Installing certificates, Problems installing my "freebie" MS cert |
![]() ![]() |
Installing certificates, Problems installing my "freebie" MS cert |
Jan 15 2006, 18:33
Post
#21
|
|||
|
Newbie Group: Posters Posts: 6 Joined: 7th October 2004 Member No.: 59,538 |
I was able to add my own certificate to my c600 by changing the value of following registry entry on the device:
HKLM\Security\Policies\Policies\00001017 from 128 to 144. I also changed 00001001 to 1 and 00001005 to 40 but i dont think that helped. Restart the device. Export the desired certificate as a binary encoded (DER) certificate (.cer). Copy the .cer file to the device. Open the .cer file on the device via file explorer. So I now have the certificate listed in the root certificate list, but when I use ActivSync with my exchange server I get an error that says "The security certifcate on the server is invalid. Contact your Exchange Server administrator or ISP to install a valid certificate on the server." Great |
||
|
|
|||
|
Jan 16 2006, 18:46
Post
#22
|
||
|
Regular Group: Posters Posts: 52 Joined: 27th May 2004 Member No.: 44,664 Device(s): Qtek 8310 |
QUOTE(cbch @ Jan 15 2006, 18:33) I was able to add my own certificate to my c600 by changing the value of following registry entry on the device: HKLM\Security\Policies\Policies\00001017 from 128 to 144. I also changed 00001001 to 1 and 00001005 to 40 but i dont think that helped. Restart the device. Export the desired certificate as a binary encoded (DER) certificate (.cer). Copy the .cer file to the device. Open the .cer file on the device via file explorer. So I now have the certificate listed in the root certificate list, but when I use ActivSync with my exchange server I get an error that says "The security certifcate on the server is invalid. Contact your Exchange Server administrator or ISP to install a valid certificate on the server." Great Ok the thing you have to be carefull with is that the exported root cert "issued to" name matches the name of the address (url) you are trying to connect to with the SPV c600, using GPRS. In my case i am using a dynamic IP (I dont use a domain name) so the root cert "issued to" name name has to be my external IP. If you are connecting to "your_external_domain.com" but the certificate you created on your CA server and then copied to your SPV has the "issued to" name as "internal_domain.com" the connection will fail. You must also make sure the the Exhchange Web components on IIS are using the same Cert to provide an SSL connection. Again in my case the SSL certficate is installed under the "Default web site" in IIS as this is where the Exchange web components are installed. Hope this helps !! |
||
|
|
|||
|
Jan 19 2006, 14:10
Post
#23
|
||
|
Newbie Group: Posters Posts: 7 Joined: 15th January 2006 Member No.: 167,681 Device(s): Audiovox |
help me....
i had extract regedit.zip file... then,what should i do next?open or run? when i open the file,its show other registry not regedit... when i run the file,it want me to put "command" and "parameters" :??: |
||
|
|
|||
|
Feb 27 2006, 18:35
Post
#24
|
||
|
Newbie Group: Posters Posts: 5 Joined: 27th February 2006 Member No.: 174,981 Device(s): TMobile SDAM |
QUOTE(dm.wood @ Jan 16 2006, 12:46) Ok the thing you have to be carefull with is that the exported root cert "issued to" name matches the name of the address (url) you are trying to connect to with the SPV c600, using GPRS. In my case i am using a dynamic IP (I dont use a domain name) so the root cert "issued to" name name has to be my external IP. If you are connecting to "your_external_domain.com" but the certificate you created on your CA server and then copied to your SPV has the "issued to" name as "internal_domain.com" the connection will fail. You must also make sure the the Exhchange Web components on IIS are using the same Cert to provide an SSL connection. Again in my case the SSL certficate is installed under the "Default web site" in IIS as this is where the Exchange web components are installed. Hope this helps !! Thanks - that's helpful. So the "issued to" name is just the IP address if you are using dynamic IP? |
||
|
|
|||
|
Feb 28 2006, 23:58
Post
#25
|
||
|
Regular Group: Posters Posts: 52 Joined: 27th May 2004 Member No.: 44,664 Device(s): Qtek 8310 |
|||
|
|
|||
|
Mar 16 2006, 21:37
Post
#26
|
||
|
Newbie Group: Posters Posts: 13 Joined: 4th March 2006 Member No.: 175,810 Device(s): HTC Tornado / Qtek 8310 |
Hi! I'm a complete idiot in this tweaking of the smartphone world. I have a Qtek 8310 which is not bound to any network carrier. (ie. no special menus and stuff).
