The Following User Says Thank You to xelo For This Useful Post: | ||
![]() |
2016-01-20
, 15:05
|
|
Posts: 4,118 |
Thanked: 8,901 times |
Joined on Aug 2010
@ Ruhrgebiet, Germany
|
#2
|
The Following 2 Users Say Thank You to peterleinchen For This Useful Post: | ||
![]() |
2016-01-20
, 18:56
|
Posts: 48 |
Thanked: 191 times |
Joined on Jan 2016
@ Münsterland, Germany
|
#3
|
short answer:
--edit
you might do it in as root with devel-su
AND possibly in "develsh" (giving some more rights), as I do not expect you to run that device in OpenMode?
# acmcli -C aegis-certman-common-ca::CertCACommonAdd -lc common-ca -a 16b5321bd4c7f3e0e68ef3bdd2b03aeeb23918d1.pem ERROR: cannot add certificates (Permission denied) # acmcli -c common-ca -a 16b5321bd4c7f3e0e68ef3bdd2b03aeeb23918d1.pem ERROR: cannot add certificates (Permission denied)
Jan 20 21:02:57 (2016) acmcli: aegis_storage.cpp(1436): ERROR add_file: access denied Jan 20 21:02:57 (2016) acmcli: aegis_storage.cpp(1641): ERROR add_link: access denied Jan 20 21:02:57 (2016) acmcli: aegis_storage.cpp(1935): ERROR commit: access denied, cannot commit '/var/lib/aegis/ps/Gs/certman.common-ca' Jan 20 21:02:57 (2016) acmcli: certman_main.cpp(1051): ERROR aegis_certman_add_certs: add certs failed (Permission denied)
# /usr/bin/acmcli -p common-ca -a 16b5321bd4c7f3e0e68ef3bdd2b03aeeb23918d1.pem Added 1 certificates # /usr/bin/acmcli -p common-ca -r 16b5321bd4c7f3e0e68ef3bdd2b03aeeb23918d1 Removed certificate '16b5321bd4c7f3e0e68ef3bdd2b03aeeb23918d1'
/usr/sbin/pasiv ariadne /usr/bin/acmcli -c common-ca -a 16b5321bd4c7f3e0e68ef3bdd2b03aeeb23918d1.pem Password for 'root': Added 1 certificates
Jan 20 21:46:26 (2016) acmcli: certman_main.cpp(184): ERROR Invalid certificate '/C=ES/L=C/ Muntaner 244 Barcelona/CN=Autoridad de Certificacion Firmaprofesional CIF A62634068/emailA ddress=ca@firmaprofesional.com' Jan 20 21:46:26 (2016) acmcli: certman_main.cpp(184): ERROR Invalid certificate '/C=NO/O=Buypass AS-983163327/CN=Buypass Class 3 CA 1' Jan 20 21:46:26 (2016) acmcli: certman_main.cpp(184): ERROR Invalid certificate '/C=NL/O=Staat der Nederlanden/CN=Staat der Nederlanden Root CA' Jan 20 21:46:26 (2016) acmcli: certman_main.cpp(184): ERROR Invalid certificate '/CN=T\xC3\x9CRKTRUST Elektronik Sertifika Hizmet Sa\xC4\x9Flay\xC4\xB1c\xC4\xB1s\xC4\xB1/C=TR/L=ANKAR A/O=(c) 2005 T\xC3\x9CRKTRUST Bilgi \xC4\xB0leti\xC5\x9Fim ve Bili\xC5\x9Fim G\xC3\xBCvenli\xC4\x9Fi Hizmetleri A.\xC5\x9E.' Jan 20 21:46:26 (2016) acmcli: certman_main.cpp(184): ERROR Invalid certificate '/CN=T\xC3\x9CRKTRUST Elektronik Sertifika Hizmet Sa\xC4\x9Flay\xC4\xB1c\xC4\xB1s\xC4\xB1/C=TR/L=Ankar a/O=T\xC3\x9CRKTRUST Bilgi \xC4\xB0leti\xC5\x9Fim ve Bili\xC5\x9Fim G\xC3\xBCvenli\xC4\x9Fi Hizmetleri A.