Software

Solutions to an Android email and untrusted server certificate problem

Microsoft's frequent changes may cause issues with the email you receive on your Android phone. Jack Wallen offers a reader advice about such a problem.

One big issue with Android email setup is when Android doesn't trust the certificate being issued by the email server. Here's a related question from TechRepublic reader Chris Hodge.

Q: I've spent the day trying to create an Exchange Serve mail account on my HTC Evo 4G. Up until recently I had Microsoft Live Small Business account for my business. Microsoft closed this service and has opened with a revamped service called Microsoft365. I have migrated everything over and followed the instructions precisely on setting up mail on my phone, but each time I receive the following msg:

Security Warning. There are problems with the security certificate of this site. This certificate if not from a trusted source.

With the whole day behind me, I have not been able to move forward from this point. Any advice?

A: The easy answer is to go into the Advanced settings of the email account and make sure Accept All Certificates is checked. If that isn't checked, check it and try again. If it is checked and it's still not working, try the following:
  • Make sure your Android platform is fully up to date. If it isn't, update and try again.
  • Once you get to the point where the setup has connected to the server (but giving you the warning), you should be able to uncheck the Verify Certificate section in your incoming and outgoing settings.

If none of these solutions work for you, install NitroDesk's TouchDown app and set up your email account using that client. There are a lot more settings in that app, and you shouldn't have any problems with it.

About

Jack Wallen is an award-winning writer for TechRepublic and Linux.com. He’s an avid promoter of open source and the voice of The Android Expert. For more news about Jack Wallen, visit his website getjackd.net.

3 comments
arnoldlodge
arnoldlodge

What do I do if it doesn't get as far as connecting when the certificate error comes up? Is there a global mail setting I can change? I can't find anything. I'm using a HTC Desire S running android 2.3.5 and HTC Sense 3.0

APSDave
APSDave

Is there a way to import CAs or other certificates into Android? Checking the "Always accept" is a HUGE security rick because it leaves you open to man in the middle attacks (i've demonstrated this to several of my clients and it's a little scary)