Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

pesos

macrumors 6502a
Original poster
Mar 30, 2006
702
196
So our Exchange 2010 activesync has been humming along just fine with winmobile, iphones, droids, etc.

Over the weekend we renewed our SSL cert - the old one was based on the Starfield root, the new one is based on the GoDaddy root. Shouldn't be an issue though - the intermediates are installed and OWA works just fine on Windows browsers as well as Safari on OS X 10.6 -- OWA also works fine from the iphone.

However! iPhones have stopped working via activesync, throwing "connection to server failed" - thanks for that helpful generic message apple.

Palm Pres and Droids still seem to be synching fine, and the weirdest part is that my iphone seems to be the only one that is still working fine (I am running os4 beta 2 - everyone else i've talked to who isn't working are running 3.1.3).

I would think if anything that I should be the one having problems! Any ideas would be quite welcome...

thanks,
Wes
 
Wow, wish I could help you. I'm still running E2K7. Most likely upgrading 3rd Qtr.

Just reaching here.....are you secured through ISA? Checked the ISA logs?

Turn up Diag Logging on the Hub Transport server, check the app log. Check IIS logs.

One of these servers should turn up an error....hopefully.
 
nope no ISA... yeah I guess it's time to dig into the logs. yay :)

thanks for the help... by the way you will love 2010!
 
yeah, it's not ideal, but we have some pretty nice Juniper boxes sitting in front of everything and it's only port 443 :)

I am testing out forefront TMG and we may go that route in the near future...

I think I pinned the problem down to the switch from the Starfield root to Godaddy root... what threw me off was that the iphones can use OWA properly, even though it looks like i have some intermediate cert tweaking to do.

it would appear that apple somehow has the iphone set to read different cert stores for activesync than they do for safari!

it also shows that they have updated their root certs for OS 4...
 
turns out i had done the cert properly...

it finally dawned on me to check our DAG and see if a couple of databases had somehow failed over to the DR site - YEP! the reason my phone was working even though my colleague and I are on the same DB is that with OS 4, I have multiple exchange accounts configured so the couple that were working were on DBs that hadn't failed over :p
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.