<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Enrolling Personal Certificates with SCMDM</title>
	<atom:link href="http://mobilitydojo.net/2009/03/09/enrolling-personal-certificates-with-scmdm/feed/" rel="self" type="application/rss+xml" />
	<link>http://mobilitydojo.net/2009/03/09/enrolling-personal-certificates-with-scmdm/</link>
	<description>place of the mobility way</description>
	<lastBuildDate>Fri, 11 May 2012 10:49:18 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Andreas</title>
		<link>http://mobilitydojo.net/2009/03/09/enrolling-personal-certificates-with-scmdm/comment-page-1/#comment-6651</link>
		<dc:creator>Andreas</dc:creator>
		<pubDate>Fri, 06 Nov 2009 17:27:43 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=685#comment-6651</guid>
		<description>Then you&#039;re ready to roll :)

It&#039;s no problem adding an option for disabling SSL. Obviously recommended to use SSL, but for debug purposes it could be useful.

I&#039;ll add a checkbox and build a new version - hope to have it online later today or tomorrow.</description>
		<content:encoded><![CDATA[<p>Then you&#8217;re ready to roll <img src='http://mobilitydojo.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>It&#8217;s no problem adding an option for disabling SSL. Obviously recommended to use SSL, but for debug purposes it could be useful.</p>
<p>I&#8217;ll add a checkbox and build a new version &#8211; hope to have it online later today or tomorrow.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://mobilitydojo.net/2009/03/09/enrolling-personal-certificates-with-scmdm/comment-page-1/#comment-6646</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Fri, 06 Nov 2009 12:37:43 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=685#comment-6646</guid>
		<description>Hi, Andreas.
I found a trouble - my CA wasn&#039;t set to work with SSL. After I enable SSL and enroll certificate for web server your tools works fine. Thank you for your help.

P.S.
May you can add in DojoCert additional switch about using SSL?</description>
		<content:encoded><![CDATA[<p>Hi, Andreas.<br />
I found a trouble &#8211; my CA wasn&#8217;t set to work with SSL. After I enable SSL and enroll certificate for web server your tools works fine. Thank you for your help.</p>
<p>P.S.<br />
May you can add in DojoCert additional switch about using SSL?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andreas</title>
		<link>http://mobilitydojo.net/2009/03/09/enrolling-personal-certificates-with-scmdm/comment-page-1/#comment-6641</link>
		<dc:creator>Andreas</dc:creator>
		<pubDate>Thu, 05 Nov 2009 22:45:17 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=685#comment-6641</guid>
		<description>Progress - that&#039;s good.

1. This would be dependent on your AD setup - should probably work with all the formats you listed. You can check by opening https://ca-fqdn/certsrv in the browser on your desktop you&#039;ll be prompted to authenticate. This would also flag any SSL errors.
2. Server can be either FQDN or IP, but make sure it matches the common name in your certificate. Usually SSL certificates aren&#039;t issued to IP so FQDN is probably your best bet. Make sure the address is resolvable by the device.
3. My tool assumes you are using SSL. (NoSSL = 0)

Since it works building the xml, and my tool basically does the same thing, I&#039;m not sure what it is. The settings you type into the xml are the same you should use in DojoCert. So the only difference is that SSL is optional in the XML.</description>
		<content:encoded><![CDATA[<p>Progress &#8211; that&#8217;s good.</p>
<p>1. This would be dependent on your AD setup &#8211; should probably work with all the formats you listed. You can check by opening <a href="https://ca-fqdn/certsrv" rel="nofollow">https://ca-fqdn/certsrv</a> in the browser on your desktop you&#8217;ll be prompted to authenticate. This would also flag any SSL errors.<br />
2. Server can be either FQDN or IP, but make sure it matches the common name in your certificate. Usually SSL certificates aren&#8217;t issued to IP so FQDN is probably your best bet. Make sure the address is resolvable by the device.<br />
3. My tool assumes you are using SSL. (NoSSL = 0)</p>
<p>Since it works building the xml, and my tool basically does the same thing, I&#8217;m not sure what it is. The settings you type into the xml are the same you should use in DojoCert. So the only difference is that SSL is optional in the XML.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://mobilitydojo.net/2009/03/09/enrolling-personal-certificates-with-scmdm/comment-page-1/#comment-6636</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Thu, 05 Nov 2009 11:00:13 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=685#comment-6636</guid>
		<description>Andreas,
Today I rename my .xml to _setup.xml as you wrote and now it&#039;s work fine.
After that I clear my device by hard reset, install root certificate and your utility, try to get user certificate by DojoCert and receive an error :(
Can you answer on some of my questions:
1. Username - there must be only username, or domain\username, or username@domain?
2. Server - there must be FQDN, or IP is correct too? In xml IP is acceptable.
3. Does your tool by default work without SSL - I mean &quot;NoSSL = 1&quot;?

