<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-798194812750898417.post6883598550112875945..comments</id><updated>2011-08-11T08:27:43.489-07:00</updated><category term='SCOM'/><category term='clustering'/><category term='MCM'/><category term='High Availability'/><category term='SQL'/><category term='Outlook'/><category term='books'/><category term='IE9'/><category term='certifications'/><category term='Windows Server 2008'/><category term='Windows'/><category term='Windows7'/><category term='Apple'/><category term='OWA 2007'/><category term='Group Policy'/><category term='dogfood'/><category term='ASP.NET'/><category term='Lync Mobile'/><category term='troubleshooting'/><category term='Coupon'/><category term='Windows Server 2008 R2'/><category term='family'/><category term='archiving'/><category term='Beta'/><category term='Networking'/><category term='virtual'/><category term='WSUS'/><category term='performance'/><category term='Microsoft Exchange 2007'/><category term='8525'/><category term='VMM'/><category term='training'/><category term='Federation'/><category term='x64'/><category term='humor'/><category term='patch'/><category term='Office 365'/><category term='IPv6'/><category term='Edge'/><category term='certificates'/><category term='Lync'/><category term='64-bit'/><category term='VHD'/><category term='VDI'/><category term='Visio'/><category term='MVP'/><category term='SP1'/><category term='Hyper-V'/><category term='System Center'/><category term='cloud'/><category term='IIS'/><category term='Best Practices'/><category term='TechEd'/><category term='LDAP'/><category term='iPhone'/><category term='VMware'/><category term='IE8'/><category term='OWA 2010'/><category term='Outlook 2007'/><category term='ActiveSync'/><category term='Microsoft Exchange 2010'/><category term='Hacking'/><category term='Siri'/><category term='Core'/><category term='Vista'/><category term='Windows Mobile'/><category term='Twitter'/><category term='Microsoft'/><category term='Windows 8'/><category term='ImagineCup'/><category term='SCCM'/><category term='PaaS'/><category term='CCR'/><category term='Exchange'/><category term='contests'/><category term='Review'/><category term='SP3'/><category term='TEC'/><category term='Security'/><category term='PowerShell'/><category term='Blackberry'/><category term='ISA'/><category term='UM'/><category term='Terminal Services'/><category term='ADLDS'/><category term='Forefront'/><category term='Microsoft Exchange 2003'/><category term='Storage'/><category term='SP2'/><category term='scripts'/><category term='RDP'/><category term='s'/><category term='Commentary'/><category term='Windows 8 Server'/><category term='MOM'/><category term='VSS'/><category term='vacation'/><category term='Outlook 2010'/><category term='SharePoint'/><category term='Exchange Cached Mode'/><category term='Search'/><category term='Office 2010'/><category term='Registry'/><category term='RemoteFX'/><category term='tip'/><category term='OCS'/><category term='PKI'/><category term='Active Directory'/><category term='slideshow'/><category term='UC Roundtable'/><category term='Exchange 2010'/><category term='Time'/><category term='Disaster Recovery'/><category term='Lync Server'/><category term='printers'/><category term='utilities'/><title type='text'>Comments on The EXPTA {blog}: How to Securely Deploy iPhones with Exchange Activ...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.expta.com/feeds/6883598550112875945/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default'/><link rel='alternate' type='text/html' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/05278298222887921824</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://3.bp.blogspot.com/-mKrGWrtfsxg/TlZs-c7teRI/AAAAAAAAGYA/sL9yxhj7rIs/s220/Me_Cairo_MVP.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>20</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-798194812750898417.post-6468773720050250051</id><published>2011-08-10T22:42:05.239-07:00</published><updated>2011-08-10T22:42:05.239-07:00</updated><title type='text'>Hallo Jeff,

