Fun With ActiveSync and SSL

HTC ApacheNew phone, new hassles. Same old same old. Due to a corporate discount opportunity, I’ve picked up a nifty little HTC Apache PDA/Phone attached to the local monopoly carrier’s EVDO system. Sweet, I thought, MS Exchange activesync over EVDO will mean I’m never out of touch.

Activesync under Windows Mobile 5.0 is streets ahead of PocketPC 2003SE (the previous OS), allowing for clean syncronisation with multiple ‘partners’, and remote sync with Exchange 2003 over SSL. Great stuff, except the SSL sync does not allow for wildcard SSL certificates. Crazy as it sounds, corporations that use a wildcard cert (e.g. *.corporation.com) to cover multiple SSL sites (e.g. mail, webmail, activesync) will not be able to provide mobile sync support to WM5 devices.

Thankfully there is a workaround. As long as you have permissions on your device, you can modify the registry such that Activesync will not check the validity of an SSL certificate before commencing an SSL connection. The security implications of this are obvious, but as long as you trust your system admins, and bank on the fact that no one will hijack your server’s sync DNS address, then it should be fine. So, grab your PPC registry editor of choice, navigate to HKCU\Software\Microsoft\Activesync\Partners\, determine which of the ‘Partners’ subkeys is your mobile exchange server (hunt through and you should see your mobile Exchange URL under one of the keys), then add a DWORD value named ‘Secure’ with a value of 0. Bingo.

Ugly hack, but it worked for me.? Unsure if this is a WM5 global thing, or just for HTC devices, or even just for this one HTC Apache.

4 Replies to “Fun With ActiveSync and SSL”

  1. this solution doesn’t work on the treo 700. setting that registry entry still causes activesync to choke on our exchange ssl connection. anyone having luck with the treo?

  2. Hmm in the end our email guys actually registered a separate SSL cert for the Activesync URL to avoid the whole hassle. Unsure if there is any better solution than that.

  3. Work well in Treo 750v WM5, but when I finish upgrade to WM6, it seem not effect. I cannot sync with my office push email powered by Exchange 2003 SP2. Anyone can help me how to solve this problem ?

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.