\xC5\x9E. (c) Kas\xC4\xB1m 2005' Jan 20 21:46:30 (2016) acmcli: certman_main.cpp(184): ERROR Invalid certificate '/C=ES/L=C/ Muntaner 244 Barcelona/CN=Autoridad de Certificacion Firmaprofesional CIF A62634068/emailA ddress=ca@firmaprofesional.com' Jan 20 21:46:30 (2016) acmcli: certman_main.cpp(184): ERROR Invalid certificate '/C=NO/O=Buypass AS-983163327/CN=Buypass Class 3 CA 1' Jan 20 21:46:30 (2016) acmcli: certman_main.cpp(184): ERROR Invalid certificate '/C=NL/O=Staat der Nederlanden/CN=Staat der Nederlanden Root CA' Jan 20 21:46:30 (2016) acmcli: certman_main.cpp(184): ERROR Invalid certificate '/CN=T\xC3\x9CRKTRUST Elektronik Sertifika Hizmet Sa\xC4\x9Flay\xC4\xB1c\xC4\xB1s\xC4\xB1/C=TR/L=ANKAR A/O=(c) 2005 T\xC3\x9CRKTRUST Bilgi \xC4\xB0leti\xC5\x9Fim ve Bili\xC5\x9Fim G\xC3\xBCvenli\xC4\x9Fi Hizmetleri A.\xC5\x9E.' Jan 20 21:46:30 (2016) acmcli: certman_main.cpp(184): ERROR Invalid certificate '/CN=T\xC3\x9CRKTRUST Elektronik Sertifika Hizmet Sa\xC4\x9Flay\xC4\xB1c\xC4\xB1s\xC4\xB1/C=TR/L=Ankar a/O=T\xC3\x9CRKTRUST Bilgi \xC4\xB0leti\xC5\x9Fim ve Bili\xC5\x9Fim G\xC3\xBCvenli\xC4\x9Fi Hizmetleri A.\xC5\x9E. (c) Kas\xC4\xB1m 2005'
![]() |
2016-01-20
, 20:43
|
Community Council |
Posts: 691 |
Thanked: 1,240 times |
Joined on Sep 2010
@ Mbabane
|
#4
|
Hey Community,
recently I discovered a N950 in my employers device archive.
Now I'd like to use this awesome device daily to replace my not so good WindowsPhone.
![]() |
2016-01-20
, 20:58
|
Posts: 48 |
Thanked: 191 times |
Joined on Jan 2016
@ Münsterland, Germany
|
#6
|
Jan 20 21:54:33 (2016) mfeplugin[5404]: [Debug] virtual void MfeCheckCredentialsDialog::createContent() Jan 20 21:54:34 (2016) mfeplugin[5404]: [Debug] void MfeCheckCredentialsDialog::onAppeared() already online Jan 20 21:54:34 (2016) mfeplugin[5404]: [Debug] void MfeCheckCredentialsDialog::sendRequest() Jan 20 21:54:34 (2016) mfeplugin[5404]: [Debug] Connecting to URL: "https://xxxxxx:443/Microsoft-Server-ActiveSync" Jan 20 21:54:34 (2016) icd2 0.213.4+0m8[1189]: Duplicate filter: Do not add filter for app :1.757 Jan 20 21:54:34 (2016) mfeplugin[5404]: [Debug] QNetworkReplyImpl::_q_startOperation was called more than once Jan 20 21:54:37 (2016) mfeplugin[5404]: [Debug] void MfeCheckCredentialsDialog::onSendFinished(QNetworkReply*) replyError= 0 "Unknown error" Jan 20 21:54:37 (2016) mfeplugin[5404]: [Debug] error( 0 )= 3
![]() |
2016-01-20
, 21:23
|
|
Posts: 4,118 |
Thanked: 8,901 times |
Joined on Aug 2010
@ Ruhrgebiet, Germany
|
#7
|
The Following User Says Thank You to peterleinchen For This Useful Post: | ||
![]() |
2016-01-20
, 21:30
|
|
Posts: 4,118 |
Thanked: 8,901 times |
Joined on Aug 2010
@ Ruhrgebiet, Germany
|
#8
|
![]() |
2016-01-21
, 08:06
|
Posts: 48 |
Thanked: 191 times |
Joined on Jan 2016
@ Münsterland, Germany
|
#9
|
Let MfE step back (need to power up my N950-in-use and have a look) and first get your certs done!