I just got over your tutorial while I...</title><content type='html'>Hallo Jeff,&lt;br /&gt;&lt;br /&gt;I just got over your tutorial while I was searching for a possibility to deploy user-certificates on our iPhone devices. I do not use certificate based ActiveSync in my Exchange 2010 though (not yet). But I some small questions, because I seem to misunderstand some points of your tutorial.&lt;br /&gt;&lt;br /&gt;1.) Every User requests his certificate himself at the ActiveDirectory CA, via CertSRV. After the Admin accepts this requests, the user can download his complete cert on his computer. &lt;br /&gt;From there he exports it completeley, with private key. Because the Public AND private key need to be imported in his iPhone profile. Correct?&lt;br /&gt;2.) I start the ICU with my administration user. Not with the user I&amp;#39;d like to set up? correct?&lt;br /&gt;3.) What do I have to do with the certificate for the admin user? &lt;br /&gt;&lt;br /&gt;Greetings&lt;br /&gt;Florian</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/6468773720050250051'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/6468773720050250051'/><link rel='alternate' type='text/html' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html?showComment=1313041325239#c6468773720050250051' title=''/><author><name>Mailer 2010</name><uri>http://www.blogger.com/profile/03649212425851015492</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html' ref='tag:blogger.com,1999:blog-798194812750898417.post-6883598550112875945' source='http://www.blogger.com/feeds/798194812750898417/posts/default/6883598550112875945' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1357587360'/></entry><entry><id>tag:blogger.com,1999:blog-798194812750898417.post-5109143437748398958</id><published>2011-08-08T10:37:28.013-07:00</published><updated>2011-08-08T10:37:28.013-07:00</updated><title type='text'>Hi Jeff,

Thanks a lot for such a great article.

...</title><content type='html'>Hi Jeff,&lt;br /&gt;&lt;br /&gt;Thanks a lot for such a great article.&lt;br /&gt;&lt;br /&gt;I have one question. Do you have any idea why iPCU supports only PKCS12 (and not a SCEP) for Exchange Certificate Based authentication?&lt;br /&gt;&lt;br /&gt;As I understand server side requires only certificate (public key). Private key can be on the iPhone and don&amp;#39;t need to be shared with any other parts of the system.&lt;br /&gt;&lt;br /&gt;Am I missing something?&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;Victor</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/5109143437748398958'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/5109143437748398958'/><link rel='alternate' type='text/html' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html?showComment=1312825048013#c5109143437748398958' title=''/><author><name>Victor Ronin</name><uri>http://www.blogger.com/profile/17803905608925273841</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html' ref='tag:blogger.com,1999:blog-798194812750898417.post-6883598550112875945' source='http://www.blogger.com/feeds/798194812750898417/posts/default/6883598550112875945' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1784646960'/></entry><entry><id>tag:blogger.com,1999:blog-798194812750898417.post-3471614034572382225</id><published>2011-06-07T14:56:11.989-07:00</published><updated>2011-06-07T14:56:11.989-07:00</updated><title type='text'>Awesome post!
A couple of people memtioned not bei...</title><content type='html'>Awesome post!&lt;br /&gt;A couple of people memtioned not being able to import the certificate into the ICU - getting the Certificate Exception error. I got this tto, despite having the full cert chain imported. I got around it be re-importing the certificate, but this time I checked the &amp;quot;Mark this key as exportable...&amp;quot; box during the import. That seemed to do the trick.&lt;br /&gt;&lt;br /&gt;Also, my Cert Authority didn&amp;#39;t allow me to enter the username etc for a user cert (even when going through the Advanced cert request). Instead it would enroll in the currently logged on uesers name, so I created a duplicate of the User cert, set the details in the Subject Name tab to &amp;quot;Supply in the Request&amp;quot;. Ensure the Issuance Requirements tab has &amp;quot;CA certificate Manager approval&amp;quot; checked, and things should be all-good.&lt;br /&gt;Cheers&lt;br /&gt;Robert</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/3471614034572382225'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/3471614034572382225'/><link rel='alternate' type='text/html' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html?showComment=1307483771989#c3471614034572382225' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html' ref='tag:blogger.com,1999:blog-798194812750898417.post-6883598550112875945' source='http://www.blogger.com/feeds/798194812750898417/posts/default/6883598550112875945' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-277640691'/></entry><entry><id>tag:blogger.com,1999:blog-798194812750898417.post-8748725262571962258</id><published>2011-05-11T13:39:09.416-07:00</published><updated>2011-05-11T13:39:09.416-07:00</updated><title type='text'>Yes, you can.  It will work fine on multiple devic...</title><content type='html'>Yes, you can.  