Remove Root Certificate without access to MDM

How do I remove root certificates that are re-installed via an itunes/icloud backup when the retired MDM profile is not re-installed from the same backup file?


Posted on Sep 22, 2022 2:02 PM

Reply
Question marked as Top-ranking reply

Posted on Sep 22, 2022 2:31 PM

If the certificate profiles are not visible and removable via Settings > VPN & Device Management, then your iPhone is seemingly supervised, and you’ll need to discuss this with the ex-employer IT, or submit proof of original purchase to Apple and have them clear this.

7 replies

Sep 23, 2022 7:45 AM in response to Thierer

Thierer wrote:

1. settings/about/certificate trust settings house root certificates issued by third parties, but authenticated by Apple

i.e.
Juniper Networks Root CA
2. COMODO RSA Certification Authority...

These are legacy root certificates I would like to delete, though they are deselected.


There is no means to deselect a trusted root certificate within the Apple trust store.


Available trusted root certificates for Apple operating systems - Apple Support

Intro to certificate management for Apple devices - Apple Support


There is no Juniper Networks Root CA listed in the Apple docs (which are somewhat stale), though there is a Comodo RSA cert.


Which circles back to this being a supervised device, and with your options to remove the associated profiles (and reportedly with no management profiles loaded here), or to get the entity holding the supervisory lock to remove it, or to contact Apple with proof of purchase and get them to remove it.


Contact Apple Support. They’ll likely want proof of original purchase from Apple or an Apple authorized reseller as part of this.




Sep 22, 2022 2:27 PM in response to Lawrence Finch

The root certificate was installed many years ago by an ex-employer. The phone is my personal phone but used with my new employer, and they have installed certificates using the Microsoft Company Portal device management platform. I want to remove the old root certificates, which are currently turned off. The root certificates on this device are a carryover from a prior iPhone backup, from over five years ago.


The old root certificates are not part of my current MDM or personal profile.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Remove Root Certificate without access to MDM

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.