No Exchange email on iphones

Posted on 2010-09-03
Last Modified: 2012-05-10
I just installed windows SBS 2003 on a new server, and exchange mail works for all clients, but some users have iphones. I cannot get exchange to actually work on iphone 4.0. I ran ExRCA and got the results below...

      ExRCA is testing Exchange ActiveSync.
       The Exchange ActiveSync test failed.
      Test Steps
      Attempting to resolve the host name in DNS.
       Host successfully resolved
      Additional Details
      Testing TCP Port 443 on host to ensure it is listening and open.
       The port was opened successfully.
      ExRCA is testing the SSL certificate to make sure it's valid.
       The SSL certificate failed one or more certificate validation checks.
      Test Steps

I've tried to follow the KB on installing a cert, but it still fails on the certs validation checks. This is worth 500 points as I have to have this up and running by Sunday.
Question by:Houston Blancett

Expert Comment

ID: 33602116
SSL certs will fail unless you pay an extortionist rate to Network Solutions or Comodo or some other company for an annual cert.  For iphones, I find I set it up, let it error but it still saves the settings.  Then edit the settings to turn off SSL.  Alternatively, if you have a self-installed cert, turn on SSL and when it checks, you must accept the cert.
LVL 76

Accepted Solution

Alan Hardisty earned 500 total points
ID: 33602272
Please have a read through my Exchange 2003 / Activesync article, check your IIS settings, run the test on the test site and resolve any errors that the test site throws up.
You don't need a 3rd party SSL cert for SBS 2003 to make Activesync work, it just has to be named correctly (e.g., The iPhones will just about accept any SSL certificate (as long as they are named properly). If the cert is not named properly, just re-run the connect to the internet wizard and change nothing until you get to the certificate part, then just create a new SSL certificate with a name that resolves to your server's IP Address, then complete the wizard, changing nothing else, re-check your IIS settings (because they will change) and then test again.
When running the test on the test site, it is important to tick the "Ignore Trust for SSL" check box unless you have a 3rd party certificate.
My article: my article cannot get you working - then only a call to Microsoft will !!


Expert Comment

ID: 33602401
I suggest to install an certificate from authorized certificate authority on exchange server and then test IPhone Active Sync. You can go for free  trial certificate from It will work for 30 days. Please get the certificate, install it on exchange and then test Active Sync using SSL.
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

LVL 76

Expert Comment

by:Alan Hardisty
ID: 33602472
A 3rd Party SSL certificate is not a requirement for Activesync to work with an iPhone. If you have Windows Mobile Phones, then you have to install the self-issued certificate on the phones, but the iPhones only care about the name on the certificate matching the FQDN entered for the servername (e.g.,
3rd Party SSL certificates can make the process easier all round and the cheapest 3rd Party SSL certs are usually found at GoDaddy ( - only a single name certificate is required. You could always visit my GoDaddy Reseller account at too) ; )
I have customers with SBS 2003 servers with self-issued certificates working 100% happily with iPhones and Windows Mobile phones.
LVL 76

Expert Comment

by:Alan Hardisty
ID: 33602482
It is also worth noting that there is a bug with the early release of iOS4 and if you don't have iOS 4.0.2 at least, then you will need to download a fix: 

Expert Comment

ID: 33602833

Please check you have exchange 2003 sp2 installed. Even if you have all the configurations correct without sp2 the iphones wont collect mail.

Apart from that alanhardisty has covered most of the bases.

LVL 76

Expert Comment

by:Alan Hardisty
ID: 33602864
@evilsi - SP2 is covered in my article ;)

Author Closing Comment

by:Houston Blancett
ID: 33603578
The first part cleared everything up. I simply needed to install service pack 2 for exchange. Excellent article!
LVL 76

Expert Comment

by:Alan Hardisty
ID: 33603923
Thanks musicmd - glad my article helped resolve your problem and glad you liked the article.  Did you vote for the article too : )

Featured Post

Gigs: Get Your Project Delivered by an Expert

Select from freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

MS Outlook is a world-class email client application that is mainly used for e-communication globally.  In this article, we will discuss the basic idea about MS Outlook, its advanced features, and types of MS Outlook File formats.
Find out what you should include to make the best professional email signature for your organization.
In this video we show how to create a Distribution Group in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >>…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit If you want to manage em…

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question