How do I add the self-signed sbs 2011 certificate to an android phone?

Posted on 2014-07-22
Last Modified: 2016-07-19
How do I add the self-signed sbs 2011 certificate to an android phone?
Question by:Ken Macleish
  • 4
LVL 11

Accepted Solution

diprajbasu earned 100 total points
ID: 40213450
place the certificate in your SD card.
go to your phone security settings and install the certificate.
LVL 63

Assisted Solution

btan earned 300 total points
ID: 40213516
pls see this if helps

Copy the .crt file to the root of the /sdcard folder inside your Android device
Inside your Android device, Settings > Security > Install from storage. It should detect the certificate and let you add it to the device

Browse to your development site. The first time it should ask you to confirm the security exception. That's all. The certificate should work with any browser installed on your Android (Browser, Chrome, Opera, Dolphin...)

Remember that if you're serving your static files from a different domain... you also need to add the certificate for that domain.

However, you should be careful to make sure your self-signed certificate has a reasonably strong key. As of 2012, a 2048-bit RSA signature with an exponent of 65537 expiring yearly is acceptable. When rotating keys, you should check for recommendations from an authority (such as NIST) about what is acceptable.
LVL 16

Assisted Solution

by:Dirk Mare
Dirk Mare earned 100 total points
ID: 40214110
If its the same key your OWA is using you can connect the phone to Wifi and browse to your OWA page and you should be able to install the certificate via your browser..

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

LVL 63

Assisted Solution

btan earned 300 total points
ID: 40214238
I was reviewing some public info and there is case where Android accept BKS certificates whereas most of the time a CER certificate with keytool is created instead. The suggested step to produce the BKS and import is as follows.

Download portecle (
Run the program
File > New KeyStore > BKS
Tools > Import Trusted Certificate > alias = server
Save Keystore (pass = keypass) as C:\temp\server.bks
Copy the file to the Android project in res/raw/server.bks
LVL 63

Assisted Solution

btan earned 300 total points
ID: 41711585
The approach for installing for android is shared,  the process is to change pem to CRT first

As is in Google’s documentation, you can add your own certificates to the phone, but it has to be in the DER or PKCS#12 format. This is different from the usual PEM format which you would set up for your website, but thankfully a few lines of a shell script and the OpenSSL toolkit will get you on your way:

echo | \
  openssl s_client -connect ${SERVER}:${PORT} 2>&1 | \
  openssl x509 -outform DER -out ${SERVER}.crt
and thereafter

Pop that resulting .crt file into the root directory of your phone, then go to the Settings -> Personal -> Security -> Credential Storage -> Install from storage. It’ll find your self-signed cert, at which point you can use it without the error messages in any of your applications.

You can then remove any of these certificates via “Trusted credentials” under the similar “Credential Storage” area, and clicking on the “User” tab. Click on the certificate, and scroll the detail view to the bottom to reveal the (otherwise hidden) “Remove” button.
LVL 63

Expert Comment

ID: 41711586
For consideration of ID: 41711585 and ID: 40213516 as solution.

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Manually Remove Symantec PGP DE 6 119
Truecrypt and swap 6 139
Security perspectives to assess for APIs 1 40
SSD encryption options with Windows 10 Pro 5 56
Explore the encryption capabilities built into Google Apps and how these features can help you meet privacy policy and regulatory compliance, but are not a full solution. Understand and compare the most popular email encryption services for Google A…
There are many Password Managers (PM) out there to choose from. PM's can help with your password habits and routines, but they should not be a crutch you rely on too heavily. I also have an article for company/enterprise PM's.
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question