We help IT Professionals succeed at work.

We've partnered with Certified Experts, Carl Webster and Richard Faulkner, to bring you two Citrix podcasts. Learn about 2020 trends and get answers to your biggest Citrix questions!Listen Now

x

Exchange Server ActiveSync 80072F0D

Rick Mills
Rick Mills asked
on
Medium Priority
1,669 Views
Last Modified: 2012-06-27
I've done this a number of times on SBS 2003, but now I have to setup a Windows Mobile 5 device to sync with Exchange 2003.  This is Exchange running on 2003 Server Standard, not SBS.

I have created a self-signed certificate on the Exchange server.  
I can login to https://servername/exchange and use OWA.
I can login from the WM5 device and use OWA.
I have exported the certificate (using a variety of methods) and installed it on the WM5 device.
I can go to certificates on the WM5 device, click on the Root tab and see the certificate.
Every time I try to sync with the Exchange server, I receive a 80072F0D error.  Everything I find about this error indicates the certificate is invalid on the server, but the certificate works fine for OWA.
I've tried a Cingular 8125 and the MS Pocket PC Emulator.  I get the same error on both.

Can anyone out there offer any suggestions on how to troubleshoot this error?
Comment
Watch Question

Hi,

As you have mentioned, this is a certificate error. Open up IE on the mobile device and browse the OWA URL. If you get a security warning prompt, then look at the point against which you get an exclamation mark. That will be the cause of your problem.

Ideally, the Issued To value on the cert and the URL that you use should match.

If you have got any intermediate Root CAs, those cert should also be trusted.

So post the message against which you get the exclamation mark when you try to access the OWA URL from the device.

Thanks,
Vasanth.
Rick MillsPresident

Author

Commented:
Vasanth,
Thanks for the response.
Let me update before I respond to your suggestions.

I'm not well versed in certificates and thought I might have messed up creating the cert.
Therefore, I went to RapidSSL.com and got a 30-day free trial on a cert.  If it worked, I would have been happy to pay for a cert and get this working.  However, it did not work.
I get the same results as the cert I created.

So, to respond to your suggestion.  I was on the mobile device and browsed to https://FQDN/owa.
I received a warning.  The exclamation mark is on the message "the certificate was issued by a company you have not chosen to trust."
I get a green check on "the certificate date is valid."
I get a green check on "the certificate has a valid name matching the name of the page you are trying to view."

If I go to root certificates on the mobile device, I can view the certificate details and verify it is issued to the FQDN that I'm using when browsing.

I'm afraid I don't know enough about certs to know if I have any intermediate root CAs.  Based on the creation process when I created the cert and based on the process with RapidSSL.com, I am not aware of any other certs related to this one.

Any suggestions on further diagnosing this?
Thanks,
Rick
Hi Rick,

It seems like you have a cert with intermediate root certificates. You will have to trust the whole chain of certs in order for AS to work fine. To do so, Open IIS --> Default Web Site --> Properties --> Directory Security --> View Certificate.

In the cert, click on the Certification Path tab. You will have to click on each and every level on the path (typically certs) and click on view certs. Go to details tab and use the copy to a file. Save all the certs and trust them in the device. Test Activesync.

Thanks,
Vasanth.

Not the solution you were looking for? Getting a personalized solution is easy.

Ask the Experts
Rick MillsPresident

Author

Commented:
Vasanth,
Thanks so much for your help.  That was the key.
I've now understand a little bit more about certs.
Thanks,
Rick
Access more of Experts Exchange with a free account
Thanks for using Experts Exchange.

Create a free account to continue.

Limited access with a free account allows you to:

  • View three pieces of content (articles, solutions, posts, and videos)
  • Ask the experts questions (counted toward content limit)
  • Customize your dashboard and profile

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.