Thanks again your patience is appreciated. I found the cert hierarchy as you explained and actually imported and converted all 2 certificates. One was the same as before and did not load in the certificate manager but was read. The other one loaded and I saved it for server email etc but when I tried to install credentials for Mfe I still get the invalid server message :-( I had a look in firefox certificate manager and in "other" tab I found a certificate that was from Equifax to the exchange/zimbra server. I imported it converted to p7b and then when I tried to load it in n900 cert manager it said the certificate date was invalid/ expired which indeed it was. Could that be the right certificate and the problem? I recall in firefox the first time I had to validate that cert it asked me if I would ignore the expiry date. Could n900 manager not be able to do this perhaps? I have asked our IT people to issue a new unexpired certificate.