Want to highlight a helpful answer? Upvote!

Did someone help you, or did an answer or User Tip resolve your issue? Upvote by selecting the upvote arrow. Your feedback helps others! Learn more about when to upvote >

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Identity Certificate not installing properly on OS 3.0

Having issues installing p12 identity certificate on OS 3.0. Same exact identity certificate installs fine on OS 2.2. I am also able to import the certificate using Firefox and Internet Explorer.

When installing the certificate on OS 3.0, the install seems to go through. But when I open the identity certificate under General>Profiles and look in More Details, the certificate is blank. Using the iPhone Configuration Utility to monitor the device console, I noticed the following error "Error (-25300) while trying to retrieve an identity certificate's details".

iPhone OS 3.0

Posted on Jun 18, 2009 8:21 AM

Reply
56 replies

Jun 19, 2009 5:14 AM in response to dosers

I figured this out last night, it appears apple changed the way the Certificates are done with Exchange. Download iPhone Configuration Utility 2.0, on the Exchange screen attach the cert. The cert then gets put in the Profiles as a Exchange Account. The same profile that would show no details previously now shows the details.

Very frustrating that Apple couldn't have a smoother migration for upgrade for Corporate customers. They treat corporate customers like retail users . . . the fact that enterprises can't test prior to the release of software is what prevents iPhone from replacing Blackberry in the enterprise.

Jun 19, 2009 9:20 AM in response to mpusateri

To be clear, one still cannot import a functional personal identity certificate even using the iPhone Configuration Utility 2.0 on the Credentials option for Configuration Profiles. You still get a blank certificate. You CAN install an Exchange Certificate using the utility under Credential Name, and this might work for those that terminate SSL on their Active Sync server; however, if you terminate your SSL on a F5 appliance, you can't authenticate since the cert imported with the utility isn't passed to the Exchange Web server in this configuration. We use client certificates for various authentication scenarios and iPhone 3.0 software breaks client certificates. I've tried every format that the iPhone supports and none of them result in a usable identity certificate. Our users are unable to upgrade to 3.0 until this is fixed.

Jun 19, 2009 1:08 PM in response to Corporate Guy

The domain/user/password fields will be blank if you use the certificate option at the bottom of the Exchange field using the configuration tool. You would need to have your exchange server setup to allow pure certificate authentication. Most people just use a cert for the SSL aspect of the authentication and still pass a user/domain/password to the Active Sync server. I suspect you used the configuration tool instead of simply importing the certificate via gmail or some such.

If we remove the requirement for a client certificate from our SSL proxy, the iPhone can log in and start doing email. The problem is with the individual certificate store on a 3G iphone upgraded to 3.0 I do not yet have a 3G-S phone or a first gen phone to test the same functionality.

Hopefully Apple will release a patch soon-ly.

Jun 23, 2009 2:39 AM in response to Sam777

I am new on this forum. I am curious to know if Apple is reading this support thread and will answer the certificate question.

I have checked with my company ISA server and obviously traces are showing that the user certificate is not sent from the iPhone to the ISA server therefore refusing the connection.

As mentionned in the top message of this discussion, the certificate that was working properly before the upgrade from 2.2.1 to 3.0 is not readable anymore when looking to detail window of the certificate. So the issue seems to be related to certificate attribute's content or missing attributes inside the certificate. I have tried to reload the certificate:

1/ using a pop email account, then the certifcate appeared as unsigned and with blank details (no issuer and no expiration date).

2/ using the iPhone configuration utility 2.0, then the certificate appeared as verified (and not unsigned as before) but with blank details.

- Is anyone know what are the changes that have occurred in the identity certificate management with version 3.0?

- Do you know about certificate that works for exchange synchronization with version 3.0?

Many thanks for your help.

Identity Certificate not installing properly on OS 3.0

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.