Profile Manager Enrollment - iOS - Server Certificate Invalid

I have been getting an error trying to enroll iOS devices into profile manager. My MacBook and iMac enroll just fine. However my iPhone and iPad do not.


When I enroll my MacBook Pro, I first log into https://(FQDN)/mydevices, select profiles, Install Trusted Profile. I then go back to devices, and click 'Enroll now'. When I check the Profiles section of System Preferences, I see that the 'Trusted Profile' has added two certificates refering to my server. I can only assume one matches the Self Signed I generated shortly after making my hostname public, and the other Apple Push generated for me.


However when I do this exact same process on my iPad/iPhone, when I attempt the 'Enroll Now' step, I get the error "The server certificate for "https://(FQDN)/devicesmanagement/api/device/ota_service" is invalid.


My searches for this issue have turned up issues close to this, but never exactly this, and the solutions don't seem to work for me. Here are some key points to note:


1. Tried demoting to standalone, re-promote to OD Master, then deleted all certificates, and regenerated all (including the Push cert from Apple)

2. Ran sudo changeip -checkhostname

3. DNS routes forward and reverse correctly in my local LAN

4. I had been getting "Remote Verification failed: (os/kern) failure" / "TEAVerifyCert() returned NULL" in my logs every 3 seconds until I did the steps listed in '1'


Looking forward to 10.7.1

Mac mini, Mac OS X (10.7), Server

Posted on Aug 10, 2011 12:38 PM

Reply
128 replies

Aug 15, 2012 11:40 PM in response to John B Portland

I'm having the same problem here with Mountain Lion Server.


I got my OSX devices enrolled on the profile manager, but my iOS don't want to work.


I logg on my iOS on: server.example.private/mydevices, then I log in with a user profile, not the adminstration one, but either one don't work, then I use the FQDN certificate, that works perfectly, but when I want to enroll my iPhone it says: "The Server certificate for https://server.example.private/devicemanagment/api/device/ota_service" is invalid.


I forwared all the Ports which have been listed before to my server lan ip adress and nothing is working.



I really need help there!

Aug 16, 2012 5:18 AM in response to xynlovesit

The certificate that was created with profile manager and OD have to be the same FQDN. I would suggust to going back earlier in the forumn, I had posted a bunch of steps on how to tare down everythying and rebuild it without re-installing the OS. It takes about 30 minutes.


Your other option would be to generate a RSA key and create a cert out on the internet and import the root CA for the cert and the signed cert from the 3rd party.


As I have not used mountain lion, and propbably wont be upgrading anything that is actually "important" until it is stable. But it seems to me like they pulled the Vista / Windows 7 trick with Lion / Mountain Lion. Im guessing the same issues are happening with the certs no matter if its 10.8 or 10.7 as everything needs certs now, and they have to be done correctly in order to get it to work.

Sep 13, 2012 4:41 AM in response to John B Portland

My question follows on this thread but is somewhat different in that all my certs show valid on my new iphone once installed but the phone itself is not passing data to the PM.


What I get is New Device and the owner plus transfer of serial but thats it. The task starts to update settings but locks and wont continue.


On the other hand it will let me download the profiles so it works fine but just wont let me set it up automatically and wont let me wipe the phone etc.


Any thoughts/ help on the matter would be appreciated

Sep 14, 2012 12:11 PM in response to Perpetually Perplexed

Do you have the firewall enabled on the OSX server or do you have a firewall between the mobile devicdes your trying to enroll and the server?


What version of OSX are you running. I know 10.7.3 was fairly stable with profile manager, I had to rebuild our production server on tuesday as someone let filemaker logs crash the OS drive and it scrwed up authentication modules when trying to log in the wiki / profile manger. I will be able to vouch for 10.7.4 hopefully shortly.


Have you tried going on 3G / 4G to see if you can enroll / sync with the server? I have also seen some issues with our wireless network with older iOS devices, as I have a older iPhone and sometimes when I push something out it will take a little bit to get pushed (maybe a few hours). Other devices like the iPhone4 will get pushed much faster. I dont know if its something to do with the Aruba Controller or if it just has issues when pushing at peak hours.