It will work fine on multiple devices.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/8748725262571962258'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/8748725262571962258'/><link rel='alternate' type='text/html' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html?showComment=1305146349416#c8748725262571962258' title=''/><author><name>Jeff</name><uri>http://www.blogger.com/profile/05278298222887921824</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://3.bp.blogspot.com/_IsItvsG4t0k/TC0CSUx6E6I/AAAAAAAAFz0/TgGZrlTq7zM/S220/MVP+Paris.png'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html' ref='tag:blogger.com,1999:blog-798194812750898417.post-6883598550112875945' source='http://www.blogger.com/feeds/798194812750898417/posts/default/6883598550112875945' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-566670614'/></entry><entry><id>tag:blogger.com,1999:blog-798194812750898417.post-1708850297305758859</id><published>2011-05-11T10:10:22.533-07:00</published><updated>2011-05-11T10:10:22.533-07:00</updated><title type='text'>Hi Jeff,
what if the user has multiple devices (ip...</title><content type='html'>Hi Jeff,&lt;br /&gt;what if the user has multiple devices (iphone + ipad) but only one login to Exchange? I can&amp;#39;t use the same ACtivesync profile can I?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/1708850297305758859'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/1708850297305758859'/><link rel='alternate' type='text/html' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html?showComment=1305133822533#c1708850297305758859' title=''/><author><name>Kenara</name><uri>http://www.blogger.com/profile/17115412858883562110</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html' ref='tag:blogger.com,1999:blog-798194812750898417.post-6883598550112875945' source='http://www.blogger.com/feeds/798194812750898417/posts/default/6883598550112875945' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-722122693'/></entry><entry><id>tag:blogger.com,1999:blog-798194812750898417.post-3648531370770630135</id><published>2010-11-09T03:37:54.251-08:00</published><updated>2010-11-09T03:37:54.251-08:00</updated><title type='text'>Hi Jeff, thanks for the reply, It&amp;#39;s working no...</title><content type='html'>Hi Jeff, thanks for the reply, It&amp;#39;s working now. (I&amp;#39;m sure I did reply before and said thanks.)&lt;br /&gt;&lt;br /&gt;I have a follow-up question, I tried to install the ActiveSync profile (username.mobileconfig) in my iPAD using iCU and email attachment but I got the following message:&lt;br /&gt;&lt;br /&gt;An error occured while contacting server&lt;br /&gt;Without verifying the account, no information will be downloaded when the installation finishes.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;In my iPhone, I can install the ActiveSync profile using the iCU, but when I try to load the EAS mail client, I got the following error message:&lt;br /&gt;&lt;br /&gt;&amp;#39;Cannot connect to mail server&amp;#39;.&lt;br /&gt;&lt;br /&gt;I don&amp;#39;t have any problem if I configure the EAS Mail client manually, except that I have problems sending/forwarding email with attachment &amp;gt;100kb.&lt;br /&gt;&lt;br /&gt;We are using Exchange 2007 SP1 with TMG 2010 SP1 in the DMZ.&lt;br /&gt;&lt;br /&gt;I&amp;#39;m wondering if this is an Apple bug or Microsoft, or something wrong in our configuration.&lt;br /&gt;&lt;br /&gt;BTW, I&amp;#39;m having a problem publishing the EAS website externally. I haven&amp;#39;t tried it in our office WiFi, since I worked remotely.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/3648531370770630135'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/3648531370770630135'/><link rel='alternate' type='text/html' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html?showComment=1289302674251#c3648531370770630135' title=''/><author><name>Bobby</name><uri>http://www.blogger.com/profile/04415901344355498835</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html' ref='tag:blogger.com,1999:blog-798194812750898417.post-6883598550112875945' source='http://www.blogger.com/feeds/798194812750898417/posts/default/6883598550112875945' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1596683255'/></entry><entry><id>tag:blogger.com,1999:blog-798194812750898417.post-6245024666758388464</id><published>2010-10-19T17:41:09.844-07:00</published><updated>2010-10-19T17:41:09.844-07:00</updated><title type='text'>Hi Bobby,

