Ask a questionAsk a question
 

Answerproblems connecting after enrollment

  • Tuesday, October 06, 2009 12:23 PMjbuszard Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     

    in our org we are running MDMSP1 and have recently enrolled a large number of devices - the majority of which appear to be working fine.
    however there are some that have successfully enrolled OK but then are unable to connect.
    using the VPN diagnostic tool on the device it comes up with the reason as 'Root certificate does not exist'
    i'm happy the connection works OK as its the same connection settings as other devices and i've tried re-adding those but to no avail.

    anyone have any ideas what would cause this?

Answers

  • Thursday, October 29, 2009 9:27 AMjbuszard Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     Answer
    HI Wayne

    no we don't seem to be getting this issue anymore, i found that if i re-installed KB951840 manually onto those devices it appeared to work, as our devices are provided to us by our mobile operator with a custom build on them we took it as they had missed the patch on a few of them.

    thanks for you help.

    regards

    Justin
    • Marked As Answer byjbuszard Thursday, October 29, 2009 9:27 AM
    •  

All Replies

  • Tuesday, October 06, 2009 10:16 PMWayne Phillips.MVP, ModeratorUsers MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     

    I'm glad to see the majority of devices are working well. Did you deploy the same make and model of devices or is there a mix of device types?
    Have you tried hard resetting one of these devices and re-enrolling. My initial thought are native security settings on the device, hardware failure (Bad batch) or just one of those things that keeps us honest.

    Cheers Wayne
    Airloom

  • Wednesday, October 07, 2009 4:26 AMMarco NielsenAnswererUsers MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     Proposed Answer
    Hi, Depending on the Windows Mobile Build level you are using and if you are using a Windows 2008 CA, I have seen this error message appear before. :-)

    Please see my previous posting on the necessary patches on downlevel WM 6.1 clients to support a Windows 2008 CA here:
    http://myitforum.com/cs2/blogs/mnielsen/archive/2009/06/05/scmdm-2008-sp1-support-for-windows-2008-ca.aspx

    Specifically it is the client/device side of this patch: http://support.microsoft.com/kb/951840/

    Hope this helps!

    |\\arco..
  • Thursday, October 08, 2009 1:36 PMjbuszard Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     
    hi guys thanks for the reply's.

    the devices used are all the same - HTC P6500 and a hard reset and new enrollment does appear to resolve the issue but was looking to fix issue by troubleshooting rather than hard reset.

    with regards to the windows KB951840 patch - this patch was installed on all our devices prior to MDM enrollment.

    cheers

    Justin
  • Friday, October 09, 2009 10:32 AMnowiresmatt Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     
    Gudday Justin,

    We had this problem on HTC TYTN II devices however the KB951840 patch from MS would not work on our 6.1 ROM version.  We had to get a hotfix to the hotfix.  Check with MS on your ROM version.

    The patch must be installed prior to MDM enrollment .... as you have noted.

    I'll check the version of the patch we have on Monday and post for you.

    Cheers

    MAtthew
  • Wednesday, October 28, 2009 12:15 AMWayne Phillips.MVP, ModeratorUsers MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     
    Justin,

    Are you still having issues?

    Cheers Wayne
    Airloom
  • Thursday, October 29, 2009 9:27 AMjbuszard Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     Answer
    HI Wayne

    no we don't seem to be getting this issue anymore, i found that if i re-installed KB951840 manually onto those devices it appeared to work, as our devices are provided to us by our mobile operator with a custom build on them we took it as they had missed the patch on a few of them.

    thanks for you help.

    regards

    Justin
    • Marked As Answer byjbuszard Thursday, October 29, 2009 9:27 AM
    •