lloydo

Q: Can't Enrol Devices to MDM via DEP

Hi, I've just finished setting up a Mac Mini running OS Server purely for our companies MDM solution. We're enrolled with Apple for DEP and have around 35 devices at the moment that I can't setup.

 

So at the moment I have an SSL certificate from GoDaddy which is used to secure the services. I also have a code signing certificate which is not install whatsoever as I can't work out how you do so. <-- not sure if it has anything to do with my issue.

 

The devices automatically detect that they belong to the company, I go through the setup process but when it comes to "This devices is managed by XXX" Download configuration" I get an error on the next screen failed to download configuration from server. In the log in Apple Configurator I get the following messages:

 

May 24 04:01:46 iPad profiled[249] <Error>:  SecTrustEvaluate  [leaf AnchorTrusted]

May 24 04:01:46 iPad Setup[255] <Error>:  SecTrustEvaluate  [root AnchorTrusted]

May 24 04:01:46 iPad Setup[255] <Notice>: (Error) MC: <MCHTTPRequestor: 0x1282105c0> failed to communicate to the server. Error: NSError:

  Desc   : The operation couldn’t be completed. (NSURLErrorDomain error -1012.)

  Domain : NSURLErrorDomain

  Code   : -1012

  Extra info:

  {

     NSErrorFailingURLKey = "https://osxserver.frontiermedical.uk/devicemanagement/api/device/dep_mdm_enroll";

     NSErrorFailingURLStringKey = "https://osxserver.frontiermedical.uk/devicemanagement/api/device/dep_mdm_enroll";

  }

May 24 04:01:46 iPad Setup[255] <Error>:  SecTrustEvaluate  [root AnchorTrusted]

 

Every device I've run I get this message. I have my Mac Mini connected straight through to the DMZ and have access to all the required ports and is accessible from the static IP and hostname above from outside world.

 

I've also tried using Apple Configurator to enrol & setup devices and get the exact same message.

 

Please help!!! I've come to wits end.

Mac mini, Mac OS X (10.7.3), 2.7GHz i7 - 8GB - 256GB SSD - 6630M

Posted on May 24, 2016 4:09 AM

Close

Q: Can't Enrol Devices to MDM via DEP

  • All replies
  • Helpful answers

  • by Strontium90,

    Strontium90 Strontium90 May 24, 2016 5:01 AM in response to lloydo
    Level 5 (4,067 points)
    Servers Enterprise
    May 24, 2016 5:01 AM in response to lloydo

    Don't have a solution but have many suggestions where to look.

     

    The error message suggests that you can not reach the server.  Are you sure all ports are open?  1640, 2195, 2196, 5223, 443, 1640?  Is Profile Manager setup properly for DEP Management?  Have you imported your DEP token?  Does Profile Manager show your devices?  Do you have a proxy on your network?  Try Push Diagnostics from TwoCanoes (https://itunes.apple.com/us/app/push-diagnostics/id689859502?mt=12) to validate that you are not blocking push.  If the mini is on the DMZ do the LAN devices have access to that node?  As a test, if you put another device on the DMZ next to the server does it work? 

     

    Reid

    Apple Consultants Network

    Author - "El Capitan Server – Foundation Services"

    Author - "El Capitan Server – Control & Collaboration"

    Author - "El Capitan Server – Advanced Services"

    :: Exclusively available in Apple's iBooks Store

  • by lloydfrompontllanfraith,

    lloydfrompontllanfraith lloydfrompontllanfraith May 24, 2016 6:54 AM in response to Strontium90
    Level 1 (4 points)
    May 24, 2016 6:54 AM in response to Strontium90

    Thanks for the advice, all of the ports are open. For testing purposes I've even disable every firewall from the Server to the Internet so there is no possibility of firewall issues there.

     

    Profile manager shows the placeholders which have been imported from DEP but they're just placeholders and not actually realising the device is trying to enrol.

    I've just tried putting another Wi-Fi iPad in the DMZ and I still get the same error I've tried them tethered to my iPhone also so they're not on the same LAN.

     

    Thanks again! - really stuck with this one.

  • by lloydo,

    lloydo lloydo May 24, 2016 7:43 AM in response to Strontium90
    Level 1 (10 points)
    Servers Enterprise
    May 24, 2016 7:43 AM in response to Strontium90

    Thanks for the advice, all of the ports are open. For testing purposes I've even disable every firewall from the Server to the Internet so there is no possibility of firewall issues there.

     

    Profile manager shows the placeholders which have been imported from DEP but they're just placeholders and not actually realising the device is trying to enrol.

    I've just tried putting another Wi-Fi iPad in the DMZ and I still get the same error I've tried them tethered to my iPhone also so they're not on the same LAN.

     

    Thanks again! - really stuck with this one.

  • by bubbaglia,

    bubbaglia bubbaglia Jun 14, 2016 1:32 AM in response to lloydfrompontllanfraith
    Level 1 (4 points)
    Servers Enterprise
    Jun 14, 2016 1:32 AM in response to lloydfrompontllanfraith

    Same problem here!

    If I use the OD Self signed certificate it works. There is some problems with certificates on DEP?

  • by lloydo,

    lloydo lloydo Jun 14, 2016 1:35 AM in response to bubbaglia
    Level 1 (10 points)
    Servers Enterprise
    Jun 14, 2016 1:35 AM in response to bubbaglia

    Hi there, working alongside apple enterprise support we finally got to a solution.

     

    It seems like they needed to do something from their end. Once that was done we completely reinstalled OS X and Server redownloaded the SSL certificate and installed it first then made sure hostnames & DNS was setup correctly, then finally turned on profile manager. They wanted it done in that order when it came to reinstalling... Hopefully that helps you like it did for me!

  • by Der Petersen,

    Der Petersen Der Petersen Jul 13, 2016 7:50 AM in response to lloydo
    Level 1 (8 points)
    Servers Enterprise
    Jul 13, 2016 7:50 AM in response to lloydo

    we have the same problem here ...

    i think i have to do so too ... will take a look