It sounds like you don&amp;#39;t have the e...</title><content type='html'>Hi Bobby,&lt;br /&gt;&lt;br /&gt;It sounds like you don&amp;#39;t have the entore certificate chain installed on your home PC. You either need to do one of the following:&lt;br /&gt;&lt;br /&gt;1. Import the root CA&amp;#39;s cert into the computer&amp;#39;s Trusted Root Certification Authorities.&lt;br /&gt;&lt;br /&gt;2. Export the user cert and private key again, this time selecting the &amp;quot;Include all certificates in the certification path if possible&amp;quot; checkbox.&lt;br /&gt;&lt;br /&gt;When you view the Certificate Path of the user cert you should see both the user cert and the root CA&amp;#39;s cert with no red X&amp;#39;s.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/6245024666758388464'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/6245024666758388464'/><link rel='alternate' type='text/html' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html?showComment=1287535269844#c6245024666758388464' title=''/><author><name>Jeff</name><uri>http://www.blogger.com/profile/05278298222887921824</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://3.bp.blogspot.com/_IsItvsG4t0k/TC0CSUx6E6I/AAAAAAAAFz0/TgGZrlTq7zM/S220/MVP+Paris.png'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html' ref='tag:blogger.com,1999:blog-798194812750898417.post-6883598550112875945' source='http://www.blogger.com/feeds/798194812750898417/posts/default/6883598550112875945' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-566670614'/></entry><entry><id>tag:blogger.com,1999:blog-798194812750898417.post-3689511100288051458</id><published>2010-10-19T17:31:22.839-07:00</published><updated>2010-10-19T17:31:22.839-07:00</updated><title type='text'>Hi Jeff,

I do have the same issue as Mark, where ...</title><content type='html'>Hi Jeff,&lt;br /&gt;&lt;br /&gt;I do have the same issue as Mark, where I try to setup my home PC with iCU,when I try to add the user certificate to the ActiveSync profile it displayed an error &amp;quot;certificate exception: key not valid for use in specified state&amp;quot;, that is, after I enter and verified the password of the user certificate.&lt;br /&gt;My home PC has Windows 7. I also tried it in my other PC which running XP SP3, which generates the same error message.&lt;br /&gt;&lt;br /&gt;I tried to run it in my office desktop which is a part of the AD domain, and it works fine. My home PC&amp;#39;s are all standalone/workgroup. Does Domain memebership matters? I assume it doesn&amp;#39;t.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/3689511100288051458'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/3689511100288051458'/><link rel='alternate' type='text/html' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html?showComment=1287534682839#c3689511100288051458' title=''/><author><name>Bobby</name><uri>http://www.blogger.com/profile/04415901344355498835</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html' ref='tag:blogger.com,1999:blog-798194812750898417.post-6883598550112875945' source='http://www.blogger.com/feeds/798194812750898417/posts/default/6883598550112875945' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1596683255'/></entry><entry><id>tag:blogger.com,1999:blog-798194812750898417.post-5923694076724757793</id><published>2010-09-10T13:03:28.106-07:00</published><updated>2010-09-10T13:03:28.106-07:00</updated><title type='text'>Jeff,
   Thank You that worked. I would have never...</title><content type='html'>Jeff,&lt;br /&gt;   Thank You that worked. I would have never figured that out</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/5923694076724757793'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/5923694076724757793'/><link rel='alternate' type='text/html' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html?showComment=1284149008106#c5923694076724757793' title=''/><author><name>Sean</name><uri>http://www.blogger.com/profile/05934816167821005239</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html' ref='tag:blogger.com,1999:blog-798194812750898417.post-6883598550112875945' source='http://www.blogger.com/feeds/798194812750898417/posts/default/6883598550112875945' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-2002290886'/></entry><entry><id>tag:blogger.com,1999:blog-798194812750898417.post-4542813306105001436</id><published>2010-09-10T12:26:56.310-07:00</published><updated>2010-09-10T12:26:56.310-07:00</updated><title type='text'>Hi Sean,

