Newsroom Update

Beginning in May, a special Today at Apple series titled “Made for Business” will offer small business owners and entrepreneurs free opportunities to learn how Apple products and services can support their growth and success. Learn more >

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Can't install enrollment profiles, logs show complaints about failed membership check for opendirectory group

Clean install of Yosemite. Using self-signed certificates, turned on Profile Manager, downloaded Trust Profile and created an enrollment profile from the web interface. Fails in Apple Configurator.

So I go to the /mydevices/ page manually on the iPad, log in and click "Enroll", but I get a 500 internal server error. Click on Profiles and try to install the enrollment profile (trust profile went through fine with Apple Configurator), but I'm then told it can't connect to the server.


Check the logs and I see this (domain removed):

14/11/14 11:18:22,671 xscertd-helper[999]: Authentication challenge password request failed authorization for (domain removed)$ as record failed membership check for opendirectory group

14/11/14 11:18:22,672 xscertd[998]: AuthenticateChallengePasswordRequest returned error

14/11/14 11:18:22,698 xscertd[998]: Request from 127.0.0.1:49628 failed, returning Failure (ChallengePassword Authenticate) status

14/11/14 11:18:22,701 php-fpm[527]: do_dmx_get_scep_challenge_for_host: caught exception -[SCEPHelper getSCEPChallengeForHost:] (/SourceCache/RemoteDeviceManagement/RemoteDeviceManagement-883.16/Compiled/Fra mework-Base/Support/SCEPHelper.m:76): "'((SCEPHELPER_GetSCEPChallenge(self.connection, hostname, hostnameCnt, &challenge, &challengeCnt)))' error 1"


Anybody have any idea what might be wrong here?

Posted on Nov 14, 2014 2:21 AM

Reply
6 replies

Feb 24, 2015 6:27 AM in response to Christian Arild Strømmen

I had the same problem but found the problem and solution.


I joined my network's windows Active Directory domain AFTER setting up the server and OpenDirectory. As a result the Open directory was looking for (computer name).local instead of (computer name).domain.local


So every time you tried to enroll, profile manager would go to (computer name).domain.local to check your authentication and fail because it couldn't find it.


To solve it I deleted the master and recreated it (since I had joined the domain). Worked like a charm.

Can't install enrollment profiles, logs show complaints about failed membership check for opendirectory group

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.