wrongly install the SSL certificate on the iphone?

There is a manual available that explains about installing root certificates.
http://manuals.info.apple.com/en_US/Enterprise_Deployment_Guide.pdf

 

by: slargePosted on 2008-07-21 at 15:48:44ID: 22055082

ExecTWI,

What is the difference between the two? The certificate that I installed was the same certificate that I am prompted to accept/install when I browse to OWA.<INSERTCOMPANY>.COM.

I installed it just how the manual states, by sending it to myself via e-mail.

wv-rog,

We do not use form based authentication. I'll look into possibly purchasing the cert, but it sounds like others have been able to do it with a self-signed cert. So I still want to stick down this route until I'm completely stumped.

 

by: exexTWIPosted on 2008-07-21 at 16:53:02ID: 22055454

The problem with self signed certificates is that browsers do not trust them. Certificates from VeriSign for instance are trusted because a CA Root Certificate of VeriSign is preinstalled in the Browser.
If you have your own Certificate Server then you have to install your Server's CA Root Certificate in the browser's Trusted Root Certification Authorities Certificate Store (not sure this is the correct name since I've only a german Windows installation here).
After the CA Root Certificate is installed, all certificates issued by your certificate server (like your OWA SSL certificate) are trusted.
If you used Microsoft Certificate Services to create the SSL certificate then you can get the CA Certificate through its web interface (http://<certificate server>/certsrv).

 

by: slargePosted on 2008-07-21 at 16:59:17ID: 22055473

Hmm,

I dunno, it seems odd to me that I can send e-mail out using the exchange account but I cannot see any. I would think that if the certificate was the issue then I wouldn't be able to send e-mail either.

 

by: wv-rogPosted on 2008-07-21 at 17:03:17ID: 22055496

slarge:
the nominal cost of the cert and little effort of installing said cert is WELL worth the money vs the time you've already spent on this.  execTWI explained it very well.  it would at least fully rule out the cert as the issue.  
Follow his direction in generating a ROOT certificate that should be installed on the phone, then as he says the owa cert can be installed and trusted.  

 

by: asllinPosted on 2008-07-21 at 17:09:00ID: 22055514

Just want to confirm again that I am able to use a self-signed CA cert using my own Certificate Server with iPhone.

 

by: slargePosted on 2008-07-21 at 17:27:02ID: 22055600

Just to save myself some time and narrow down the possible problems, I went ahead and ordered a signed SSL cert from Network Solutions. I'm just awaiting on verification from them, then once I have that setup and installed, I will post an update on where I am at.

Thanks for the help so far everyone.

 

by: slargePosted on 2008-07-24 at 17:04:39ID: 22084893

Ok, looks like we can close this now.

I gave my iPhone to the consulting company that does a lot of the behind the scenes server work and originally setup our Exchange server. Apparently there was a few missing pieces in IIS for OMA, that needed to be changed.

Once that was completed, it's syncing properly with a self-signed cert! Woo hoo. :)

 

by: OmarSenussiPosted on 2008-07-28 at 07:06:33ID: 22103236

Hi slarge,
I'm still battling with this.. can you please elucidate for my and others sake what exactly was "missing" in your setup? Would be very helpful..

I posted another query along trhese lines and have had no responses.. So I'm glad I fell upon this thread.. !!

Still not sure how one would set the timeout on a Cisco pix 501 (for SSL) I only find SSH ..  Any clues?

Thanks to all for useful info.

 

by: sirvodkaPosted on 2008-07-29 at 11:22:21ID: 22114076

slarge,

Please post what those missing pieces were that fixed your issue. Thanks.

isn't it funny how many times you come across a forum thread from any site that discusses your exact problem but is missing part or all of the solution?

Ok, not funny but frustrating!

 

by: Longshot9Posted on 2008-07-29 at 14:09:05ID: 22115697

Yeah I gotta agree with the last 2 posts... what's the point of telling everyone it's working now without telling us what you did to fix it.  I've been reading this site and tons of others on the internet trying to get this to work and it just refuses too.  What things were "missing" and how did you fix it?

