Question

Palm Centro Outlook EAS sync problems - Exchange 2003 SSL Error

Asked by: Whereismys4

Hello,

I setup a new SBS 2003 box (sp2 all updates, exchange sp2 all updates) recently and everything seems to be working fine except when i try to sync my mail to a palm centro with versamail 4.0.1 - i get an SSL error below.  

I've tested all the settings for the virtual directories in IIS and they all function as they should.  I tested the Centro with a different exchange server running SBS 2003 and it synced fine  (different division in Europe)-- checked all the settings on that exchange server and they are identical.

1.  https://mail.mydomain.com/exchange -- functions properly (i can load this in the palm and login)
2.  https://mail.mydomain.com/oma -- i get prompted for username/pw and it logs in (both on the palm and on a remote laptop)
3.  certificate is valid (not a self certificate) issued by Starfield Secure Certification Authority (not go daddy)
4.  performed https://www.testexchangeconnectivity.com/ activesync test on a testuser -- passed all activesync tests
5.  verified this works http://kb.palm.com/wps/portal/kb/common/article/16733_en.html
6. verified i have latest version for centro http://kb.palm.com/wps/portal/kb/common/article/6012_en.html
7.  I also installed the SSL certificate onto the phone -- i don't have the link to the step-by-step but it involved downloading the certificate from the server, saving locally (where palm desktop is installed), converting the SSL certificate to a file that phone could understand (with a tool that was provided), adding new file to install directory for palm desktop, syncing with centro then soft resetting a couple times

Below is the exact error on the Palm Centro:

"SSL Error: No Trusted root.  Update CA list. Contact your administrator if this error persists."

Centro is updated to the latest versions of software (sprint 1.07) and versamail (4.0.1.00)     I'm running out of options to check/modify.  I need this to work so that i can monitor admin alerts while away from the office.  Thanks for any help.

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-04-24 at 23:15:32ID24354568
Tags

palm centro

,

exchange 2003

,

activesync

,

oma

,

exchange

,

Palm Devices

Topics

Handhelds and PDAs

,

Exchange Email Server

,

Secure Socket Layer (SSL) & HTTPS

Participating Experts
2
Points
250
Comments
18

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Problem using ActiveSync w/ Palm OS - SSL Certificates
    Hello, My company recently converted from Lotus Notes to Exchange 2007, and they are piloting the use of ActiveSync. Since it is a pilot program, they aren't giving much in the way of support. My account has been setup for Activesync, however, each time I try to sync, I am...
  2. Blackberry and Palm devices on SBS 2008
    I did some searching around but did not find anything concrete. I have SBS 2008 setup and I have a few Blackberry and Palm mobile users. I do not have a BES and the busines is too small to afford one. Has any one had success setting up these mobile devices to sync with the e...
  3. palm pre and exchange
    anyone figure out how to configure a palm pre to work with an exchange server yet
  4. Palm Treo Synch with SBS Exchange Server
    A worker has a Palm Treo 700WX that we are synching with our exchange server on SBS 2003. When in the office with his workstation on and outlook running it synchs perfectly. When the workstation is off it stops synching. On the treo it is set to synch with the exchange s...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: Whereismys4Posted on 2009-04-24 at 23:24:32ID: 24230994

below is the test result from activesync test using  https://www.testexchangeconnectivity.com/  

      
Connectivity Test Successful
Test Details
Copy to Clipboard      Expand/Collapse       
      Testing Exchange Activesync for host mail.MYDOMAIN.com
       Exchange Activesync was tested successfully
      Test Steps
       
      Attempting to Resolve the host name mail.MYDOMAIN.com in DNS.
       Host successfully Resolved
      Additional Details
       IP(s) returned: xxx.xxx.xxx.xxx
      Testing TCP Port 443 on host mail.MYDOMAIN.com to ensure it is listening/open.
       The port was opened successfully.
      Testing SSLCertificate for validity.
       The certificate passed all validation requirements.
      Additional Details
       Subject: CN=mail.MYDOMAIN.com, OU=Domain Control Validated, O=mail.MYDOMAIN.com, Issuer SERIALNUMBER=XXXXXXX, CN=Starfield Secure Certification Authority, OU=http://certificates.starfieldtech.com/repository, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US
      Testing Http Authentication Methods for URL https://mail.MYDOMAIN.com/Microsoft-Server-Activesync/
       Http Authentication Methods are correct
      Additional Details
       Found all expected authentication methods and no disallowed methods Methods Found: Basic realm="mail.MYDOMAIN.com"
      Attempting an Activesync session with server
       Testing an ActiveSync session completed successfully
      Test Steps
       
