• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1592
  • Last Modified:

Exchange Server ActiveSync 80072F0D

I've done this a number of times on SBS 2003, but now I have to setup a Windows Mobile 5 device to sync with Exchange 2003.  This is Exchange running on 2003 Server Standard, not SBS.

I have created a self-signed certificate on the Exchange server.  
I can login to https://servername/exchange and use OWA.
I can login from the WM5 device and use OWA.
I have exported the certificate (using a variety of methods) and installed it on the WM5 device.
I can go to certificates on the WM5 device, click on the Root tab and see the certificate.
Every time I try to sync with the Exchange server, I receive a 80072F0D error.  Everything I find about this error indicates the certificate is invalid on the server, but the certificate works fine for OWA.
I've tried a Cingular 8125 and the MS Pocket PC Emulator.  I get the same error on both.

Can anyone out there offer any suggestions on how to troubleshoot this error?
0
rickmills
Asked:
rickmills
  • 2
  • 2
1 Solution
 
vasanthgnbCommented:
Hi,

As you have mentioned, this is a certificate error. Open up IE on the mobile device and browse the OWA URL. If you get a security warning prompt, then look at the point against which you get an exclamation mark. That will be the cause of your problem.

Ideally, the Issued To value on the cert and the URL that you use should match.

If you have got any intermediate Root CAs, those cert should also be trusted.

So post the message against which you get the exclamation mark when you try to access the OWA URL from the device.

Thanks,
Vasanth.
0
 
rickmillsAuthor Commented:
Vasanth,
Thanks for the response.
Let me update before I respond to your suggestions.

I'm not well versed in certificates and thought I might have messed up creating the cert.
Therefore, I went to RapidSSL.com and got a 30-day free trial on a cert.  If it worked, I would have been happy to pay for a cert and get this working.  However, it did not work.
I get the same results as the cert I created.

So, to respond to your suggestion.  I was on the mobile device and browsed to https://FQDN/owa.
I received a warning.  The exclamation mark is on the message "the certificate was issued by a company you have not chosen to trust."
I get a green check on "the certificate date is valid."
I get a green check on "the certificate has a valid name matching the name of the page you are trying to view."

If I go to root certificates on the mobile device, I can view the certificate details and verify it is issued to the FQDN that I'm using when browsing.

I'm afraid I don't know enough about certs to know if I have any intermediate root CAs.  Based on the creation process when I created the cert and based on the process with RapidSSL.com, I am not aware of any other certs related to this one.

Any suggestions on further diagnosing this?
Thanks,
Rick
0
 
vasanthgnbCommented:
Hi Rick,

It seems like you have a cert with intermediate root certificates. You will have to trust the whole chain of certs in order for AS to work fine. To do so, Open IIS --> Default Web Site --> Properties --> Directory Security --> View Certificate.

In the cert, click on the Certification Path tab. You will have to click on each and every level on the path (typically certs) and click on view certs. Go to details tab and use the copy to a file. Save all the certs and trust them in the device. Test Activesync.

Thanks,
Vasanth.
0
 
rickmillsAuthor Commented:
Vasanth,
Thanks so much for your help.  That was the key.
I've now understand a little bit more about certs.
Thanks,
Rick
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now