Nov 13, 2012 12:53 AM in response to John B Portland

Hello


The enroll for my iOS Devices is okay, but i have now the problem how can make a push to a device that are not in my local net?


Example: When i send a push "LOCK" to a device that are not in my local network it's outside (3G), then i see the task in the Profilmanager (Active Tasks).


All tasks that i try in my local net are going. What i need it open ports on my router or settings on my server?


I hope i find here a answer


Thank you very much


Greeting

Roger

Nov 13, 2012 5:33 AM in response to John B Portland

@burton11234


Yes i have open this TCP-Ports: 2195, 2196 and 5223 and make a forwarding to my server.


I don't know is it purhaps my hostname a problem (server.domain.private), is this only for inside my local net and not for outside (internet)?


Must re-install my server for a offical domain like "myname.com" and so also a new Apple certificate for this domain (myname.com)? And then i must make the enroll over the internet with the domain (myname.com)?


Greeting

Nov 13, 2012 11:30 PM in response to John B Portland

Thank you very much for the feedback. I see the best way is when i re-install my mini server and then i make it with offical domain like 'myname.com' and open all the ports 2195, 2195, 5223, 1640 and 443. So i can make first the enroll over the offical domain and after that i can also send push to my devices, if the device inside my net and if it outside.


Greeting

Roger

Nov 14, 2012 7:13 AM in response to John B Portland

@burton11234


Thank you very much for the help.


Now i have re-install my server and now everthing works, perfect!


Is this right ...


Port: 1640 and 443 is only for enroll over the internet


Port: 2195, 2196 and 5223 is only for push over the internet


If i want make the enroll only in my local net, then i can close the ports 1640 and 443, but for the push over the internet i will need the ports 2195, 2196 and 5223?


If this right and i want make the enroll in my local net, then i must use (http://myname.com/mydevices) that it's works, but how can do that with my Url (myname.com), i think it will going outside over the internet and then it's not going because the ports (1640, 443) are closed, but i want use the url only in my local net. Is this possible?


I type in my local net http://myname.com/mydevices it will go directly to ip of my local server and not over the internet.


Greeting

Roger

Nov 14, 2012 7:31 AM in response to rogerodermatt

Your welcome!


In a nutshel yes thats how it would work, but then in the end its all about DNS. If you have myname.com dns zone in your production dnz server and the dns record myname.com points to your internal IP of the osx server then it will only go inside. If you change that DNS record to the public IP and the nat rule your using is not using the same public IP (only in cases that port forwarding are used and you have 1 public IP) then it will work as well.


Otherwise if you want to test the public connection you could go on 3g and test that way. If ports 443 is open and your on 3g you will be able to hit the URL. If the port 443 is closed and your on 3g it wont work. Port 1640 is used for SCEP which is basically the process of the certificates getting pushed down so your device is a trusted device.


As everything with profile manager and mobile devices is all related to FQDN's and Certificates.

Nov 4, 2013 4:12 PM in response to John B Portland

I, too, have been experiencing this issue and have never got the profile manager working properly until yesterday. I'm on a home network with mavericks server running on a mac mini, although I had the same issue with Lion and I passed on Mountain Lion.


After several clean installs, and failed enrollments on iphones, ipod touches and macbook airs I noticed an error message saying something about the hostnames for the certs not matching.


I then remembered that the first thing I did after a clean install was create the OD and later changed the hostname to server.local.


When the os is installed, both the computer name and host name are "server" only, so I did ANOTHER clean install and the first thing I did was make the hostname server.local and THEN create the OD, which in turn creates the self-signed cers, but this time with the matching hostname.


It worked like a champ and every device in the house enrolled in profile manager first try 😮


I hope you get the same mileage, good luck !!


p.s. I found out you can do a clean install from a time machine backup in about 10 minutes, rather than 50 minutes or so if you have the mavericks installer on a thumb drive. That took a lot of the pain away too 🙂

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Profile Manager Enrollment - iOS - Server Certificate Invalid

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.