"The problem lies with self signed certificates or CA certificates approved without an android.
The button accept all certificates does not operate well
The system can not add a CA unless you have a P12 certificate. And even the certificate not allways properly install.
There are three simple solutions:
1. Install and manage touchdown exchange mails and contacts from it. (demo 30 days)
2. Install a certificate from a recognized company like Verisign startssl (free) or another.
3. Wait for the final OTA and meanwhile see yours mails from OWA normally 
https://www.yourcompanydomain.com/exchange
Makes no sense to go round in circles, try a solution and claim directly to google for the publication of a new ota arranging.
From my point of view perhaps the best and safest is to change the certificate by one of a CA recognized.
Finally if your problem is " This server requires security features your phone does not support " you have two solutions
Add an exception to your user in Exchange Admin
Wait for de OTA with this feature released.
I hope this finally clarifies yours doubts.
Thanks all
Roman"