Avatar of aucklandnz
aucklandnz
Flag for New Zealand asked on

windows mobile sync problem (certificate is not valid)

Hi All,
I was trying to install certificate (issued by godaddy) on my treo750v  using spaddcert but im getting error "This certificate is not valid root certificate. Please select a valid root certificate"
The i have added the certificate using .cab file. It appears under root certificates but i still cannot syn with my exchange.

im running exchange 2003sp2 and iis6.
treo is running windows mobile version 5

thanks

Ps i was able to syn before with self signed certificate but i had to buy one from godaddy as i have upgraded my laptop to vista and i could not sync my outlook over rpc/https. after i bought certificate from godaddy i could sync my outlook on my vista machine but now i cannot sync my mobile.

please help

Thanks
Exchange

Avatar of undefined
Last Comment
Computer101

8/22/2022 - Mon
Sembee

Have you added the intermediate certificate to the device as well?
That can only be done with a cabinet file - not with the spaddcert tool.

Simon.
aucklandnz

ASKER
do i have to create .cab from intermidiate certificate follow your steps www.amset.info/pocketpc/certificates3.asp 

aucklandnz

ASKER
when i purchasede ssl from godaddy they have sent me two certificates
1. mydomain.com.crt
2. gd_iis_intermidiates.p7b
Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy
Sembee

If you open the second file you will have two additional certificates.
One needs to go in to the intermediate certificate store on the server, the other in to the root store.
GoDaddy Class 2 in the root
GoDaddy Secure in the intermediate.

As long as the valicert is in the root certificates on the Windows Mobile device there is nothing to install on the device - it is all server.

Simon.
aucklandnz

ASKER
thanks for the reply,

Im a bit confused.

I opened the gd_iis_intermidiates.p7b in certmgr.
what do i have to do with 2 files that are there?

Thnkas
Sembee

You need to right click on them and save them out to separate files. Make sure that they are saved as .cer files. Once you have saved them both out, you can double click on them to see which one is which.

Simon.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
aucklandnz

ASKER
after i save them, do i have to install them on the server and mobile device ?

Thanks
Sembee

Only the server, not the device.

The whole point of using these certificates is so that you don't have to install anything on the device.

Simon.
aucklandnz

ASKER
what should i save them as ?

thanks
Your help has saved me hundreds of hours of internet surfing.
fblack61
Sembee

Doesn't really matter. You are going to be importing the files, so once they have been saved you can dispose of the files or store them somewhere. I think I called mine root and intermediate so I knew which was which.

Simon.
aucklandnz

ASKER
still doesnt work, i have restared IIS and my mobile.
on my mobile im getting the following error

0x80072F0D

cheers
Sembee

If you browse to the site in Internet Explorer on the desktop, double click on the yellow shield icon, then choose Certificate path, you should see four steps. If you only see three then you have one of the certificates wrong.

I am writing my own guide for the installation of these certificates at the moment, but been a little busy with clients.

Simon.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
aucklandnz

ASKER
all i see is a lock. when i click on it i get
Website identification
godaddy calss 2  certification authority
mymailserver.mydomain.com
This connection to the server is encrytpted
should i trust this site?
view certificates



thanks
Sembee

That sounds you are looking on the Windows Mobile device - I meant Internet Explorer on the desktop. You should have three tabs - certificate path is the the third tab.

Simon.
aucklandnz

ASKER
i used my desktop computer
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck
Sembee

I have articles in progress on installing the GoDaddy certificates.
However I do have some screenshots on my web site of working and non-working certificate installations.
http://www.amset.info/ssl/wmerror.asp

Simon.
aucklandnz

ASKER
i have 4 steps
1.VeliCert Class 2 Policy Validation Authority
1.1 Go Daddy Class 2 Certification Authority
1.2 Go Daddy Secure Certification Authority
1.3 Mymailserver.mydomain.com

Sembee

Not entirely sure that the top certificate is correct.
That should be a Starfield certificate if the Go Daddy certificate has been issued since February 2007.

Simon.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
aucklandnz

ASKER
so what should i do now, reinstall certificate ?
Sembee

It isn't your certificate that is wrong - it is the root certificate.
Did you use the certificates that came with your certificate, or did you download them from the repository web site?

Simon.
aucklandnz

ASKER
cant realy remember
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes
Sembee

Do you still have the files that were sent to you by the certificate issuer?
You have should have had two - you own certificate file and the root/intermediate bundle.

This is their repository: https://certificates.godaddy.com/Repository.go
The one you want is "Go Daddy PKCS7 Certificate Intermediates Bundle (for Windows IIS) "

Download that and open it up. Inside is two certificates. Save the one issued by valicert as the root and the other one as the intermediate.
Then import them in to the relevant certificate stores.

Simon.
aucklandnz

ASKER
still not working :(
Sembee

I would remove the certificates that you have installed and and reinstall them.
Also ensure that you are working in the correct context for the certificates when you start the Certificate MMC applet - it should be the local computer.

Simon.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
aucklandnz

ASKER
i have unistalled cerificates and installed it again and now, nothing is working even web access.
aucklandnz

ASKER
when i right click on my default web site and then click on security tab and server certificate i have option create new certificate. what do i do now ?

Thanks
aucklandnz

ASKER
i got my OWA working but my mobile doesnt sync . now i have a different error code
0x85030022

thanks
I started with Experts Exchange in 2004 and it's been a mainstay of my professional computing life since. It helped me launch a career as a programmer / Oracle data analyst
William Peck
ASKER CERTIFIED SOLUTION
Sembee

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
Computer101

Forced accept.

Computer101
EE Admin