      Attempting to send OPTIONS command to server
       OPTIONS response was successfully received and is valid
      Additional Details
       Headers received: MicrosoftOfficeWebServer: 5.0_Pub Pragma: no-cache Public: OPTIONS, POST Allow: OPTIONS, POST MS-Server-ActiveSync: 6.5.7638.1 MS-ASProtocolVersions: 1.0,2.0,2.1,2.5 MS-ASProtocolCommands: Sync,SendMail,SmartForward,SmartReply,GetAttachment,GetHierarchy,CreateCollection,DeleteCollection,MoveCollection,FolderSync,FolderCreate,FolderDelete,FolderUpdate,MoveItems,GetItemEstimate,MeetingResponse,ResolveRecipients,ValidateCert,Provision,Search,Notify,Ping Content-Length: 0 Date: Sat, 25 Apr 2009 06:00:23 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET
      Attempting FolderSync command on ActiveSync session
       FolderSync command completed successfully.
      Additional Details
       Number of Folders: 11
      Attempting initial sync (no data) for Inbox folder
       Completed Sync Command successfully
      Additional Details
       Status: 1
      Attempting to test GetItemEstimate command for Inbox Folder
       Successfully received GetItemEstimate Response from Server
      Additional Details
       Estimate: 1 messages
      Attempting to test Sync of Inbox Folder
       Completed Sync Command successfully
      Additional Details
       Number of items synchronized: 0

 

by: Sourabh-ExcahngePosted on 2009-04-27 at 04:29:52ID: 24240658

hi,
have you tried configuring the profile over the windows mobile ?
and what is the common name of your certificate ?

 

by: Whereismys4Posted on 2009-04-27 at 12:48:01ID: 24245049

hi -- i dont have any users with windows mobile.  Just Palm users.  

The common name of the certificate is mail.MYDOMAIN.com

all the details are in the SSL test:

Testing SSLCertificate for validity.
       The certificate passed all validation requirements.
      Additional Details
       Subject: CN=mail.MYDOMAIN.com, OU=Domain Control Validated, O=mail.MYDOMAIN.com, Issuer SERIALNUMBER=XXXXXXX, CN=Starfield Secure Certification Authority, OU=http://certificates.starfieldtech.com/repository, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US
      Testing Http Authentication Methods for URL https://mail.MYDOMAIN.com/Microsoft-Server-Activesync/
       Http Authentication Methods are correct

please advise if there is a emulator i can load for windows mobile -- maybe i could try something with that.

 

by: Sourabh-ExcahngePosted on 2009-04-28 at 08:38:25ID: 24251960

please download the emulator from here
http://msexchangeteam.com/archive/2007/09/17/447033.aspx

 

by: Whereismys4Posted on 2009-04-28 at 10:28:18ID: 24252958

thanks will download and install as per instructions.  once i have it setup i will attemp to sync and post results.

 

by: Whereismys4Posted on 2009-04-29 at 06:18:04ID: 24260051

i installed a windows mobile 5 emulator and it works like a charm.  Palm still will not sync however now the device shows 'forming secure connection' then after about 60 secs it errors with: "SSL certificate not accepted due to possible expiration. check device date & time and re-sync".

SSL certificate is valid untill 2011 -- and works on windows mobile 5 without any problems.

to test the communication with the server and the Palm device I setup IMAP on the server (SSL only) and enabled it with Chattermail which works (removed the EAS account from versamail).  However chattermail is limited in that it only pulls emails and does not sync calendar/contacts.  

