Profile Manager Enrollment - iOS - Server Certificate Invalid

I have been getting an error trying to enroll iOS devices into profile manager. My MacBook and iMac enroll just fine. However my iPhone and iPad do not.


When I enroll my MacBook Pro, I first log into https://(FQDN)/mydevices, select profiles, Install Trusted Profile. I then go back to devices, and click 'Enroll now'. When I check the Profiles section of System Preferences, I see that the 'Trusted Profile' has added two certificates refering to my server. I can only assume one matches the Self Signed I generated shortly after making my hostname public, and the other Apple Push generated for me.


However when I do this exact same process on my iPad/iPhone, when I attempt the 'Enroll Now' step, I get the error "The server certificate for "https://(FQDN)/devicesmanagement/api/device/ota_service" is invalid.


My searches for this issue have turned up issues close to this, but never exactly this, and the solutions don't seem to work for me. Here are some key points to note:


1. Tried demoting to standalone, re-promote to OD Master, then deleted all certificates, and regenerated all (including the Push cert from Apple)

2. Ran sudo changeip -checkhostname

3. DNS routes forward and reverse correctly in my local LAN

4. I had been getting "Remote Verification failed: (os/kern) failure" / "TEAVerifyCert() returned NULL" in my logs every 3 seconds until I did the steps listed in '1'


Looking forward to 10.7.1

Mac mini, Mac OS X (10.7), Server

Posted on Aug 10, 2011 12:38 PM

Reply
128 replies

Mar 12, 2012 9:10 AM in response to TXED

Try enrolling locally to the FQDN. When you enroll over the internet the public DNS record has to have the same FQDN as you used for your internal DNS.


If you want your push to work over the internet you will have to create a public DNS record that coresponds to your FQDN.


If your server is called server.apps.net that will have to corespond to your OD Realm and your push certs you obtained from apple with the FQDN of everything that was used.


Since certs are bassed off of a FQDN..... Your DNS name will have to be able to resolve the FQDN. If this doesn't it will say your cert is invalid. The apple push certs use your FQDN of your OD realm. So in order to make everything happy depending on what your public DNS record is and your internal domain you may have to start over to make everything match up properly.


If you use internal DNS for testing purposes you can always create another DNS zone in Windows and and then the devices will be able to resolve that zone.

Mar 12, 2012 10:55 AM in response to burton11234

Ok i tried to enroll the mac mini that the profile manager is running off of and it fails to install. I can reach my server with same domain name from both local and Internet and it resolves correctly. What would you suggest i do? Wipe it all and start over? If I do start over I did read both post you guys made about it and I am confused to the correct way to start this over with fresh setup. Do I created the local self signed cert before I do the apple push certs etc. My head is starting to spin. I really do appreciate all your help.


Thank You.

Mar 13, 2012 8:59 AM in response to TXED

Hey guys I would like to start over and do a fresh setup of the Profile manager and OD stuff. Seems my OD wasn't getting setup right. So I have read two post showing ways of performing but I am a bit confused! I just want to start fresh. I do not have a SSL cert from anyone so I guess I would use a self signed one? I am stopping now as I have worn myself out trying to get this going. I know its asking a lot but it would be nice if someone had a walk thru? Would it better if I bought a SSL cert? I would rather not. I am not using active directory either. It seems to me that there should be a plan to follow so we don't get our certs created wrong. As I stated I am new to all this and I am learning as we go along.


Thanks for all you guys help!

Mar 13, 2012 9:25 AM in response to TXED

@TXED


You can start by thanking apple for making a poor install / config guide. As 10.6 that had much better documentation for install / config guides :-)


Go back to page 3 and go toward the bottom, there is a guide i put together that tells you everything to do inorder to get it up and working properly, you can do this without wiping the unit.


If you do this I would just ignore this step below in quotes as it retains to having your OD master join your AD realm.


"3) I would suggest removing kerberos, and binding it to the AD realm."


If you decide to do a reformat / wipe then go for it. Only thing you have to worry about is DNS.


Make sure you have a proper forward / reverse zone and you can do lookups both forwards and backwards on the host. Once your DNS is configured properly, you can configure OD / Profile Manager as it will use your DNS for your FQDN that is already configured.


Once that is done you can sign up for the push certs through apple, you will notice the FQDN of your push certs will match up to what your FQDN is. Since everything apple does is bassed of your FQDN they all need to match.


If you want to go public, you will have to setup the DNS record to match the FQDN of your server so that way the server will have a proper CERT (the cert has the FQDN of your server).


If you want to have a different public DNS record like server.domain.com you will need to setup that forward / reverse zone on your DNS server and make sure the hostname / FQDN of the server matches this structure before creating your OD / Profile Manager settings and Apply Push Certificates.


If you create a public cert, that will work, although you still need to be in the correct format since the public cert uses your self signed cert in order to create the public cert. So if DNS / FQDN is not correct the public cert will be a waste and a new one will have to be created.


You are better off getting everything working and then setting up a public cert.