My question is. Do I need to install a root certificate on my phone? If i do, where do I find it? As I said, completely new to this. So I beg for your patience. Thanks! |
||
|
|
|||
|
Mar 16 2006, 23:26
Post
#27
|
||
![]() Hardcore Group: Moderator Team Posts: 8,218 Joined: 9th April 2003 From: Coventry, UK Member No.: 4,510 Device(s): HTC Touch Dual / SPV E650 |
The simple answer is 'no' - unless you know what these guys are talking about
I assume you're thinking about application unlocking. The lock is put on the phone (usually by the operator/network) to stop you installing software that they haven't approved. (etc...blah...) If the phone refuses to install software and gives you the message that the program isn't digitally signed then you need to do the unlocking procedure. This usually occurs where registry changes are required. Unlocking instructions are in the pinned 'SP5 Tweaks' thread pinned at the top of this section. Otherwise I wouldn't worry about it. Most things will work with just a warning and you simply confirm you want to continue the install. -------------------- First 48 Hours with a Smartphone ? Go here
Installing skins & other software MoDaCo Plus ! - join here Orange Official SPV Application Unlocking "What shirt am I wearing bro ? Are you serious ?" Jermaine Beckford 14th January 2008 |
||
|
|
|||
|
Mar 21 2006, 21:43
Post
#28
|
||
|
Newbie Group: Posters Posts: 5 Joined: 27th February 2006 Member No.: 174,981 Device(s): TMobile SDAM |
QUOTE(dm.wood @ Feb 28 2006, 17:58) I forwarded the request for changing the "Issued To" name to our tech person, plus a suggestion from MoDaCo which advised us to "Export the root certificate from the Certificate Authority in your domain (in DER format)" Our tech person came back to me with the following problem: "Unfortunately, we require a certificate of authority which our server is not configured with. The certificate from exchange can not be exported into a *.der format. " Does that make sense? Any advice? Thanks! |
||
|
|
|||
|
Mar 21 2006, 23:45
Post
#29
|
||
|
Regular Group: Posters Posts: 52 Joined: 27th May 2004 Member No.: 44,664 Device(s): Qtek 8310 |
QUOTE(wbremner @ Mar 21 2006, 21:43) I forwarded the request for changing the "Issued To" name to our tech person, plus a suggestion from MoDaCo which advised us to "Export the root certificate from the Certificate Authority in your domain (in DER format)" Our tech person came back to me with the following problem: "Unfortunately, we require a certificate of authority which our server is not configured with. The certificate from exchange can not be exported into a *.der format. " Does that make sense? Any advice? Thanks! If your network administrator purchased a certificate from a commercial certificate authority (such as Verisign) for use with your Exchange Outlook Web Access component or website etc it is unlikely that they have a windows certificate authority set up. You might like to explain to him that setting up a Windows Certificate Authority is quite a simple process. Your are not actually exporting the root certificate from the Certificate Authority in *.der format. What you need to do is export the root certificate in "DER Encoded binary X.509" fomat. When you export in this format it creates a *.CER file (not a *.DER file). Hope this helps! |
||
|
|
|||
|
Mar 26 2006, 16:12
Post
#30
|
||
|
Newbie Group: Members Posts: 1 Joined: 26th March 2006 Member No.: 179,375 Device(s): Tmobile SDA |
Hi I have T-Mobile SDA (US Version) and I did all the steps above.
ApplicationUnlock.exe fails with error "Internal Error" Anyone got the same error and fixed it. EDIT: had to reset my phone and then it worked fine. QUOTE(willcheng @ Jan 5 2006, 05:39) Thanks for this - I'm probably doing some of the steps wrong - I'll have another go.
I don't think this could be an issue with my device - I think it is a WM5 issue so hopefully if it works on your QTeks then it should work on my MDA Vario (which is a Qtek 9100). Btw - Did you have a look at the version of regedit that I attached? This post has been edited by tmosda: Mar 27 2006, 11:52 |
||
|
|
|||
Mar 26 2006, 17:58
Post
#31
|
|||
|
Newbie Group: Members Posts: 1 Joined: 26th March 2006 Member No.: 179,488 Device(s): Cingular 8125 |
Hello - I am a first time poster begging for assistance.
I have a Cingular 8125 running WM5.0. I am using Activesync 4.1 (which came with the phone). My business uses Exchange - from which I can access via the web using OWA. My Activesync on my 8125 was working on and off about 4 days ago - and now does not work at all in synching with my server. Everytime my mail on my 8125 tries to synch with my server, I receive an error on Activesync that says, "Your account in Microsoft Exchange Server does not have permission to synchronize with your current settings. Contact your Exchange Server administrator. Support code:0x85010001" I have called Cingular, Microsoft, and my company internal IT department. Cingular and MS basically said, "not our problem". My company exchange server IT group is looking at it - but nothing has changed in 5 days. It appears to me that my issue is related to the one on this board. I am asking that someone who has seen this issue and knows how to resolve it - please let me know. I can email you - or even call you for assistance. Like many of you on this board - the reason I bought this phone was for the email Activesync - which is not working at all! PLEASE PLEASE HELP! Thanks, Dan |
||
|
|
|||
|
Oct 26 2006, 04:37
Post
#32
|
||
|
Newbie Group: Posters Posts: 5 Joined: 23rd October 2006 Member No.: 211,283 Device(s): null |
I'm able to copy the regtryit.exe to the phone however, when i try o run it by double clicking - it doesn't do anything but opens up the properties - what am i doing wrong? desperately need help.
