Posts
254
Comments
120
Trackbacks
120
Windows Mobile 5.0 and SSL certs

I still owe y'all a review of my new Qtek 9100 PDA/cellphone running Windows Mobile 5.0, but in the meantime, as I'm working on some other WM5.0 projects, I wanted to share word of what is turning out to be a potentially huge problem with the new WM 5.0 devices, depending on which devices you buy and which carriers you get them from. This post from the Windows Mobile Team Blog, "Adding Root Certificates for Exchange Activesync", doesn't provide a lot of detail and background, but the comments give you a bigger picture of how much trouble this is causing folks.

The base problem is that some WM5.0 devices, depending on how they've been configured by the OEM (in many cases the carrier that sells the device), do not allow end-users to install additional root certificates. This is great if you're only using SSL certs from a major vendor, but if you're using self-signed certs, this becomes a problem. The Windows Mobile 2003 workaround of disabling SSL for EAS isn't an option in WM5.0. Normally, I'd be happy about how the use of SSL is enforced -- I've never advised using OWA/EAS/OMA over unencrypted connections -- but in this case, a lot of people are frustrated because they can't use their new devices to synchronize with Exchange. Since that was the only real functionality I was interested in for my Qtek, I have to say I'd have been extremely unhappy to find out I wasn't able to do it.

The moral of the story is simple: be very, very choosy about which vendors and carriers you buy your WM5.0 devices from. Insist that they either provide the tool you need to install your own root certificates (if you don't get management access to the device) or insist on having devices configured so that you have management access.

posted on Wednesday, February 15, 2006 10:05 AM Print
Comments
Gravatar
# re: Windows Mobile 5.0 and SSL certs
Ben Winzenz
3/8/2006 11:24 AM
Have you tried gaining access to the registry on your device? If you can get access to the registry, you can disable cert-checking, which should still allow you to use SSL, it just doesn't check if the cert is valid. I thought I had blogged about it , but it appears I haven't yet. I'll send you the info I used (and will blog about it today).

Ben
Gravatar
# An update on Windows Mobile 5.0 certificates
(e)Mail Insecurity
3/23/2006 11:54 AM
Gravatar
# An update on Windows Mobile 5.0 certificates
(e)Mail Insecurity
3/23/2006 11:55 AM
Gravatar
# re: Windows Mobile 5.0 and SSL certs
Jason
5/21/2007 11:03 AM
Hi there,

Trying to hook my TMobile Dash up to Exchange 2003, but am repeatedly receiving the error message 0x85010014. Any ideas? This hex number is everywhere online, however nobody seems to have a definitive solution to the problem.

Thank you!
Jason
Comments have been closed on this topic.
News

Devin has moved on
to new adventures.
This blog is preserved
for historical purposes.

Please follow his
personal blog at:

Devin on Earth


Virtual Devin