Thursday, 29 November 2007

Direct Push on Windows Mobile using Self Signed SSL

I was just looking through some old notes on how to set up Windows Mobile Devices for Direct Push (Calendar, Tasks, Contacts and Email!!!) with a self signed SSL certificate (you can't just install the 64bit .cer file as it won't allow the file type). Anyway, thought I'd publish the solution here....

Note: this only works on Windows Mobile 5 and above - not WM 2003 :(

I'll assume here that people know how to create the SSL certificate (if not theres a good guide at http://www.petri.co.il/install_windows_server_2003_ca.htm)

Next download the SSLChainsaver tool to the root of your C: drive

http://blogs.msdn.com/windowsmobile/archive/2006/08/11/sslchainsaver.aspx

Follow the instructions on the page to pull a copy of the root and leaf certificates, then export the ROOT certificate in Base-64 encoded format.


Open the certificate from a command prompt using the line:

C:\Type rootcert.cer

Which will output the hash of the certificate, which will look like:

C:\>type rootcert.cer


-----BEGIN CERTIFICATE-----

MIIEYzCCA0ugAwIBAgIQG4HnhkoEsahFnmBPR65JWjANBgkqhkiG9w0BAQUFADA9
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
A1UEAxMHYmhzcnYwMjAeFw0wNTEwMDMxNzA3NTRaFw0xMDEwMDMxNzE1MjFaMD0x
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
VQQDEwdiaHNydjAyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GTQ

xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
N2RtoT4HcNUHYyDTlLrydD4tCOq21o4cNHRk67UsRGRHjZz/BI1YsdOXl1rakOva
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
COsC4ULQDytkuw9gCifqiCyxnT0k7+zkIgNxF4ncFdbnESLm3Bw2wCBz1G/MtUwY
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
2AiOz+jgGeYKv9jD8wIDAQABo4IBXTCCAVkwEwYJKwYBBAGCNxQCBAYeBABDAEEw
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
5a5dW4PRqcsXEAMtMIHyBgNVHR8EgeowgecwgeSggeGggd6GgatsZGFwOi8vL0NO
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
dmljZXMsQ049U2VydmljZXMsQ049Q29uZmlndXJhdGlvbixEQz1iaCxEQz1sb2Nh
bD9jZXJ0aWZpY2F0ZVJldm9jYXRpb25MaXN0P2Jhc2U/b2JqZWN0Q2xhc3M9Y1JM
RGlzdHJpYnV0aW9uUG9pbnSGLmh0dHA6Ly9iaHNydjAyLmJoLmxvY2FsL0NlcnRF

bnJvbGwvYmhzcnYwMi5jcmwwEAYJKwYBBAGCNxUBBAMCAQAwDQYJKoZIhvcNAQEF
BQADggEBAEGdXuUfA7kvCxLLOI+W3+Nbz7lENOZF59cNVaQJ5HwjIGtLhw2tv2c0
SibjlB68ecuyuD6K4gYLVlhZrLelDKqGYsV3uF+Q4293+t2S+D3cMXW/gPAYeBU2
Ld+P6dm4tjmzcSC/Xpi3mQpw8kQF93rEEkApbP4LOXh/X5LpyZ2iS15RTMMomxvL

xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
ILk4wkjERNGgRRl5eOF3QZ/hMWRu1UMb1C6mrcxs4pBW1qyOJQNJB+Y3eHuWCzfw
oZMi16R2/MCkY6xCqvDRj302UKLHUbU=

-----END CERTIFICATE-----

Create a new file in notepad using the following template and call it _setup.xml, then paste the cert above into the section as below.




Then open your root certificate, look at the thumbprint of the certificate and copy that into the characteristic type section (highlighted in red above, without the spaces). My Thumbprint looked like 963688b77d91307e0164661f9550e2a2

Finally, all you need to do is make the .xml file into a cab file for installation into the Windows Mobile Device using the command line makecab (which ships is %systemroot%\system32 with windows

Makecab _setup.xml rootcert.cab

Copy this to your Windows Mobile device with Activesync, then run.

You should now have an appropriate certificate to allow you to use Direct Push Email through Exchange Activesync…..

Hoorah!!

Wednesday, 28 November 2007

Business Contact Manager

Following on from the previous post....I had been unable to install Business Contact Manager for Outlook as a preinstalled option, and every time the user went into Outlook a nagging screen popped up to create a BCM database....

After much swearing as I repeatedly got the error "unable to complete the un/installation" - which was highly descriptive I found the following:

http://support.microsoft.com/kb/903094/en-us?spid=2520&sid=904

Although not strictly an uninstall, it would have done....

As a last ditch effort though I thought I'd log on as the original local account for the machine, attempted the uninstall and it worked straight away....

Grrr.....

I thought I'd start a new blog, as last years was pretty much all about travelling, and this is primarily going to be a resource for me to remember the things that I learn and to let off steam about all things technical.....

...what's prompted me to do this? well.....

Today the firm have bought a batch of PC's, a number of which are HP, and one is a rather sexy looking Sony Vaio notebook.... what's the problem? I hear you ask....well...

I'm seriously starting to despise the policies of hardware manufacturers.... if it's not bad enough that no serious players ship desktop machines with alternative OS's (apart from Dell, which I hope will start a trend), and even getting XP rather than Vista is a challenge now - the machines I have recently received have truly taken the piss though with literally hundreds of apps preinstalled....primarily Norton Internet Security and Microsoft Office "Free Trial".

If I want software installing on a machine, I'll fucking install it myself......having just spent HOURS removing bloatware from PC's in order to get them functional at all and being unable to reinstall the OS due to the lack of installation media that ships with them any more I'm thoroughly dejected - it's almost enough to make me boycott these vendors..... The recovery media includes a preinstall of all the shit I'm trying to get rid of, as I found out to my cost!

If only I could get past the training issues and software compatibility issues and get everyone on an open source OS i'd be happy....