How to Obtain an APNs Certificate for CA MDM



Similar documents
Creating an Apple APNS Certificate

Guide for Generating. Apple Push Notification Service Certificate

APNS Certificate generating and installation

Generating an Apple Push Notification Service Certificate for use with GO!Enterprise MDM. This guide provides information on...

Generating an Apple Enterprise MDM Certificate

Generating the APNs certificate is a three-step process: Download the AirWatch-signed CSR from the AirWatch Admin Console.

Generating an Apple Push Notification Service Certificate

Generating an Apple Push Notification Service Certificate for use with GO!Enterprise MDM. This guide provides information on...

QMX ios MDM Pre-Requisites and Installation Guide

How to generate an APNs Certificate to use the Apple MDM protocol via the portal

CA Mobile Device Management. How to Create Custom-Signed CA MDM Client App

Generating and Renewing an APNs Certificate. Technical Paper May 2012

Zenprise Device Manager 6.1

Sophos Mobile Control Installation guide. Product version: 3

Sophos Mobile Control Installation guide. Product version: 3.5

Mobile Secure Cloud Edition Document Version: ios Application Signing

Sophos Mobile Control SaaS startup guide. Product version: 6

AVG Business SSO Partner Getting Started Guide

Sophos Mobile Control Installation guide

QuickStart Guide for Mobile Device Management

QuickStart Guide for Mobile Device Management. Version 8.6

Kony MobileFabric Messaging. Demo App QuickStart Guide. (Building a Sample Application

Vodafone Secure Device Manager Administration User Guide

Entrust Managed Services PKI. Configuring secure LDAP with Domain Controller digital certificates

Sophos Mobile Control Installation guide. Product version: 3.6

Configuration Guide. BES12 Cloud

Remote Access End User Reference Guide for SHC Portal Access

Getting Started - MDM Setup

Mobility Manager 9.0. Installation Guide

SHC Client Remote Access User Guide for Citrix & F5 VPN Edge Client

Sophos Mobile Control Startup guide. Product version: 3.5

QuickStart Guide for Managing Mobile Devices. Version 9.2

Sophos Mobile Control Startup guide. Product version: 3

e-cert (Server) User Guide For Microsoft IIS 7.0

Apple Push Notification Service (APNS) Creation Guide

EM L12 Symantec Mobile Management and Managed PKI Hands-On Lab

ECA IIS Instructions. January 2005


App Orchestration 2.0

Mobile Device Management Fleet manager s guide. Philippe CAJET Admin Guide MDM R1.6_2013 August 1 st _V 1

Kaspersky Lab Mobile Device Management Deployment Guide

Entrust Managed Services PKI

Install and End User Reference Guide for Direct Access to Citrix Applications

UP L18 Enhanced MDM and Updated Protection Hands-On Lab

App Orchestration 2.5


Entrust Managed Services PKI Administrator Guide

NETWRIX IDENTITY MANAGEMENT SUITE

ManageEngine Desktop Central. Mobile Device Management User Guide

Frequently Asked Questions Enterprise Mobile Manager

Microsoft IIS 7 Guide to Installing Root Certificates, Generating CSR and Installing certificate

BlackBerry Universal Device Service. Demo Access. AUTHOR: System4u

Copyright 2013, 3CX Ltd.

owncloud Configuration and Usage Guide

BlackBerry Enterprise Service 10. Secure Work Space for ios and Android Version: Security Note

Massey University Wireless Network Client Configuration Mac OS X

Shakambaree Technologies Pvt. Ltd.

Dell Mobile Management. Apple Device Enrollment Program

Swisscom Mobile Device Services Quick Start Guide: Set-up Remote Management basic. Mobile Device Services Februar 2014

Device Enrollment Guide

Microsoft Exchange Hosted Archive (MEHA)

1. Introduction Activation of Mobile Device Management How Endpoint Protector MDM Works... 5

Getting Started Guide: Getting the most out of your Windows Intune cloud

Browser-based Support Console

SAP Best Practices for SAP Mobile Secure Cloud Configuration March 2015

Cloud Services MDM. Control Panel Provisioning Guide

TechNote. Contents. Overview. Using a Windows Enterprise Root CA with DPI-SSL. Network Security

BuzzTouch ios Push Notifications

Sophos Mobile Control Installation guide. Product version: 5.1

Building a BYOD Program Using the Casper Suite. Technical Paper Casper Suite v9.4 or Later 17 September 2014

Product Manual. MDM On Premise Installation Version 8.1. Last Updated: 06/07/15

Sophos Mobile Control as a Service Startup guide. Product version: 3.5

System Administration Training Guide. S100 Installation and Site Management

ios Team Administration Guide (Legacy)