And thank you for your help one more time... :)

Alex</description>
		<content:encoded><![CDATA[<p>Andreas,<br />
Today I rename my .xml to _setup.xml as you wrote and now it&#8217;s work fine.<br />
After that I clear my device by hard reset, install root certificate and your utility, try to get user certificate by DojoCert and receive an error <img src='http://mobilitydojo.net/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /><br />
Can you answer on some of my questions:<br />
1. Username &#8211; there must be only username, or domain\username, or username@domain?<br />
2. Server &#8211; there must be FQDN, or IP is correct too? In xml IP is acceptable.<br />
3. Does your tool by default work without SSL &#8211; I mean &#8220;NoSSL = 1&#8243;?</p>
<p>And thank you for your help one more time&#8230; <img src='http://mobilitydojo.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Alex</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://mobilitydojo.net/2009/03/09/enrolling-personal-certificates-with-scmdm/comment-page-1/#comment-6620</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Wed, 04 Nov 2009 08:15:24 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=685#comment-6620</guid>
		<description>Many thanks for your help, Andreas! It&#039;s very important for me.

I can&#039;t right now make new tests, but I can see some of my mistakes:
1. My xml&#039;s name is not _setup.xml before I start make cab
2. I was tried to enroll certificate only with NoSSL = 1
3. I think it would be better to reimport root certificate to device

Tomorrow I will try again and write here about my results.</description>
		<content:encoded><![CDATA[<p>Many thanks for your help, Andreas! It&#8217;s very important for me.</p>
<p>I can&#8217;t right now make new tests, but I can see some of my mistakes:<br />
1. My xml&#8217;s name is not _setup.xml before I start make cab<br />
2. I was tried to enroll certificate only with NoSSL = 1<br />
3. I think it would be better to reimport root certificate to device</p>
<p>Tomorrow I will try again and write here about my results.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andreas</title>
		<link>http://mobilitydojo.net/2009/03/09/enrolling-personal-certificates-with-scmdm/comment-page-1/#comment-6609</link>
		<dc:creator>Andreas</dc:creator>
		<pubDate>Tue, 03 Nov 2009 18:19:08 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=685#comment-6609</guid>
		<description>The XML from bansky.net is ok, but keep in mind a few things:
- The quoute characters (&quot;&quot;) are often corrupted into a very similar quote sign when copying from a webpage to notepad. Make sure you have the correct quotes.
- The xml file should be called _setup.xml before you run makecab on it.
- When &quot;NoSSL&quot; is set to 1 the device will attempt to enroll over plain HTTP. A default install of an enterprise CA will not let you enroll without SSL. (Set NoSSL = 0.)
- You need to change the guid in the xml (and thus rebuild the cab) for each attempt.

I tested creating a cab like this, and it worked.

I was able to replicate your error with my own utility. If I try to enroll without the root certificate installed on my device I get the same error code.

After installing the root certificate it worked with both methods. If you have the root cert available as a .cer file I would recommend copying to the device and run it just to be sure.</description>
		<content:encoded><![CDATA[<p>The XML from bansky.net is ok, but keep in mind a few things:<br />
- The quoute characters (&#8220;&#8221;) are often corrupted into a very similar quote sign when copying from a webpage to notepad. Make sure you have the correct quotes.<br />
- The xml file should be called _setup.xml before you run makecab on it.<br />
- When &#8220;NoSSL&#8221; is set to 1 the device will attempt to enroll over plain HTTP. A default install of an enterprise CA will not let you enroll without SSL. (Set NoSSL = 0.)<br />
- You need to change the guid in the xml (and thus rebuild the cab) for each attempt.</p>
<p>I tested creating a cab like this, and it worked.</p>
<p>I was able to replicate your error with my own utility. If I try to enroll without the root certificate installed on my device I get the same error code.</p>
<p>After installing the root certificate it worked with both methods. If you have the root cert available as a .cer file I would recommend copying to the device and run it just to be sure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://mobilitydojo.net/2009/03/09/enrolling-personal-certificates-with-scmdm/comment-page-1/#comment-6604</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Tue, 03 Nov 2009 14:09:06 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=685#comment-6604</guid>
		<description>Sorry, xml code was filtered, so I copy it one more time, but without &quot;more than&quot;&amp;&quot;less than&quot;

