Article ID: 915840 - Last Review: October 25, 2007 - Revision: 1.4 How to install root certificates on a Windows Mobile-based deviceOn This PageINTRODUCTIONThis article describes certificate stores and root certificates in Microsoft Windows Mobile 5.0 software for Pocket PCs. This article also describes how to install root certificates on a Windows Mobile-based device. MORE INFORMATIONCertificate storesCertificate stores contain the digital certificates of a mobile device. By default, Windows Mobile-based devices have the following set of certificate stores:
Microsoft Exchange ActiveSync is a program in Microsoft Exchange Server 2003 that is used to examine the root certificate store on a Windows Mobile-based device. Exchange ActiveSync is used to verify that the certificate on a server to which a Windows Mobile-based device connects is issued by a trusted authority. Root certificates that are installed on a Windows Mobile-based deviceThe following root certificates are installed on a Windows Mobile-based device:
http://www.valicert.com/
We recommend that you install a certificate that is issued by an authority that the device trusts. Alternatively, install a certificate that is issued by a company that is chained to an authority that the device trusts. Known third-party Secure Sockets Layer (SSL) certificates are issued by trusted root certification authorities that have a root store presence in Windows Mobile-based devices. Sometimes you may have to issue a self-signed certificate or to obtain a certificate from a certification authority that the device does not trust. In this case, Exchange ActiveSync cannot use SSL certificates unless the root certificate can be installed on the device. Whether a root certificate can be installed on the device depends on how the device was configured by the original equipment manufacturer (OEM) or by the mobile operator. How to install root certificatesOnly trusted processes can install certificates. On a two-tier device, only privileged applications can run trusted processes. Therefore, the device manager (the OEM or the mobile operator) must let you install a certificate. Alternatively, the device manager must sign the application with a certificate that is in the privileged execution certificate store on the device.When you are granted a device manager role on a Windows Mobile-based device, you can install a root certificate file by using the built-in certificate installer. To use the built-in certificate installer, follow these steps:
65416
(http://support.microsoft.com/kb/65416/
)
Hardware and software vendor contact information, A-K 60781 (http://support.microsoft.com/kb/60781/ ) Hardware and software vendor contact information, L-P 60782 (http://support.microsoft.com/kb/60782/ ) Hardware and software vendor contact information, Q-Z
| Article Translations
|

Back to the top

