iOS 4 Mail and self-signed certificates

I connect to a mail server that has a self-signed certificate. Under previous versions of iOS, this meant that I would have to allow the server connection once after a phone restore or update; however under iOS 4.2.1, I have to allow the certificate every time I access mail after the phone has been idle for the 'lock' time.

Can I get iOS 4.2.1 to trust the self-signed certificate the mail server uses?

MacPro Quad Core, G4 1000bT, MacBookPro, mini server, Mac OS X (10.6.5), 10.6.5 Server on MacPro

Posted on Nov 23, 2010 2:59 AM

Reply
91 replies

Dec 7, 2010 10:14 AM in response to dsuchter

The only thing I see in this forum, is the lack of support from apple.

Apple released a big update and disastrous.

They have more problems than improvements.

MobileMail has many problems, not only with the certificates, in some users (like me) can not send mail if the port is 25 and using 3G.

Lot of users have problems with data transfer is cut off or they run slow.

There are comparative and videos everywhere.

Apple does not say anything!

too swindled us with a phone that has manufacturing defects, poor quality antenna and sensor problems that to this day have not been solved well.

Should be more careful, I think that users are not that dumb. We will not always be buying everything that apple makes.

Apple is forgetting who gave them to eat and begins to perform worse than microsoft to their consumers.

Dec 12, 2010 7:54 AM in response to jemenake0

I just tried substituting the ip address for the name of the server for an imap certificate.

Used (from the terminal):
nslookup imap.myserver.com

to find the actual ip address

Typed it in where the name was and then accepted the non-trusted certificate inside the "Detail" dialog box (as someone described above). It didn't work UNTIL I rebooted the iphone. I had tried changing the port number, but that was to no avail. Also emailing the pef form of the certificates didn't wok (you can get them by using Firefox 4 to go the server site and exporting the non-trusted certificates).

This is a huge issue as you can't even access your phone without dismissing the dialog box, which is presented multiple times, every time you wake the phone (lots of fun when you need to make a call while driving)

I'll post if for some reason it stops working,

Jan 6, 2011 7:41 PM in response to Syth

Hey everyone.

Here's the scoop....

This update requires that you keep "Use SSL" connected, no matter what.

Most of us are either resellers or on a reseller account, so the SSL is set up with the company that owns the server.

You can easily access the smtp information (for using an SSL) from your server through CPanel, or by contacting your host.

Once I changed the SMTP, everything worked perfectly.

My solution:
Original SMTP - mail.mydomainname.com
New SMTP - cs26.servercompany.net

Hope this helps everyone out.

Feb 6, 2011 1:32 PM in response to JakRen

Here's what I did to fix my repeated errors:

Load up Keychain Access on your Mac, choose "Certificates" from the Category panel.
Find the certificate for your mail server in the list, and double click it.
In the information window that should open, Option/Alt-drag the certificate image from the top-left corner into a new message in Mail. You'll know it's done it right if you have a .PEM attachment, not a .CER one.
Send that email to yourself.

Now, on the iOS device, open the email and tap on the certificate. It should take you into Settings and allow you to install the certificate.

On my iPhone, this worked fine, but not on my iPad! You can check if it's trusted by going into Settings, General, Profiles.

Edit: Ah ha, make sure it's the one from the system keychain, not the login one!

Message was edited by: Drarok

Feb 7, 2011 10:35 PM in response to mflocks

Dear mflocks:

First, you "sound" like you are an Apple employee. Whether you actually are or not is irrelevant.

However, the tone in your comment (e.g., "xxx has been elevated to Apple Engineering . . .") is dismissive and has tones of...unfortunately arrogance.

I'm a end-user who uses PKI issued soft certificates AND who wants to migrate from my Blackberry to an iPhone. Frankly, I acknowledge and credit Apple with developing an innovative product.

However, on the other side, telling users that "ABC has been elevated to Apple engineering..." and "DEF has been elevated to Apple Engineering" is just quite frankly arrogant.

Maybe you ...or others in Apple should have considered and included in the "systems engineering concept, design, engineering, implementation and 'test and evaluation' as well as 'validation' components" of the iPhone development?

If you still retain your ..quite frankly 'cocky attitude' maybe the fact that there are xxx of Blackberry users...who represent a potential market could or should persude you and Apple to have a more "consilitary, amicable attitude"? What would that attitude, tone or gesture hurt ...other than a smile on your face?

References:

1. "Blackberry has a 55 percent market share in North America"
http://us.blackberry.com/developers/whyblackberry.jsp

2. Blackberry still boss in smartphone users
http://www.bizjournals.com/washington/stories/2010/03/08/daily60.html

Feb 25, 2011 7:13 PM in response to Drarok

Drarok, you're a genius! This totally fixed the problem for me. It was driving me nuts 🙂

I've written up your procedure in a bit more detail, including how to ensure you export a .pem file instead of a .cer file:

http://mac.elated.com/2011/02/26/how-to-fix-ios-mail-cannot-verify-server-identi ty-error-with-self-signed-certificates/

Thanks man!

Mar 13, 2011 2:25 PM in response to VW Web Design

This worked for me.

I use siteground for my hosting. in cPanelx > Email Accounts > Configure Email Client > Manual Settings

there are different settings for:

Mail Server Username: +.org
Incoming Mail Server: ..org
Incoming Mail Server: (SSL) x.y.com
Outgoing Mail Server: ..org (server requires authentication) port 2525
Outgoing Mail Server: (SSL) x.y.com (server requires authentication) port 465

I did not have the SSL settings in place.

I'm not saying that my mistake is what is troubling others; I'm only saying that this was what was troubling me. Thanks to the previous respondant.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

iOS 4 Mail and self-signed certificates

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.