Can not re-enroll devices on Profile Manager (Server 5.3.1)

Hi there,


my self signed certificate run out of date and I updated it after the expiring date. After that Profile Manager do not longer pushes MDM notifications. Because iOS Devices still got the old certificate in there MDM Management profile.

I delete the MDM Management profile on the device und even in Profile Manager the Device itself and try to re-enroll the derive with the latest certificates.

If I try this (with or without using the actual trust certificate), the MDM profile can not be installed anymore. (Installation Error by SECP Server) But this behavior only concerns devices who been once enrolled before. A completely new device will be enrolled perfectly.

It seems to me that on Profilmanagers Database there still data of deleted device remain.


Did anyone know the way to find and kill all "hidden" data from deleted devices (manually) in Profile Managers database?


Kind regards

Jerry

Posted on May 18, 2020 2:02 AM

Reply

Similar questions

7 replies

May 21, 2020 1:33 AM in response to MaXenaeL

Thanks for the helpful Screenshots! Even if I try that way the result is ending up in still waiting process. After all I have read: if a certificate runs out of date I needs that wireless connected clients like iPads, MDM must deleted and re-enrolled again.

And this procedure did not function anymore with iOS Clients 13.4.x Still 12.x.x clients could be enrolled.

Could you please advice at your System (what Server Version did you use?) if you can enroll MDM on Clients with latest iOS?

May 19, 2020 2:39 AM in response to MaXenaeL

Hello MaXenael,


thanks for the advice! I have tested to update Groups & Users. Groups it self seems to work fine, but then I also tried to update Users and it end up in the "spinning wheel"


Today I received a brand new iPad and figured out that even this one now ends up with the result of a error while the profile installation.

It seems that there is a overall certificate problem that blocks the server to accept new devices an even stops pushing profile to well known devices.

Did anyone knows the procedure to completely update (or renew) (self-signed) certificates to the server?

May 20, 2020 1:26 AM in response to Jerry Spring

I didn't even notice THAT update info before you :-)



Then check status completion in Active Tasks first, then in Completed



For certificates you may check my another post: https://discussions.apple.com/thread/251319510?answerId=252630682022#252630682022

I had solved iOS 13 problem this way even in 5.2 Server. In 5.10 also works good.



Finally it seems you need to reinstall the Profile Manager after destroying its' database. After reinstall you'll have to reenroll devices.

May 21, 2020 11:54 PM in response to Jerry Spring

I repeat:


I had solved iOS 13 problem this way even in 5.2 Server. In 5.10 also works good.


I'm not a great expert in certificates thing, but I made working server with these ones onboard:
legal trust certificate from vendor
profile manager generated certificate
local hostname - self-signed - SSL server
domain name - sertificate list - SSL Server
local hostname - self-signed - code signing
domain name - sertificate list - code signing
Also the last certificate is used in Profile Manager settings (Sign configuration profiles)

Try to install Trust Profile first (My Devices)


This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Can not re-enroll devices on Profile Manager (Server 5.3.1)

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.