I had the same issue with the latest ver...</title><content type='html'>Hi Sean,&lt;br /&gt;&lt;br /&gt;I had the same issue with the latest version of iCU, and it appears to be a bug.  If I copied the profile I just created, I was able to enable it on the copy.  Then I deleted the first one I created.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/4542813306105001436'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/4542813306105001436'/><link rel='alternate' type='text/html' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html?showComment=1284146816310#c4542813306105001436' title=''/><author><name>Jeff</name><uri>http://www.blogger.com/profile/05278298222887921824</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://3.bp.blogspot.com/_IsItvsG4t0k/TC0CSUx6E6I/AAAAAAAAFz0/TgGZrlTq7zM/S220/MVP+Paris.png'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html' ref='tag:blogger.com,1999:blog-798194812750898417.post-6883598550112875945' source='http://www.blogger.com/feeds/798194812750898417/posts/default/6883598550112875945' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-566670614'/></entry><entry><id>tag:blogger.com,1999:blog-798194812750898417.post-1467053225838951397</id><published>2010-09-10T12:22:39.707-07:00</published><updated>2010-09-10T12:22:39.707-07:00</updated><title type='text'>For some reason when I build the ActiveSync Profil...</title><content type='html'>For some reason when I build the ActiveSync Profile, I cannot select the Include Authentication Credential Passphrase option. It is greyed out. Everything works fine up until that point. Can you tell me why I am having this issue.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/1467053225838951397'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/1467053225838951397'/><link rel='alternate' type='text/html' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html?showComment=1284146559707#c1467053225838951397' title=''/><author><name>Sean</name><uri>http://www.blogger.com/profile/05934816167821005239</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html' ref='tag:blogger.com,1999:blog-798194812750898417.post-6883598550112875945' source='http://www.blogger.com/feeds/798194812750898417/posts/default/6883598550112875945' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-2002290886'/></entry><entry><id>tag:blogger.com,1999:blog-798194812750898417.post-4221169392814647642</id><published>2010-06-30T14:08:58.104-07:00</published><updated>2010-06-30T14:08:58.104-07:00</updated><title type='text'>NICE work, Sysadminlab.net!  Thanks for sharing th...</title><content type='html'>NICE work, Sysadminlab.net!  Thanks for sharing this.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/4221169392814647642'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/4221169392814647642'/><link rel='alternate' type='text/html' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html?showComment=1277932138104#c4221169392814647642' title=''/><author><name>Jeff</name><uri>http://www.blogger.com/profile/05278298222887921824</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://3.bp.blogspot.com/_IsItvsG4t0k/S2oNugXwflI/AAAAAAAAEHA/hHiQ9uJhFmc/S220/Jeff+Guillet.png'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html' ref='tag:blogger.com,1999:blog-798194812750898417.post-6883598550112875945' source='http://www.blogger.com/feeds/798194812750898417/posts/default/6883598550112875945' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-566670614'/></entry><entry><id>tag:blogger.com,1999:blog-798194812750898417.post-8085384424350302067</id><published>2010-06-30T14:07:12.310-07:00</published><updated>2010-06-30T14:07:12.310-07:00</updated><title type='text'>Now when iPhone 4.0 has been released I tested all...</title><content type='html'>Now when iPhone 4.0 has been released I tested all the ActiveSync policies to see which ones that worked. Here&amp;#39;s a summary: http://www.sysadminlab.net/activesync/iphone-os-4-and-exchange-activesync-policies-what-really-works</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/8085384424350302067'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/8085384424350302067'/><link rel='alternate' type='text/html' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html?showComment=1277932032310#c8085384424350302067' title=''/><author><name>Sysadminlab.net</name><uri>http://www.sysadminlab.net</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html' ref='tag:blogger.com,1999:blog-798194812750898417.post-6883598550112875945' source='http://www.blogger.com/feeds/798194812750898417/posts/default/6883598550112875945' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-583340548'/></entry><entry><id>tag:blogger.com,1999:blog-798194812750898417.post-4993721565058570386</id><published>2010-06-18T09:36:19.662-07:00</published><updated>2010-06-18T09:36:19.662-07:00</updated><title type='text'>Hi Mark,

