iOS 4 Mail and self-signed certificates

I connect to a mail server that has a self-signed certificate. Under previous versions of iOS, this meant that I would have to allow the server connection once after a phone restore or update; however under iOS 4.2.1, I have to allow the certificate every time I access mail after the phone has been idle for the 'lock' time.

Can I get iOS 4.2.1 to trust the self-signed certificate the mail server uses?

MacPro Quad Core, G4 1000bT, MacBookPro, mini server, Mac OS X (10.6.5), 10.6.5 Server on MacPro

Posted on Nov 23, 2010 2:59 AM

Reply
91 replies

Nov 24, 2010 1:47 PM in response to Syth

I'm having the same problem here with my company's self-signed mail server. No problems with my 3GS iPhone until yesterday's update to 4.2.1. Now, every time I send or receive mail after waking the phone I'm prompted to Accept, Cancel or Continue. Choosing Accept or Continue doesn't permanently change anything--the dialog appears the next time the phone is woken up for mail.

I just downloaded the iPhone Configuration Utility to see if there's a way to fix this.

-Terry

Nov 24, 2010 3:20 PM in response to terryb

I'm interested in hearing how it worked out.

Although, having to use the configuration utility is absolutely not a workaround for most people. 😟 I don't even think that I can use it, because there is no .csr file to import. I'm using Courier-IMAP and it has its own certificate generating tool - http://www.courier-mta.org/mkimapdcert.html

Nov 24, 2010 3:26 PM in response to Merged Content 1

I have tried to understand a bit more on this, installed iPhone Configuration Utility, but it seems a bit complex. I tried to create a profile, installed it, but it didn't seem to work. It probably didn't help that the email account I created through this was already set up on my phone, but still, it didn't actually seem to work anyway. If anything, it looks like it's corrupted the rest of the working accounts. By the look of it, I am now bound to having to delete all my accounts yet again and recreate them, for the third time in two days. Surely there should be some fix to this.

Nov 24, 2010 6:12 PM in response to Syth

Yup, I'd say iOS 4.2.1 broke SSL email usability in general (relative to iOS 4.1, in which it worked fine) . Apple should issue a more meaningful popup that allows you to do all the proper things related to Certificate Trust. Specifically, when any newly opened SSL connection has an invalid certificate the user should be presented with, at least

(1) Cancel this operation
(2) Continue this operation anyway for now, but do NOT save this exception (aka "trust this certificate for right now only")
(3) Continue this operation AND save this exception permanently (aka "trust this certificate until I say otherwise")

Additionally it probably makes sense for Apple to show:

(4) Show me more details about this certificate

In iOS 4.1 (and probably previous versions) Apple was showing #1, #4, and #3 (the popup showed "Cancel" "Details" and "Continue" respectively and in that order). With the release of iOS 4.2.1 Apple has swapped the middle option from #3 to #2, so even though it still says "Cancel" "Details" and "Continue," the option for "Continue" now does something less and different! To be fair, the message in the popup is and has always been more appropriate for option #2 since it doesn't explicitly say anything about saving the exception permanently, which fairly closely follows the paradigm just about every other comparable application uses (Firefox, Webkit, Mail.app, etc). In my opinion it was a bit of a security mistake previously since some poor users might just hit "continue" and not realize they've somewhat permanently exposed themselves (presumably until the untrusted certificate expires or changes).

Of course, option #3 also opens the door to the fact that there should be a way for users to remove/add/change trust for saved certificates, just like there is in OSX (you can get to saved certificates via the Keychain.app). Importantly this feature needs to exist on the phone, not as a separate application for corporate/enterprise IT people to manage profiles.

I also checked Mobile Safari and it seems to exhibit the same new (annoying) switch from option #3 to #2.

Multiple punctuation and minor grammatical fixes

Nov 25, 2010 6:38 AM in response to Peter Crocker

Peter, please read the entire thread. Others have tried that (in fact, there's an entire post about it!) and it has not resolved the issue. Please do not present that as a solution.

The iPhone Configuration Utility is not a feasible option for most end users anyway. It's also not possible with certain mail setups. (Courier is an example, and I have found it to be a pain on even Mac OS X Server, which lets you click a couple times and generate a self-signed certificate)

Apple needs to address this and soon. As another person mentioned, it's hosing mail, web, and iCal for people.

Nov 25, 2010 7:04 AM in response to Dr_Stein

Dr_Stein wrote:
No. The cert is not expired and has no other errors. ONLY "MobileMail" on iOS 4.2.1 is affected by this. Everything worked fine before the 4.2.1 update.

The exact error is: "Cannot verify server identity. MobileMail can't verify the identity of "my.mail.server". Would you like to continue anyway? Cancel/Details/Continue"


Weird that I'm using a self-signed cert and not seeing this error myself on three iP4s accessing my linux box. The name on my cert matches my email box domain name - I wonder if that matters or not.

Nov 25, 2010 8:57 AM in response to Dr_Stein

Dr_Stein, I'm sorry that the solution I presented didn't work for you. It did, however work for me, and it could work for others.

There are others reading the forums who can benefit from various approaches. Please consider being a little more considerate to those spending time to try and help. Don't take your frustration out on me.

I agree that the iPhone util isn't feasible for most people, hence why I said that in the first line of my post.

Another note (for those who do want to try using the iPhone util) is that you have to make sure you push the right SSL cert on to your iPhone. It must be the CA signing cert, not the actual SSL cert presented to the iPhone on SSL negotiation.

Nov 26, 2010 8:44 AM in response to Syth

OK, what is the best place to report this bug so we can get a critical mass of people to get it fixed???

It also seems to be causing the inadvertent effect of sending any reply email you are in the process of typing (when the dialog box pops up). My ISP uses a self signed certificate, and this is a huge headache.

Jeffrey

Nov 26, 2010 8:24 PM in response to Peter Crocker

We can skip the lecture on forum etiquette. I'm quite considerate, but I (along with others) are VERY disappointed in having an update that causes unexpected problems.

According to a couple iOS app developer friends, this behavior was NOT present in the developer builds.
Nobody seems to know when exactly it popped up and why. It's as if the "Accept" button that is displayed should permanently store the exception but just fails to do so.

Nov 27, 2010 9:34 AM in response to Dr_Stein

Dr_Stein wrote:
According to a couple iOS app developer friends, this behavior was NOT present in the developer builds.


It wasn't.

Nobody seems to know when exactly it popped up and why. It's as if the "Accept" button that is displayed should permanently store the exception but just fails to do so.


Seems like it appeared in the initial GM release.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

iOS 4 Mail and self-signed certificates

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.