Profile Manager Enrollment - iOS - Server Certificate Invalid

I have been getting an error trying to enroll iOS devices into profile manager. My MacBook and iMac enroll just fine. However my iPhone and iPad do not.


When I enroll my MacBook Pro, I first log into https://(FQDN)/mydevices, select profiles, Install Trusted Profile. I then go back to devices, and click 'Enroll now'. When I check the Profiles section of System Preferences, I see that the 'Trusted Profile' has added two certificates refering to my server. I can only assume one matches the Self Signed I generated shortly after making my hostname public, and the other Apple Push generated for me.


However when I do this exact same process on my iPad/iPhone, when I attempt the 'Enroll Now' step, I get the error "The server certificate for "https://(FQDN)/devicesmanagement/api/device/ota_service" is invalid.


My searches for this issue have turned up issues close to this, but never exactly this, and the solutions don't seem to work for me. Here are some key points to note:


1. Tried demoting to standalone, re-promote to OD Master, then deleted all certificates, and regenerated all (including the Push cert from Apple)

2. Ran sudo changeip -checkhostname

3. DNS routes forward and reverse correctly in my local LAN

4. I had been getting "Remote Verification failed: (os/kern) failure" / "TEAVerifyCert() returned NULL" in my logs every 3 seconds until I did the steps listed in '1'


Looking forward to 10.7.1

Mac mini, Mac OS X (10.7), Server

Posted on Aug 10, 2011 12:38 PM

Reply
128 replies

Feb 9, 2012 7:30 AM in response to DOLAdmin

Good Job!!!! :-)


Yeah sometimes its easier to take a few steps back, and start over. At least you didn't have to export everything from Open Directory and re-import....


The part that you didn't understand was the part about removing yourself form the kerberos realm on the OD master, and joinging the AD realm.


It only helps a few tings with MAC users using SMB shares. Kerberos works behind the scnese and creates tickets when trying to access shared drives. Its one step closer into SSO for shared drives.

Feb 9, 2012 8:25 AM in response to DOLAdmin

Sounds good! Im happy I could help, and got you up and running!


Just remember that what is stored in devicemgr (profile manager) is not backed up user management for open directory. If your pushing policies to anything under 10.6 you still need to create the setup in workgroup manager on the server so you can control both environments.


I actually got lucky on who I talked to at apple, he wouldn't support the AD / OD without having a service contract, but was very helpful and had some good advice!!!


It would be nice if apple used the info from the forum and compiled a nice howto. I have helped a few people know from my experience and its not like its impossible. Their documentation is just not very straight forward on 10.7 like it was with 10.6.


The default profile is not used by my organization, that is just a profile that the user can actually download to their device if they chose.


We push out the profiles through profile manager, and you can also make it so the user is not able to delete the pushed profiles (Profile Manager Web -> Group Settings -> General -> Security -> Never / Authorization)


If the device is behind a firewall you need these ports open below in order to push to wifi / 3g on the internet.


ping

https

tcp - 2195

tcp - 1640

tcp - 2196

tcp - 5223

Feb 9, 2012 10:22 AM in response to burton11234

Thanks for clarification. I've seen both port related resources (thanks). This has been another challenging area since I have to meet extra stringent security measures here. I've been wanting to know what are the minimum ports (or protocols/services) that need to be open (on both firewalls) if we're ONLY doing iPad policy enrollments/enforcement?. Would it only be the following based on the Services and Ports list?


Apple push notifications

2195

2196

TCP

TCP

Profile Manager

80 or 443

1640

2195

2196

5223

TCP

TCP

TCP

TCP

TCP

Web service HTTP

Web service HTTPS

Web service custom website

Note: Exposing web service also exposes wiki, web calendar, webmail, and Profile Manager services.


80

443

YourPortNumber

TCP

TCP

TCP

Feb 10, 2012 5:50 AM in response to DOLAdmin

The only ports that are open from the DMZ to Untrst are the ones listed below. Those were the ports I found needed to be opened in order to enroll a iOS device. Although there is nothing stoping anyone from enrolling a laptop to those ports. Im not sure if you can be that restrictive since the same ports seem to be used for push services on OSX as well as iOS.


ping

https

tcp - 2195

tcp - 1640

tcp - 2196

tcp - 5223


You can restrict access by not using active directory, or if you use active directory, create a security group in AD and then apply that security group to Server Manager -> Select Server Name -> Select Access -> Select Profile Manager.


With applying users / groups to profile manager you shoudl be able to restrict who is allowed to login to the site via web. You could always allow these users at first time connecting to login, and then remove access from them.

Feb 20, 2012 7:44 AM in response to tmcmurtr

Can you do forward and reverse lookups of the server on the network your iOS devices are on?


Are you using DNS Service on the OSX server?


If you log into the section on where you can register your push certs from apple, It brings you in a web interface. It generates 4 certs with the FQDN. If you have wiped the server and changed hostnames it may have multiple FQDNS for the certs. Do those certs corespond to your correct FQDN?


When you said you follwed the steps, did you start over, like I had mentioned and wiped everything?

Feb 20, 2012 10:36 AM in response to tmcmurtr

I have posted a few different places and everyone was able to get things working at some point or another.


When you re-created your OD master, with the FQDN did you revoke your apple push certs?


Did you remove all of your certs after destroying your OD Master?


I moved a mini I had to our lab, on a different domain and everything, just removed the certs after removing OD, and wiping devicemgr. No need to reformat... I didn't have any issues at all enrolling after everything was said and done.


There has to be some mismatch in what was done when you went through the instructions. Maybe there is an invalid cert that was left lying around before you re-created OD?

Feb 20, 2012 11:27 AM in response to burton11234

burton, thanks for your help. It took purging everything again, but it finally worked. Based on your experience, is there a need to open anything besides 2196 and 2195 if I don't plan on device enrollment occurring outside of my environment? All I want is remote wipe capabilities to occur on iOS devices and the ability to perform remote udpates/policy changes through profile manager.

Feb 20, 2012 11:38 AM in response to tmcmurtr

Your more then welcome!


Unless the networks are seperated by a firewall, you dont need to open any ports. If your network is seperated by a firewall you will need to open a few ports. Our mini in the dmz serves just iOS devices and these were the ports opened inorder enroll and push services. Obviously ping was enabled for verifying the device was up, and https was browsing the to the web page so you can enroll the device. The other 4 ports were for the process of enrolling to work and push services.


ping

https

tcp - 2195

tcp - 1640

tcp - 2196

tcp - 5223

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Profile Manager Enrollment - iOS - Server Certificate Invalid

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.