Thread: certificates?
View Single Post
  #5 (permalink)  
Old 10-29-2009, 11:34 AM
Time_Lord's Avatar
Time_Lord
Lurker
Offline
Threadstarter
 
Join Date: Jan 2009
Posts: 18
Reputation: 0
Time_Lord is a n00b
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Re: certificates?

I spoke to Sprint who then connected me to HTC, the short answer is you can not import a certificate into the phone. However that is not completely correct.

The problem is the application needs to accept the certificate, in this case the mail application, the mail application supplied with the phone refuses to use a self signed certificate. I did find K-9 email (and yes its named after the dog in Dr. Who where my nick comes from ) and that does accept a self signed certificate, but there is a caveat with the program...

The program accepts any certificate and stores it without presenting you with any way to verify the authenticity (fingerprint) of the certificate which in turn leaves you open to a man in the middle attack. Realistically I'm more concerned of somebody pulling a clear text password off the wire rather than a man in the middle attack but your mileage may vary.

My next problem is find what program other than the sms client is keeping the phone awake... maybe K9?

TL
Reply With Quote