Profile installation failed.

I am getting this error on Lion when trying to register my device on the Lion server using the MyDevices page. I have already installed the trust certificate as well as the Everyone profile. I then proceed to the Devices tab and click on the Register button, but get this error in the process:


Profile installation failed.

The profile "Remote Management (come.apple.config.rocking-mm.private.mdm)" could not be installed due to an unexpected error.


Any ideas how to resolve this?


Thanks!

~Mike

Mac mini, Mac OS X (10.7.1), 8GB RAM

Posted on Aug 27, 2011 5:33 PM

Reply
20 replies

Dec 5, 2011 1:38 PM in response to Stress Test

Unfortunally when you use the push certs from apple, they generate a cert from the FQDN and if that FQDN doesn't match the cert for Open Directory then profile manager will cause issues.


Best thing would be to export open directory so you can save everything first, blow it away by telling it its a standalone server, change the hostname and fqdn, make sure both forward and reverse lookups are working and then setup open directory, and regenerate the certs for the push, and setup profile manager.


You then can import your records from open directory.


Profile manager is really picky on the certs, and it gets upset if certs are not consistent between the push and OD.


Hope this helps for future references!!!

Aug 28, 2011 7:43 PM in response to Miggl

I made some "progress" on this issue. I put it in quotes, because it's not really a solution, but a work-around:


Basically, for these to work you need to do a clean install of Lion on your machine. If you migrate data and user settings, it appears to break the functionality.


I had originally migrated right off the bat, and couldn't get it to connect properly. However, after doing a clean reinstall (erase harddrive partition and reinstall from recovery partition), it worked on the first try.


Between this and the many, many other issues and speedbumps that come with Lion Server, it doesn't surprise me that it only costs $50. I would like to see all the issues addressed, and a truly plug-and-play server emerge (maybe around 10.7.5 or so, who knows) where everything works as advertised and without complicated setup processes. I do believe that Lion Server could be something great, but it's just too riddled with issues at the moment.

Sep 12, 2011 1:27 AM in response to Miggl

I have a similar problem. I have a 2011 Mac Mini Server and a 2010 MBP 15". I was just trying to set up both with profile manager and was able to successfully enroll the MBP without too much difficulty. I am using a self-signed certificate, so I downloaded the Trust Profile and then enrolled the MBP. But when I went back over to the server, installed the Trust Profile, and then tried to try to enroll it, I got the following error:


"Profile Installation Failed. The certificate for this server is invalid. You might be connecting to a server that is pretending to be “server.flyer05.private” which could put your confidential information at risk."


Based on my understanding of certificates, since I am only going to be using this server for my own home use and as a VPN to connect to my home network when traveling, it seems unnecessary to pay for a CA-signed certificate, and I'd like to avoid the added unnecessary expense if I can. Does anyone have any suggestions for how to deal with this issue?

Sep 12, 2011 6:56 AM in response to Miggl

Miggl wrote:

Profile installation failed.

The profile "Remote Management (come.apple.config.rocking-mm.private.mdm)" could not be installed due to an unexpected error.


Same here 😟


Server was a clean install, and no upgrade from Snow Leopard.


Error Logs from Console.app:


12.09.11 15:48:04,361 com.apple.UserEventAgent-System: Sep 12 15:48:04 <servername> ProfileManager[5346] <Info>: CertUpdateHandler.run: replace/etc/certificates/MDM SCEP SIGNER.2AC3B0163956D237FCB1CF208CA5B9EBE28528BF.cert.pem0x00/etc/certificates/M DM SCEP SIGNER.0E1A80185764011A7C5CDE7E4880C26ADFF02C30.cert.pem0x00

12.09.11 15:48:04,492 com.apple.UserEventAgent-System: /usr/libexec/certupdate/certupdate_devicemgr.sh: line 30: exit: result: numeric argument required

12.09.11 15:48:20,455 com.apple.UserEventAgent-System: *** Error: certificate path does not exist: /etc/certificates/MDM SCEP SIGNER.0E1A80185764011A7C5CDE7E4880C26ADFF02C30.cert.pem



and a second error message:


12.09.11 15:55:28,217 System Preferences: *** ERROR *** [CPInstallerUI:501] Profile installation (Entfernte Verwaltung (com.apple.config.serverbook.test.intern.mdm)) (Checkin 'Authenticate' failed: 0 <InternalError:1>)

Sep 12, 2011 7:34 AM in response to Jager2247

Jager,


From what I am understanding you are saying, is that you have a server and a client machine. You were able to set up the MBP (client) in Profilemanager without issue, but you also want to register the server in Profilemanager.

As far as I am aware, this is not a supported configuration, as you would be registering the server with itself.

Dec 2, 2011 11:00 AM in response to Miggl

Miggi


No need for a clean install, the issues you described are cert issues bassed upon your OD setup and certs from apple for the push services.


If you need to destroy profile manager you can run this command and it will blow away everything in profile manager so its like starting over.


sudo /usr/share/devicemgr/backend/wipeDB.sh


Once that command is run, you can demote your OD server.


Change the hostname to the proper hostname you have and make sure you can do forward / reverse lookups.


Once you can, renew your push certs so they have the new hostname, and go into profile manager and chose configure, once you configure it, it will setup OD for you under the proper hostnames.


Once your OD hostname / Intermediate_CA Cert matches the hostnames on the push services, you should be able to download the trust profile and enroll.


I hope this helps!

Feb 18, 2013 9:01 AM in response to SteffNL

When enrolling wiht a mac, are you using the shorname or the FQDN? I would recomend using the FQDN that the cert has in it, as that could cause issues.


Another peice of info... I had our production server crash due to disk space, which I used profile manager for mac's only on this specific host. After the crash, I was forced to rebuild as specific services woudln't allow AD authentication to take place. I had exported the db for profile manager and re-imported it and it was corrupted.


I have never had issues exporting the collab db (wiki) and wiki calenders even with the funky permissions as it has to be re-imported back into collab.


Due to the impact of having to either re-enrolll all devices that were lost I decided to go back to legacy mode with work group maanger. I had decided that it was best to use workgroup maanger for any MAC's. It is much easier to export open directory and re-import it then having to muck wiht databases from profile maanger. Some of the things I have tried to deploy with profile manager wern't successful including profiles for 802.1x auth for wifi.


So for what proflie manager was really used for on the MAC's it wasn't worth it to put more devices on it incase of an issue in the future.

Feb 19, 2013 12:59 AM in response to burton11234

OSX 10.7 Server has a simple internet domainname such as server.domainname.com. I connect to that webserver running Profile Manager, login with the user credentials (not the admin's) and simply click 'Enroll' .


Download of ota_profile.mobileconfig and opes up System Preferences. The information in the profile shows the full FQDN and shows the certificate is 'Verified'. (I have the Trust Profile installed)


After all of this I still get the 'Profile installation failed' error. "Could not be installed due to an unexpected error". I'll try build up another server, see how this works out. Anyone perhaps know this is a glich in 10.7 and should I go for 10.8?

Feb 19, 2013 6:29 AM in response to SteffNL

What version of 10.7 are you running. I didn't seem to have any major issues once I got it working wiht earlier releases of 10.7.


Normally the issues occur with iOS devices and macs are fine. Its odd your seeing so many issues with your mac. Can you do forward / reverse lookups of server.domainname.com from the client machines? Do you have any firewall policies applied between clients and the host?

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Profile installation failed.

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.