The setup is as follows;
Exchange 2013 SP1 published through -- Web Application Proxy server (2012 R2) --- ADFS v3.0 (2012 R2) - all latest windows updates applied.
iPhones, iPads, Windows Mobiles all working without issue. Samsung devices get a certificate warning when attempting to use activesync
Can browse to OWA on the samsung device and no SSL warning is displayed, can log in and read email.
Exchange connectivity Tests - reveal all is okay, other than the SSL Chain for older generation mobile windows phones.
Samsung is running the latest OS from Andriod 4.2.2
Tried resetting permissions on windows account for Exchange servers
Tried creating numerous Mobile device policies
Tried activating mobile device with SIM card, WiFi disabled / enabled etc
Same Samsung devices work fine when connecting to Exchange 2010 via TMG using same WildCard SSL.
any further ideas welcome please?