I gave you the hint already:
devel-su
develsh
acmcli -c common-ca -e -a myCert.pem
~ $ devel-su Password: BusyBox v1.20.0.git (MeeGo 3:1.20-0.2+0m8) built-in shell (ash) Enter 'help' for a list of built-in commands. ~ # develsh BusyBox v1.20.0.git (MeeGo 3:1.20-0.2+0m8) built-in shell (ash) Enter 'help' for a list of built-in commands. ~ # acmcli -c common-ca -e -a /home/user/MyDocs/Downloads/16b5321bd4c7f3e0e68ef3bdd2b03aeeb23918d1.pem ERROR: cannot add certificates (Permission denied)
~ # accli -I Current mode: open IMEI: Credentials: UID::root GID::root CAP::chown CAP::dac_read_search CAP::fowner CAP::fsetid CAP::kill CAP::linux_immutable CAP::net_bind_service CAP::net_broadcast CAP::net_admin CAP::net_raw CAP::ipc_lock CAP::ipc_owner CAP::sys_ptrace CAP::sys_pacct CAP::sys_boot CAP::sys_nice CAP::sys_resource CAP::sys_time CAP::sys_tty_config CAP::lease CAP::audit_write CAP::audit_control CAP::setfcap GRP::root GRP::dialout GRP::video GRP::pulse-access GRP::users GRP::metadata-users GRP::gallerycoredata-users GRP::calendar AID::.develsh. tracker::tracker-extract-access tracker::tracker-miner-fs-access libaccounts-noa::accesssvt package-manager::packagemanager_limited package-manager::packagemanager_private icd2::icd2-plugin Cellular TrackerReadAccess TrackerWriteAccess Location FacebookSocial develsh::develsh
~ # ariadne acmcli -c common-ca -e -a /home/user/MyDocs/Downloads/16b5321bd4c7f3e0e68ef3bdd2b03aeeb23918d1.pem Password for 'root': 16b5321bd4c7f3e0e68ef3bdd2b03aeeb23918d1
Powered on and ...
what are your settings in MfE account (obfuscate)?
E-Mail: mail@domain.tld User: mail@domain.tld Pass: PASSWORD Domain: Nothing Server Address: horde.domain.tld Secure: YES Port:443
E-Mail: mail@domain.tld User: mail Pass: PASSWORD Domain: domain.tld Server Address: horde.domain.tld Secure: YES Port:443
![]() |
2016-01-21
, 08:36
|
Community Council |
Posts: 691 |
Thanked: 1,240 times |
Joined on Sep 2010
@ Mbabane
|
#10
|
We already tested that with a testaccount on sicelo's N900. Which seems to work.
The Following 2 Users Say Thank You to sicelo For This Useful Post: | ||
![]() |
Tags |
activesync, harmattan |
|
recently I discovered a N950 in my employers device archive.
Now I'd like to use this awesome device daily to replace my not so good WindowsPhone.
I've already been capable of bringing the N950 into Openmode.
I've got two Questions:
1) How to install custom CA's (cacert.org)
2) How to enable Mail for Exchange (Question might depend on Q1)
Ok, let's talk about more details:
I fail when trying to install new Root-Certificates (those of cacert.org)
When downloading and installing the certificate, I can see the certificate and it is added in the certificatemanager, but the /var/log/syslog says:
I use cacert to secure my Mail, Calender and Contacts which are "hosted" with horde and can be accessed with ActiveSync.(Exchange)
Unfortunately I'm not able to connect to the "Exchange" Server with Mail-For-Exchange.
We could connect successfully with a N900 (with and without cacert certificates), Windows Phone and Android devices, so the server should not be the Problem.
MFE reports "Invalid host address for Mail for Exchange Server".
What I already tried:
But, as of now: no success
Do you have any ideas how to get this working?
Best Regards
xelo
=========
Solution:
Certificates:
1. Additional certificates can be Installed with
If neither develsh was elevated nor the device uses inception and ariadne, you will receive a
Not found yet (2016-01-24)
Last edited by xelo; 2016-01-24 at 16:23. Reason: Added partial solution to first Post