wap-provisioningdoc
   characteristic type=&quot;BrowserFavorite&quot;
      characteristic type=&quot;MSN Search&quot;
         parm name=&quot;URL&quot; value=&quot;http://search.msn.com/&quot;
      /characteristic
   /characteristic
/wap-provisioningdoc</description>
		<content:encoded><![CDATA[<p>Sorry, xml code was filtered, so I copy it one more time, but without &#8220;more than&#8221;&amp;&#8221;less than&#8221;</p>
<p>wap-provisioningdoc<br />
   characteristic type=&#8221;BrowserFavorite&#8221;<br />
      characteristic type=&#8221;MSN Search&#8221;<br />
         parm name=&#8221;URL&#8221; value=&#8221;http://search.msn.com/&#8221;<br />
      /characteristic<br />
   /characteristic<br />
/wap-provisioningdoc</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://mobilitydojo.net/2009/03/09/enrolling-personal-certificates-with-scmdm/comment-page-1/#comment-6603</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Tue, 03 Nov 2009 14:01:52 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=685#comment-6603</guid>
		<description>P.S.
I try to enroll certificate from device using xml which described here:

http://bansky.net/blog/2008/11/enrolling-user-certificate-into-windows-mobile-over-the-air/

and make changes to IE on device using follow xml:


   
      
         
      
   


But none of them work :( CAB where made by makecab and signed by EM CAB Signing Utility. Root certificate is installed on device. Where can I make a mistake?</description>
		<content:encoded><![CDATA[<p>P.S.<br />
I try to enroll certificate from device using xml which described here:</p>
<p><a href="http://bansky.net/blog/2008/11/enrolling-user-certificate-into-windows-mobile-over-the-air/" rel="nofollow">http://bansky.net/blog/2008/11/enrolling-user-certificate-into-windows-mobile-over-the-air/</a></p>
<p>and make changes to IE on device using follow xml:</p>
<p>But none of them work <img src='http://mobilitydojo.net/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' />  CAB where made by makecab and signed by EM CAB Signing Utility. Root certificate is installed on device. Where can I make a mistake?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://mobilitydojo.net/2009/03/09/enrolling-personal-certificates-with-scmdm/comment-page-1/#comment-6602</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Tue, 03 Nov 2009 12:39:20 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=685#comment-6602</guid>
		<description>Andreas, Thanks for your help, but there is no any progress.
I was looked through logs and didn&#039;t find anything interesting. After this I create new .xml file without username and password keys, make a .cab-file by makecab.exe and try to install it to device. The only thing I have is message &quot;installation unsuccessful&quot;. No any other errors or request (like name, password). May be you can recommend any step-by-step guides about .xml creation.</description>
		<content:encoded><![CDATA[<p>Andreas, Thanks for your help, but there is no any progress.<br />
I was looked through logs and didn&#8217;t find anything interesting. After this I create new .xml file without username and password keys, make a .cab-file by makecab.exe and try to install it to device. The only thing I have is message &#8220;installation unsuccessful&#8221;. No any other errors or request (like name, password). May be you can recommend any step-by-step guides about .xml creation.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andreas</title>
		<link>http://mobilitydojo.net/2009/03/09/enrolling-personal-certificates-with-scmdm/comment-page-1/#comment-6599</link>
		<dc:creator>Andreas</dc:creator>
		<pubDate>Tue, 03 Nov 2009 08:22:53 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=685#comment-6599</guid>
		<description>SCMDM SP1 will provision the root certificate during enrollment, but will remove on the first application of group policies if you haven&#039;t included the root cert for distribution as part of the policy. If you can see certificate listed on the device you should be ok though.

The next part then is definitely looking at the CA to see if there&#039;s any clues there.

You don&#039;t need to know anything about OMA CP/DM to work with the xml above. If you manage to pack the xml into a cab/cpf file it should work. Are you getting any error on the device (other than &quot;installation unsuccessful&quot;)? You could try removing username/password from the xml as I have seen issues doing silent enrollments with the xml. The user will then be prompted to enter credentials when the xml executes. (Haven&#039;t got my own source code accessible right now, but I believe I had to include a silent parameter when the user isn&#039;t prompted for credentials.)</description>
		<content:encoded><![CDATA[<p>SCMDM SP1 will provision the root certificate during enrollment, but will remove on the first application of group policies if you haven&#8217;t included the root cert for distribution as part of the policy. If you can see certificate listed on the device you should be ok though.</p>
<p>The next part then is definitely looking at the CA to see if there&#8217;s any clues there.</p>
<p>You don&#8217;t need to know anything about OMA CP/DM to work with the xml above. If you manage to pack the xml into a cab/cpf file it should work. Are you getting any error on the device (other than &#8220;installation unsuccessful&#8221;)? You could try removing username/password from the xml as I have seen issues doing silent enrollments with the xml. The user will then be prompted to enter credentials when the xml executes. (Haven&#8217;t got my own source code accessible right now, but I believe I had to include a silent parameter when the user isn&#8217;t prompted for credentials.)</p>
]]></content:encoded>
	</item>
</channel>
</rss>