Thanks. |
||
|
|
|||
|
Oct 28 2006, 08:08
Post
#33
|
||
|
Newbie Group: Posters Posts: 2 Joined: 28th October 2006 Member No.: 211,951 Device(s): tmobile Dash |
I have the Tmobile Dash - I can't add my own certificate as described here, but I can't make any changes to the Registry either. Apparently Tmo has the registry locked down.
Anybody run into this? Regedit doesn't work - and either does RAPI. Everytime I try to change a value in the registry, it is it can't do it. I even tried renaming and creating, but it seems like it is a read only register file. I can't get to my exchange server. No fun! |
||
|
|
|||
|
Nov 16 2006, 22:49
Post
#34
|
||
|
Newbie Group: Posters Posts: 1 Joined: 16th November 2006 Member No.: 214,456 Device(s): Dash |
I have the Tmobile Dash - I can't add my own certificate as described here, but I can't make any changes to the Registry either. Apparently Tmo has the registry locked down. Anybody run into this? Regedit doesn't work - and either does RAPI. Everytime I try to change a value in the registry, it is it can't do it. I even tried renaming and creating, but it seems like it is a read only register file. I can't get to my exchange server. No fun! Same problem - I really need to get a fix because the CEO for my company is now my only Dash user and hence the only one using email without SSL. Everyone else uses Motorola Q's. I sent a details technical support email via T-Mobiles website, however I didn't even recevie a ticket opened auto response. If you know the solution for the T-Mobile Dash adding a root cert please share? |
||
|
|
|||
|
Nov 22 2006, 22:45
Post
#35
|
||
|
Newbie Group: Posters Posts: 1 Joined: 22nd November 2006 Member No.: 215,231 Device(s): dash |
I have the Tmobile Dash - I can't add my own certificate as described here, but I can't make any changes to the Registry either. Apparently Tmo has the registry locked down. Anybody run into this? Regedit doesn't work - and either does RAPI. Everytime I try to change a value in the registry, it is it can't do it. I even tried renaming and creating, but it seems like it is a read only register file. I can't get to my exchange server. No fun! I too had problems using the regedit program on the dash. I found a reg editor called MobileRegistryEditor on the net and it runs on the desktop and edits the registry of the device through activesync. All seems to be working now. James |
||
|
|
|||
|
Nov 14 2007, 20:25
Post
#36
|
||
|
Newbie Group: Posters Posts: 3 Joined: 14th November 2007 Member No.: 322,145 Device(s): Opticon H16 |
1. Go to http://www.modaco.com/INFO_Decert_SIM_Unlo...50-t222786.html. 2. Download the HTC-signed "regeditSTG.zip" and move it to your smartphone. IMPORTANT: Put it on the phone, not on a memory card - this was my first sticking point. 3. Extract the zip file using Explorer on the device (if it's a WM5 device). 4. Run the Regedit exe and follow the instructions on the page above for registry changes to make. It was also suggested by a Microsofty a few posts down to change 00001017 (4119) to 144 (in the same part of the registry), although I'm not sure what each entry does. I did all three. :-) 5. Download SDA_ApplicationUnlock.exe from http://www.modaco.com/Motorola_MPx220_and_...0_app_locked..., connect the device, run this app, click "Unlock" or whatever, then restart the device. 6. Export the root certificate from the Certificate Authority in your domain (in DER format), copy it to the phone (again NOT the memory card) and simply run it from Explorer. Bob's yer uncle. I can't seem to get step 3 to work, but first as I look at this, are these instructions smartphone specific? I'm running PPC. I can't unzip the file on the device. If I unzip on my PC and copy it over to the H16, the regedit comes up, but only shows the hive roots, and I can't open below the roots. -------------------- |
||
|
|
|||
![]() ![]() |
Similar Topics
| Topic | Replies | Topic Starter | Views | Last Action | |
|---|---|---|---|---|---|
![]() |
i900 - Installing original Australian ROM | 0 | Ranga | 286 | 15th November 2008 - 12:00 Last post by: Ranga |
![]() |
Help to fix some bugs after installing Manila 2D Comm Manager, iGo 8, change buttons... |
1 | foxmylife | 376 | 26th November 2008 - 01:53 Last post by: foxmylife |
![]() |
"OMNIA_i900DXHK2_PV05_M2D" |
7 | teslation | 621 | 17th December 2008 - 13:52 Last post by: fredswatchbox |
![]() |
Installing new T9 dictionary (WM6) I need a bit of help with my new device |
0 | toketoke | 250 | 25th December 2008 - 13:12 Last post by: toketoke |
![]() |
Having trouble installing ROMs | 4 | xnickyxcorex | 149 | 30th December 2008 - 20:47 Last post by: Nost@lgia |
![]() |
[FIXED] Trouble installing Windows Mobile Device Center Installation error |
0 | Tim Sandau | 55 | 4th January 2009 - 19:21 Last post by: Tim Sandau |
|
Lo-Fi Version | Time is now: 8th January 2009 - 18:38 |
Please visit our 'Plus Partners' - these companies support MoDaCo through 'MoDaCo Plus' - Click Here for more details!
ActiveKitten |
Aiko Solutions |
Ateksoft |
Binaryfish |