Telstra Mobile Device Management (T MDM) Getting Started Guide

Remote Desktop Web Access. Using Remote Desktop Web Access

formerly Help Desk Authority Upgrade Guide

DIGIPASS KEY series and smart card series for Juniper SSL VPN Authentication

Engage ios App Administrator s Guide

Wavecrest Certificate

Administration Guide. BlackBerry Enterprise Service 12. Version 12.0

mystanwell.com Installing Citrix Client Software Information and Business Systems

eschoolpad for ipad INSTALLATION GUIDE v3.0 Prepared by: Avrio Solutions Company Limited

Getting Started with MozyPro Online Backup Online Software from Time Warner Cable Business Class

VMware Identity Manager Connector Installation and Configuration

Security Guide. BlackBerry Enterprise Service 12. for ios, Android, and Windows Phone. Version 12.0

Portal Recipient Guide

Secure IIS Web Server with SSL

VMware Horizon FLEX User Guide

User Manual for Version Mobile Device Management (MDM) User Manual

Scenarios for Setting Up SSL Certificates for View

Marriott Enrollment Server for Web User Guide V1.4

Integrating Cisco ISE with GO!Enterprise MDM Quick Start

The IceWarp SSL Certificate Process

System Area Management Software Tool Tip: Integrating into NetIQ AppManager

IceWarp SSL Certificate Process

3. Viewing and Restoring Items and Files from the Mimosa Archive

Configuration Guide BES12. Version 12.3

Transcription:

How to Obtain an APNs Certificate for CA MDM Contents How to Obtain an APNs Certificate for CA MDM Verify Prerequisites Obtaining Root and Intermediate Certificates Create a Certificate Signing Request Get Your CSR Signed Upload Signed CSR to Apple Push Certificate Portal Complete the CSR and Export the APNs Certificate Upload MDM APNs Certificate to CA MDM Server To manage ios devices using CA MDM, the following certificates are required. An Apple Push Notification Service (APNs) certificate. An Apple, Inc. root certificate. An Apple Application Integration certificate. The apple certificates allow CA MDM to perform the following tasks: To communicate securely with ios devices. Uniquely identify your enterprise CA MDM installation as a trusted vendor for the mobile device management (MDM). Install the certificate for CA MDM operations when an enterprise uses a Macintosh or Windows OS, and the Apple Push Certificates. The Apple Push Certificates Portal obtains the push, root, and application integration certificates.

How to Obtain an APNs Certificate for CA MDM The Apple Push Notification Service (APNs) gives the ability to perform the following tasks securely: Enroll ios Devices in an enterprise environment. Monitor compliance with corporate policies Remotely wipe or lock managed ios Devices. It is important to consider the configuration of your enterprise tenant environment when installing APNs push certificates: System tenant is the machine name where you have installed the CA MDM application. A non-system tenant is a tenant added by the administrator to separate operations or customers. If you are an enterprise using only system tenant, install your Apple push certificate on the system tenant. If you are an enterprise, using multiple tenants to separate operations install your Apple push certificate on the system tenant. If you are a hosting enterprise using multiple tenants to separate multiple customers, ensure each customer installs their own Apple push certificate on their tenant. Do not install a push certificate on the system tenant as it will be used as the backup certificate for tenants that do not have a certificate. To obtain an APNs Certificate for CA MDM, perform the following tasks: 1. Verify Prerequisites 2. Create a Certificate Signing Request 3. Get Your CSR Signed 4. Upload Signed CSR to Apple Push Certificate Portal 5. Complete the CSR and Export the APNs Certificate Verify Prerequisites Verify the following prerequisites before obtaining an APNs certificate: Obtain root and application integration certificates from the Apple Root Certification Authority site. Windows server with administrator rights. Installation of Mozilla Firefox, Safari, or the Google Chrome Web browser. Apple issues Apple ID that is assigned to your enterprise or to you. To associate with the certificates, use the Apple ID.