 

by: Sourabh-ExcahngePosted on 2009-04-29 at 10:16:09ID: 24262578

try and check if you have any option to cee the certificates available on the device if you see those certificate please check if you have any certificate which is not valid please delete those certificates
export the new certificate on the device.
please install all the clases of the certificate
like Root, intermitent
and i hope this will work

 

by: Whereismys4Posted on 2009-04-29 at 16:25:02ID: 24265661

here are some steps i did which did not help:

1.  deleted all outdated certificates on the server
2.  downloaded the valid mail.MYDOMAIN.com certificate on the server
3.  moved certificate to local laptop where Palm ActiveSync is installed
4.  hard reset the centro/deleted all data -- created new user profile -- hotsynced centro
5.  installed certificate from step 2
6.  setup eas on centro
7.  attempted to test settings
8.  same error: "forming secure connection' then after about 60 secs it errors with: "SSL certificate not accepted due to possible expiration. check device date & time and re-sync".

trying to locate a palm os emulator to see if i can get to work on another device  (still works on windows mobile)

 

by: Sourabh-ExcahngePosted on 2009-04-30 at 00:53:47ID: 24267720

are you using desktop sync of the air sync ?

 

by: Whereismys4Posted on 2009-04-30 at 08:05:51ID: 24270735

i'm using HotSync Manager 7.0.2
I only use the app above to upload prc files -- i do not sync outlook files

 

by: Whereismys4Posted on 2009-04-30 at 08:09:09ID: 24270778

fogot to add I have Palm Desktop 6.2.2 which i only use to upload media files

 

by: Whereismys4Posted on 2009-04-30 at 11:16:22ID: 24272802

i was able to get the palm to sync with a test SBS box by creating a self signed SSL certificate here is what i did:

1. used selfssl.exe to create new certificate (site 1)
2. exported certificate with keys locally
3. installed new certificate in trusted root cert auth folder
4. exported new root certificate without keys locally
5. pulled new cert into palm install tool
6. hard reset centro
7. hotsynced centro (installs cert)
8. setup EAS
9. was able to sync

i performed the same steps on the live SBS box and was able to sync using the self signed certificate.  However when i try this using the valid Starfield Secure Authority certificate i receive the 'SSL cert not accepted due to possible expiration'.

The certificate we have expires in 2011, i'm thinking that i may just give up on it -- what are the ramification of using a self signed SSL certificate -- only my users connect to the server for OMA/Exchange and I can just direct them to accept the error that comes up in IE/Mozilla (SSL certificate not signed by trusted authority) and add the SSL certificate exception.  

Is my traffic any less secure when using a self signed SSL certificate as opposed to a authorized CA certificate?

 

by: Sourabh-ExcahngePosted on 2009-05-01 at 02:55:30ID: 24277698

not it is still secure as you are using the Port 443 for communication
please install the root certificate on the client machine from where you are using OWA then you will not get the certificate error

 

by: Whereismys4Posted on 2009-05-01 at 05:15:43ID: 24278422

in the installation instructions of the Starfield Secure Authority (SSA) certificate i am advised to disable the Starfield Secure Authority root certificate.  This is because the SSA certificate uses a intermediate certificate.  I attempted installing first the SSA root certificate on the client which caused the the original error -- then i disabled the root and installed the intermediate certifiate on the client (same error) and finally i tried installing the 'personal' certificate and get the same error.

I'm leaning towards the certificate being too new for the palm OS to understand -- i read about that somewhere in researching this problem.  At this point i think i would rather try to test this on the Centro emulator which i have, except that i cannot get the emulator to connect to the internet thus sync.

 

by: Whereismys4Posted on 2009-05-06 at 12:49:35ID: 24318881

Palm emulator does not like the Starfield certificate either -- even after installing certificate on emulator.  I am now stuck with a valid certificate that does not work on the Palm OS... oh well when the time comes we will switch back to MS Mobile OS devices.  thanks for sticking with this question.  

 

by: Whereismys4Posted on 2009-05-06 at 12:54:04ID: 31578695

im giving you the points even though we dint come up with a solution.  i believe this is because the certificate is too new and the palm os will not recognize it -- and the fact that it's an intermediary certificate.  

 

by: oalvaPosted on 2009-07-31 at 11:27:46ID: 24991213

is this a godaddy cert?

 

by: Whereismys4Posted on 2009-08-20 at 18:10:56ID: 25148384

it is a starfield certificate -- i know godady certs have issues with palm... i've read that on other posts

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...