Just remember everything is bassed of DNS (Certs / OD / Apple Push Certs). If you dont have the proper DNS / FQDN then it wont work. If you have to create a DNS zone for this purpose then it wont hurt to do so.


Im more then happy to help, and help troubleshoot your issue, but there should be more then enough info just alone in this forum in the direction you need to go. As I have helped some users that apple couldn't even help. If you need step by step help you may want to consider opening a ticket with apple since they employee people to do that kind of work.


Apple did not make it easy this time trying to deploy things, they thought it would be best to strip out confiuration settings and steps in the GUI so that it would be more toned down for the "every day" user although it doesn't work that way in the end. I had alot of issues at first but in the end it all comes down to DNS, since the Self Signed certs are auto geneated from the FQDN.

Mar 22, 2012 8:47 AM in response to burton11234

Well i decided to wipe out everything and start over! I wiped the hard drive and reinstalled server software.


I am at the beginning where it ask me to enter my Server name and have decided to use godaddy instead what we where using long story!


I have purchased a domain at godaddy and ready to start fresh. Since its just a domain name parked there i should be able to use there url forward to it to my mac mini server if i give it an ip to forward to? How would i use godaddy to setup the forward and reverse lookup? I want to get this working first before i start the setup on the mac mini that way i would be sure to get the certs correct. Sorry to ask all this but i am worn out trying to get it all working.


Thanks for any info you can give me!

Mar 27, 2012 5:42 AM in response to TXED

Using godaddy isn't going to do you any good except having a public DNS record. If you bought a DNS name that doesn't have anything to do with your organization you will have to create a DNS zone so your ogranization will be able to resolve the DNS name of your server.


Its easier to start off using a local DNS server that your in control off. The easiest way to do everything since everything revolves around your FQDN that you give the server. Is setup the server with a relivant FQDN that is from your ogganization and create a Host (A) record for forward and (PTR) record for reverse. Once clients can resolve them by IP / Hostname then go through the motions and create OD / Profile Manager, and get your apple certs. This all works off your FQDN on the server.

Mar 29, 2012 5:46 AM in response to TXED

No, there is no way I am aware of. Profile Manager (devicemgr) uses a postgres database to save the settings to. There is no easy way to back it up other then use time machine and / or, export the database, or use some other 3rd party tool that uses some sort of rsync or scp to pull off backups.


I recreated all my policies over again from workgroup manager. If the users use a global policy and all of the VPN configs are the same, just create a group and apply those settings to a group and every time you add the device to the group it will get those policys.

Jun 15, 2012 1:01 PM in response to burton11234

What happend in my case is that I had changed the OD IntermediateCA_* certificate to "Always Trust" and I was not able to enrol a device any more (but it got rid of the xscertd: Returning response with code 200 log enrty every 30sec). Changing back to "use System Default" fixed it (of course everything else like an intact OD is required as well) Hope that helps.

Jul 23, 2012 3:01 PM in response to John B Portland

I've spent hours on this now and simply cannot get it working. The cert stuff is all sorted and enrolling OSX devices works fine but I just cannot get IOS devices to enroll. I keep getting 'invalid profile'.


I reiterate - all the certificates are working and it shows verified for everything but just will not enroll.


Any ideas? This is doing my head in slightly now!


I'm currently running https://servername.local/mydevices


I have tried .private and fully accessibly internet addresses and all with the same result

Jul 24, 2012 1:54 PM in response to jgcumming

Certs are all done by FQDN. With that being said OSX devices work fine with using short names, but mobile devices need the full domain name in order to enroll and the cert to be valid.


Are you enrolling locally on your network or the public internet?


If you are enrolling locally, im assuming that servername.local means the hostname of the OSX server. What is the domain / DNS that your iPad is in, and what is the Search Path given from dhcp?


Ex.


DNS zone is work.lab.local, and your server is servername.local. OSX machiens will be able to register to as they dont require the proper FQDN like iOS devices.


In order to test a iOS devices you may want to see if you can append only the serach string of the domain the server is bound to. (ex. servername.local)


If you go a few pages back it has a tutorial I posted on how to re-do everything without reinstalling. I would then recomend putting the OSX machine in the same DNZ zone as everything else so that way users can resolve it properly when it comes time to the cert.

Jul 24, 2012 4:21 PM in response to jgcumming

Can you please provide a screen shot of the error, or state the error message.


iOS have to use the cert inorder to enroll. The cert for OD has to be the same format for FQDN as where the server resides, and that same FQDN has to be where you enroll the devices.


Ex.


DNS Zone: lab.local

Servername: osx-app01.lab.local


OD will have to generate the cert osx-app01.lab.local so profile manager can use it and you can sign your profiles with this cert. Once everythign is said and done, you will enroll at https://osx-app01.lab.local/enroll If all of these paramaters are not correct you will get an error when trying to enroll about the cert saying something about an ota_service is invalid.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Profile Manager Enrollment - iOS - Server Certificate Invalid

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.