Note: To obtain an Apple ID, an Apple ios Developer Program membership is not required. Obtaining Root and Intermediate Certificates For each CA MDM environment, obtain the root and application integration certificate. Obtain these certificates so that installation of any APNs certificates has a valid chain to the root. Install the certificates when you install and configure the Enrolment Server for ios operations. 1. Go to the Apple Root Certification Authority site at http://www.apple.com/certificateauthority. 2. Download the Apple Inc. Root Certificate. 3. Download Application Integration. Create a Certificate Signing Request You can create a certificate signing request either on a Windows server or a Macintosh server. Valid on Windows To create your CSR on a Windows server in your enterprise, use the IIS Manager utility. 1. Click Start Internet Information Services (IIS) Manager. 2. Select the server from the Connections column, and navigate to Server Certificates in the IIS section. 3. Click Create Certificate Request and provide the details. Common name defines the name of the person generating the request. 4. Click Save. 5. Select Microsoft RSA SChannel in the Cryptographic Service Provider. 6. Select 2048 or greater Bit length. 7. Enter the file name for the certificate request. 8. Click Finish. The CSR request is created on Windows and is ready for signing. Valid on Macintosh

On any Macintosh server in your enterprise, use the Keychain Access utility to create your CSR. 1. Open Applications Utilities Keychain Access on your server. 2. Select Keychain Login and Category Certificates in the left pane. 3. Select Keychain Access Certificate Assistant Request a Certificate from a Certificate Authority. 4. Enter the email address and common name. 5. Select Save to disk, and Let me specify key pair information, and click Continue. 6. Save the file (.CSR) and record the location. The CSR request is created on Macintosh and is ready for signing. Get Your CSR Signed As a required part of the Apple certificate process, CA Technologies must sign your enterprise CSR. Follow TEC602303 Getting your CSR Signed for APNs Certificate to achieve this. After you obtain the signed CSR, upload the CSR to the Apple Push Certificates Portal to obtain an APNs certificate. Upload Signed CSR to Apple Push Certificate Portal You can install the APNs certificate in CA MDM to authorize the CA MDM-based Apple Push Notification Service requests. To install the APNs certificate, obtain an Apple-signed APNs certificate. 1. Log in to Apple Push Certificates Portal using the following URL: http://identity.apple.com/pushcert. 2. Click Create a Certificate. 3. Read and Accept the End-user License Agreement. 4. Click Choose File and select the signed CSR (.SCSR). 5. Click Upload. A new Apple-signed push certificate for the mobile device appears on the Certificates for the Third-Party Servers page. 6. Click Download.

The certificate is saved in the.pem format. The APNs certificate has been obtained from the Apple Portal. Complete the downloaded certificate on the server that originated the CSR. Complete the CSR and Export the APNs Certificate Complete the request and export the APNs certificate for CA MDM operations on to the Macintosh or Windows Server. Valid on Windows On the Windows server that originated the CSR, complete the request and export the APNs certificate for CA MDM operations. 1. Click Start Administrative Tools Internet Information Services (IIS) Manager. 2. Select the server from the Connections column, and navigate to Server Certificates in the IIS section. 3. Click Complete Certificate Request. 4. Select the.pem certificate that you downloaded from the Apple Push Certificates Portal. 5. Enter a common name for tracking the certificate and click OK. 6. To export the APNs certificate to the correct format, right-click the certificate and select Export. 7. Save the certificate file in.pfx or p12 format. 8. Enter a password, and then click OK. Valid on Macintosh On the Macintosh server that originated the CSR, complete the request and export the APNs certificate for CA MDM operations. 1. On your server, locate the APNs certificate file (.PEM), as downloaded from the Apple Push Certificates Portal. 2. Double-click the.pem file. 3. Select Keychain Login and Category Keys in the Keychain Access utility.

4. Verify that the certificate, that the common name identifies, appears with a key value in the Kind column. 5. Right-click the private key and select Export. 6. Save the file in.p12 or.pfx or p12 format. 7. To export the certificate, enter and note the password. You now have an MDM APNs certificate from Apple that can be added to the CA MDM Server. Upload MDM APNs Certificate to CA MDM Server Once the CSR is completed, export the APNs Certificate to.pfx or p12 format. Later, upload the MDM APNs certificate to CA MDM Server. 1. Log in to the CA MDM Administrator Console, navigate to Server Configuration Component ios Notification. 2. Fill in the details for APNs Push Certificate (for Mobile Device Management). Push Service displays the push service name. For example, com.apple.mgmt.external.22721840-3c25-46bb-b611-c12d51f439ad. File allows you to browse for the certificate file in.pfx or p12 format. Password defines the password that you used during exporting the APNs Certificate. 3. Click Install. The certificate is installed to the personal certificate on the CA MDM Server. The MDM certificate name populates the page. (System tenant) If your Apple root and intermediate certificates are not installed, the interface prompts you to install them. (The nonsystem tenant) If Apple root and intermediate certificates are not installed, the interface opens an error. Notify your system tenant administrator. The MDM APNs certificate is successfully uploaded to the CA MDM Server. You have successfully obtained an APNs certificate to support Apple ios devices.