Configuring Activesync in Exchange 2003 (SBS)
Hi,
I am having difficulty to configure exchange 2003 (ON a SBS server) for Activesync. My requirement is to synchronise exchange emails and contact with iphones.
I installed godaddy certificate in the IIS default website and OWA works fine.
I followed your site instructions which is similar to MS article ID 817379.
When I tried to sync iphone, it says user authentication failed. I tested it with Exchange Remote Connectivity analyzer and got following result.
Testing Exchange ActiveSync
Exchange ActiveSync test Failed
Test Steps
Attempting to resolve the host name mail.cygresearch.com in DNS.
Host successfully resolved
Additional Details
IP(s) returned: 24.215.43.226Testing TCP Port 443 on host mail.cygresearch.com to ensure it is listening and open.
The port was opened successfully.
Testing SSL Certificate for validity.
The certificate passed all validation requirements.
Test Steps
Validating certificate name
Successfully validated the certificate name
Additional Details
Found hostname mail.cygresearch.com in Certificate Subject Common nameValidating certificate trust for Windows Mobile Devices
The test passed with some warnings encountered. Please expand additional details.
Additional Details
Certificate is only trusted on Windows Mobile 6.0 and later. Windows Mobile 5.0 and 5.0 + MSFP devices will not be able to sync. Root = OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USTesting certificate date to ensure validity
Date Validation passed. The certificate is not expired.
Additional Details
Certificate is valid: NotBefore = 10/26/2009 1:00:08 PM, NotAfter = 10/26/2012 1:00:08 PM"Testing Http Authentication Methods for URL https://mail.cygresearch.com/Microso...er-Activesync/
Http Authentication Test failed
Additional Details
An HTTP 403 forbidden response was received. The response appears to have come from IIS6. Body is: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>You are not authorized to view this page</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; charset=Windows-1252">
<STYLE type="text/css">
BODY { font: 8pt/12pt verdana }
H1 { font: 13pt/15pt verdana }
H2 { font: 8pt/12pt verdana }
A:link { color: red }
A:visited { color: maroon }
</STYLE>
</HEAD><BODY><TABLE width=500 border=0 cellspacing=10><TR><TD><h1>You are not authorized to view this page</h1>
The Web server you are attempting to reach has a list of IP addresses that are not allowed to access the Web site, and the IP address of your browsing computer is on this list.
<hr>
<p>Please try the following:</p>
<ul>
<li>Contact the Web site administrator if you believe you should be able to view this directory or page.</li>
</ul>
<h2>HTTP Error 403.6 - Forbidden: IP address of the client has been rejected.<br>Internet Information Services (IIS)</h2>
<hr>
<p>Technical Information (for support personnel)</p>
<ul>
<li>Go to <a href="http://go.microsoft.com/fwlink/?linkid=8180">Microsoft Product Support Services</a> and perform a title search for the words <b>HTTP</b> and <b>403</b>.</li>
<li>Open <b>IIS Help</b>, which is accessible in IIS Manager (inetmgr),
and search for topics titled <b>About Security</b>, <b>Limiting Access by IP Address</b>, <b>IP Address Access Restrictions</b>, and <b>About Custom Error Messages</b>.</li>
</ul></TD></TR></TABLE></BODY></HTML>
Can you please tell me where the problem is.
Thanks in advanced.
Charles
- Moved byWayne Phillips.MVPSunday, November 01, 2009 9:21 PMBetter match forum (From:System Center Mobile Device Manager)
Answers
- It looks like IIS has "IP Address and Domain Name Restrictions" configured. Read the Error Message: 403.6 - Forbidden: IP address rejected Technote, for a resolution.
Cheers Wayne
Airloom- Marked As Answer byElvis Wei -MSFTMSFT, ModeratorFriday, November 06, 2009 8:25 AM
- Proposed As Answer byElvis Wei -MSFTMSFT, ModeratorWednesday, November 04, 2009 8:45 AM
All Replies
- THis is the forum for System Center Mobile Device Manager.
I believe your post would belong in the Exchange Mobility forum:
http://social.technet.microsoft.com/Forums/en-US/exchangesvrmobility/ - It looks like IIS has "IP Address and Domain Name Restrictions" configured. Read the Error Message: 403.6 - Forbidden: IP address rejected Technote, for a resolution.
Cheers Wayne
Airloom- Marked As Answer byElvis Wei -MSFTMSFT, ModeratorFriday, November 06, 2009 8:25 AM
- Proposed As Answer byElvis Wei -MSFTMSFT, ModeratorWednesday, November 04, 2009 8:45 AM
It seems like the device doesn't trust the Root Cert, Go Daddy, you need add that to the approved list on the device.
Mark Morowczynski|MCT| MCSE 2003:Messaging, Security|MCITP:ES, SA,EA|MCTS:Windows Mobile Admin|Security+|http://almostdailytech.com