It sounds like you don&amp;#39;t have the pr...</title><content type='html'>Hi Mark,&lt;br /&gt;&lt;br /&gt;It sounds like you don&amp;#39;t have the private key installed for the user on the second desktop.  Try exporting the user cert and private key again from the first desktop to a PFX file and reimporting it on the second desktop.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/4993721565058570386'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/4993721565058570386'/><link rel='alternate' type='text/html' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html?showComment=1276878979662#c4993721565058570386' title=''/><author><name>Jeff</name><uri>http://www.blogger.com/profile/05278298222887921824</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://3.bp.blogspot.com/_IsItvsG4t0k/S2oNugXwflI/AAAAAAAAEHA/hHiQ9uJhFmc/S220/Jeff+Guillet.png'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html' ref='tag:blogger.com,1999:blog-798194812750898417.post-6883598550112875945' source='http://www.blogger.com/feeds/798194812750898417/posts/default/6883598550112875945' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-566670614'/></entry><entry><id>tag:blogger.com,1999:blog-798194812750898417.post-4383511000731380380</id><published>2010-06-17T22:33:23.311-07:00</published><updated>2010-06-17T22:33:23.311-07:00</updated><title type='text'>Jeff,

I have an issue where I set up a second des...</title><content type='html'>Jeff,&lt;br /&gt;&lt;br /&gt;I have an issue where I set up a second desktop in a remote location (so iphone can be provisioned there) and when I go to add the cert to the activeSync mobile profile it generates an error &amp;quot;certificate exception: key not valid for use in specified state&amp;quot;&lt;br /&gt;&lt;br /&gt;I generate the same config on mine here and it works fine (although I dont have the device here)  - same cert&lt;br /&gt;&lt;br /&gt;Any ideas????</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/4383511000731380380'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/4383511000731380380'/><link rel='alternate' type='text/html' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html?showComment=1276839203311#c4383511000731380380' title=''/><author><name>Mark</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html' ref='tag:blogger.com,1999:blog-798194812750898417.post-6883598550112875945' source='http://www.blogger.com/feeds/798194812750898417/posts/default/6883598550112875945' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1435883919'/></entry><entry><id>tag:blogger.com,1999:blog-798194812750898417.post-4760276004394428301</id><published>2010-05-11T12:19:47.006-07:00</published><updated>2010-05-11T12:19:47.006-07:00</updated><title type='text'>Right now, just in the iPhone configuration profil...</title><content type='html'>Right now, just in the iPhone configuration profile.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/4760276004394428301'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/4760276004394428301'/><link rel='alternate' type='text/html' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html?showComment=1273605587006#c4760276004394428301' title=''/><author><name>Kevin Westby</name><uri>http://www.blogger.com/profile/18366574010554845061</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://3.bp.blogspot.com/_icGKSObIz_E/SfCxiBWkWNI/AAAAAAAABUA/QU7wFxxUk_c/S220/St.Lucia.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html' ref='tag:blogger.com,1999:blog-798194812750898417.post-6883598550112875945' source='http://www.blogger.com/feeds/798194812750898417/posts/default/6883598550112875945' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-2058018475'/></entry><entry><id>tag:blogger.com,1999:blog-798194812750898417.post-2828350010053866600</id><published>2010-05-11T11:03:24.129-07:00</published><updated>2010-05-11T11:03:24.129-07:00</updated><title type='text'>Kevin, are you configuring the setting in an iPhon...</title><content type='html'>Kevin, are you configuring the setting in an iPhone configuration profile or using an EAS policy?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/2828350010053866600'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/2828350010053866600'/><link rel='alternate' type='text/html' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html?showComment=1273601004129#c2828350010053866600' title=''/><author><name>Jeff</name><uri>http://www.blogger.com/profile/05278298222887921824</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://3.bp.blogspot.com/_IsItvsG4t0k/S2oNugXwflI/AAAAAAAAEHA/hHiQ9uJhFmc/S220/Jeff+Guillet.png'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html' ref='tag:blogger.com,1999:blog-798194812750898417.post-6883598550112875945' source='http://www.blogger.com/feeds/798194812750898417/posts/default/6883598550112875945' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-566670614'/></entry><entry><id>tag:blogger.com,1999:blog-798194812750898417.post-3282965370726605583</id><published>2010-05-11T10:59:41.316-07:00</published><updated>2010-05-11T10:59:41.316-07:00</updated><title type='text'>When applying a baseline profile on the iPhone tha...