 

by: OmarSenussiPosted on 2008-07-29 at 14:25:09ID: 22115822

Hello again,

I think this certificate stuff is a bit of a red herring!  I have a test server with my nephew playing with it.. it is SBS 2003 SP2 and the push works perfectly for me on that one!  When it says certificate is not valid, I just say ok.. and it connects anyway!  No problems

There is SOMETHING on my 2003 server (NOT SBS) which is blocking this.. We have a Cisco Pix 501, but OWA works fine with SSL ..

I'm damned if I can figure out what the hell is going on here!

 

by: Longshot9Posted on 2008-07-29 at 15:15:54ID: 22116187

I'm just not having any luck with this, I just installed my SSL cert on my iphone and it still doesn't work.  Server is showing it's trying to connect, but event logs just fill up with ID#3005.  I've done everything I can find for that error on the server and no luck.  I'll probably open up my own question

 

by: slargePosted on 2008-07-29 at 15:30:25ID: 22116258

I'm sorry that I cannot get into specific details as to what was missing, because I had handed it off to the consulting group that handles our mail server and had him look into it. According to him, there was some ActiveSync settings on the server relating to IIS that were missing.

So it wasn't an issue with the self-signed cert, rather it was just some missing ActiveSync settings. If you have a Windows Mobile device with ActiveSync, then try and connect using that phone. If you cannot connect then you know whether it is an issue on the server or something related to the iPhone specifically.

Try googling ActiveSync settings and I'm sure there are plenty of available guides on how to set it up, then just go off of that to confirm that you have everything setup properly server-side.

 

by: OmarSenussiPosted on 2008-07-30 at 04:04:36ID: 22119191

There are so few things t set server side with active sync.. the only thing that comes to mind is did you set up the moble carrier? someting like @mobile.o2.co.uk (in my case)

 

by: Longshot9Posted on 2008-07-30 at 06:36:33ID: 22120225

I'm sorry, I don't understand what you mean by mobile carrier?  First mention of that I've seen in any thread anywhere.

 

by: OmarSenussiPosted on 2008-07-30 at 06:42:15ID: 22120278

In Exchange manager.. Global settings -->mobile services .. In the right hand pane right click add new mobile carrier.. that is where you put your mobile provider O2 Vodafone etc in the format @mobile service (ask your provider what that sgould be!)

 

by: exexTWIPosted on 2008-07-30 at 08:21:31ID: 22121350

Server Side:
On the server side it ist important NOT to require SSL or forms based authentication (at least not in a single server environment). See MS KB 817379. In our environment we had required SSL, and  ActiveSync did not work until I unchecked the corresponding checkbox for the Exchange virtual directory in IIS.
Actually we DO use SSL to connect to OWA and to ActiveSync. The point is that it must be allowed NOT TO USE SSL, since internally ActiveSync wants to access the Exchange Virtual Directory without SSL.
I did not configure a mobile carrier. (don't know what this is)

Client Side:
On the iPhone I installed the CA root certificate of our internal self-signed certificate server. I could do this through the certificate server's web interface  (http://<certificate server>/certsrv). There is a link "Download a CA certificate..." and the installation worked on the iPhone.
When configuring the exchange server on the iPhone, it is important to specify the fully qualified external name (as defined in the SSL certificate of the Exchange virtual directory). I first tried the internal name since I was connected to the intranet, but I received a certificate error because of the mismatch of the used name and the issued name of the certificate. After correcting the name, everything worked perfectly.
 

 

by: Longshot9Posted on 2008-07-30 at 08:53:10ID: 22121690

Thanks for the info exexTWI, i'll go over this in a bit in my situation.  I have an open question here, http://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/Q_23605965.html  , if you could have a look at it and see if anything catches your eye as a glaring reason why this isn't working for me i'd appreciate it.  Thanks.

 

by: sirvodkaPosted on 2008-07-30 at 09:54:57ID: 22122312

I also have an open thread. He's suggesting rebuilding the Exchange Virtual Directories in my case.

http://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/Q_23605468.html#a22122164

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...