</title><content type='html'>When applying a baseline profile on the iPhone that is intended to restrict the passcode timeout to 1 hour, it doesn&amp;#39;t appear to limit it to the 1 hour setting.  After installing the profile, I can still set the timeout value to 4 hours.  Is there a way to restrict that, or am I missing something?&lt;br /&gt;&lt;br /&gt;BTW: this article series is great, very helpful!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/3282965370726605583'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/3282965370726605583'/><link rel='alternate' type='text/html' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html?showComment=1273600781316#c3282965370726605583' title=''/><author><name>Kevin Westby</name><uri>http://www.blogger.com/profile/18366574010554845061</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://3.bp.blogspot.com/_icGKSObIz_E/SfCxiBWkWNI/AAAAAAAABUA/QU7wFxxUk_c/S220/St.Lucia.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html' ref='tag:blogger.com,1999:blog-798194812750898417.post-6883598550112875945' source='http://www.blogger.com/feeds/798194812750898417/posts/default/6883598550112875945' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-2058018475'/></entry><entry><id>tag:blogger.com,1999:blog-798194812750898417.post-1697715704007625480</id><published>2010-03-02T15:22:39.951-08:00</published><updated>2010-03-02T15:22:39.951-08:00</updated><title type='text'>This solution only requires the user to enter thei...</title><content type='html'>This solution only requires the user to enter their Active Directory password once, when installing the iPhone profile.  The user will NEVER need to know or enter the certificate password. ActiveSync will never lock the user out.&lt;br /&gt;&lt;br /&gt;BTW, Exchange ActiveSync clients cannot handle password expiration notification messages. Additionally, you cannot change an expired password by using an Exchange ActiveSync client.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/1697715704007625480'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/1697715704007625480'/><link rel='alternate' type='text/html' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html?showComment=1267572159951#c1697715704007625480' title=''/><author><name>Jeff</name><uri>http://www.blogger.com/profile/05278298222887921824</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://3.bp.blogspot.com/_IsItvsG4t0k/S2oNugXwflI/AAAAAAAAEHA/hHiQ9uJhFmc/S220/Jeff+Guillet.png'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html' ref='tag:blogger.com,1999:blog-798194812750898417.post-6883598550112875945' source='http://www.blogger.com/feeds/798194812750898417/posts/default/6883598550112875945' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-566670614'/></entry><entry><id>tag:blogger.com,1999:blog-798194812750898417.post-3700535982556257618</id><published>2010-03-02T15:15:01.563-08:00</published><updated>2010-03-02T15:15:01.563-08:00</updated><title type='text'>Hi,


I was hoping to see how to configure iPhone ...</title><content type='html'>Hi,&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I was hoping to see how to configure iPhone and certificates on the device so that user doesn&amp;#39;t have to enter their AD username and password to sync with Exchange. The challenge we have is that company policy dictates password to be changed every 60 days, and if the iPhone uses UN/Pass credentials to get to Exchange it will lock the account out (unless user remembers to change his AD password in iPhone as well, which we all know is not something we should rely on).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Thanks</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/3700535982556257618'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/798194812750898417/6883598550112875945/comments/default/3700535982556257618'/><link rel='alternate' type='text/html' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html?showComment=1267571701563#c3700535982556257618' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.expta.com/2010/03/how-to-securely-deploy-iphones-with_01.html' ref='tag:blogger.com,1999:blog-798194812750898417.post-6883598550112875945' source='http://www.blogger.com/feeds/798194812750898417/posts/default/6883598550112875945' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-895281832'/></entry></feed>
