How to Obtain an APNs Certificate for CA MDM Contents How to Obtain an APNs Certificate for CA MDM Verify Prerequisites Obtaining Root and Intermediate Certificates Create a Certificate Signing Request Get Your CSR Signed Upload Signed CSR to Apple Push Certificate Portal Complete the CSR and Export the APNs Certificate Upload MDM APNs Certificate to CA MDM Server To manage ios devices using CA MDM, the following certificates are required. An Apple Push Notification Service (APNs) certificate. An Apple, Inc. root certificate. An Apple Application Integration certificate. The apple certificates allow CA MDM to perform the following tasks: To communicate securely with ios devices. Uniquely identify your enterprise CA MDM installation as a trusted vendor for the mobile device management (MDM). Install the certificate for CA MDM operations when an enterprise uses a Macintosh or Windows OS, and the Apple Push Certificates. The Apple Push Certificates Portal obtains the push, root, and application integration certificates.
How to Obtain an APNs Certificate for CA MDM The Apple Push Notification Service (APNs) gives the ability to perform the following tasks securely: Enroll ios Devices in an enterprise environment. Monitor compliance with corporate policies Remotely wipe or lock managed ios Devices. It is important to consider the configuration of your enterprise tenant environment when installing APNs push certificates: System tenant is the machine name where you have installed the CA MDM application. A non-system tenant is a tenant added by the administrator to separate operations or customers. If you are an enterprise using only system tenant, install your Apple push certificate on the system tenant. If you are an enterprise, using multiple tenants to separate operations install your Apple push certificate on the system tenant. If you are a hosting enterprise using multiple tenants to separate multiple customers, ensure each customer installs their own Apple push certificate on their tenant. Do not install a push certificate on the system tenant as it will be used as the backup certificate for tenants that do not have a certificate. To obtain an APNs Certificate for CA MDM, perform the following tasks: 1. Verify Prerequisites 2. Create a Certificate Signing Request 3. Get Your CSR Signed 4. Upload Signed CSR to Apple Push Certificate Portal 5. Complete the CSR and Export the APNs Certificate Verify Prerequisites Verify the following prerequisites before obtaining an APNs certificate: Obtain root and application integration certificates from the Apple Root Certification Authority site. Windows server with administrator rights. Installation of Mozilla Firefox, Safari, or the Google Chrome Web browser. Apple issues Apple ID that is assigned to your enterprise or to you. To associate with the certificates, use the Apple ID.
Note: To obtain an Apple ID, an Apple ios Developer Program membership is not required. Obtaining Root and Intermediate Certificates For each CA MDM environment, obtain the root and application integration certificate. Obtain these certificates so that installation of any APNs certificates has a valid chain to the root. Install the certificates when you install and configure the Enrolment Server for ios operations. 1. Go to the Apple Root Certification Authority site at http://www.apple.com/certificateauthority. 2. Download the Apple Inc. Root Certificate. 3. Download Application Integration. Create a Certificate Signing Request You can create a certificate signing request either on a Windows server or a Macintosh server. Valid on Windows To create your CSR on a Windows server in your enterprise, use the IIS Manager utility. 1. Click Start Internet Information Services (IIS) Manager. 2. Select the server from the Connections column, and navigate to Server Certificates in the IIS section. 3. Click Create Certificate Request and provide the details. Common name defines the name of the person generating the request. 4. Click Save. 5. Select Microsoft RSA SChannel in the Cryptographic Service Provider. 6. Select 2048 or greater Bit length. 7. Enter the file name for the certificate request. 8. Click Finish. The CSR request is created on Windows and is ready for signing. Valid on Macintosh
On any Macintosh server in your enterprise, use the Keychain Access utility to create your CSR. 1. Open Applications Utilities Keychain Access on your server. 2. Select Keychain Login and Category Certificates in the left pane. 3. Select Keychain Access Certificate Assistant Request a Certificate from a Certificate Authority. 4. Enter the email address and common name. 5. Select Save to disk, and Let me specify key pair information, and click Continue. 6. Save the file (.CSR) and record the location. The CSR request is created on Macintosh and is ready for signing. Get Your CSR Signed As a required part of the Apple certificate process, CA Technologies must sign your enterprise CSR. Follow TEC602303 Getting your CSR Signed for APNs Certificate to achieve this. After you obtain the signed CSR, upload the CSR to the Apple Push Certificates Portal to obtain an APNs certificate. Upload Signed CSR to Apple Push Certificate Portal You can install the APNs certificate in CA MDM to authorize the CA MDM-based Apple Push Notification Service requests. To install the APNs certificate, obtain an Apple-signed APNs certificate. 1. Log in to Apple Push Certificates Portal using the following URL: http://identity.apple.com/pushcert. 2. Click Create a Certificate. 3. Read and Accept the End-user License Agreement. 4. Click Choose File and select the signed CSR (.SCSR). 5. Click Upload. A new Apple-signed push certificate for the mobile device appears on the Certificates for the Third-Party Servers page. 6. Click Download.
The certificate is saved in the.pem format. The APNs certificate has been obtained from the Apple Portal. Complete the downloaded certificate on the server that originated the CSR. Complete the CSR and Export the APNs Certificate Complete the request and export the APNs certificate for CA MDM operations on to the Macintosh or Windows Server. Valid on Windows On the Windows server that originated the CSR, complete the request and export the APNs certificate for CA MDM operations. 1. Click Start Administrative Tools Internet Information Services (IIS) Manager. 2. Select the server from the Connections column, and navigate to Server Certificates in the IIS section. 3. Click Complete Certificate Request. 4. Select the.pem certificate that you downloaded from the Apple Push Certificates Portal. 5. Enter a common name for tracking the certificate and click OK. 6. To export the APNs certificate to the correct format, right-click the certificate and select Export. 7. Save the certificate file in.pfx or p12 format. 8. Enter a password, and then click OK. Valid on Macintosh On the Macintosh server that originated the CSR, complete the request and export the APNs certificate for CA MDM operations. 1. On your server, locate the APNs certificate file (.PEM), as downloaded from the Apple Push Certificates Portal. 2. Double-click the.pem file. 3. Select Keychain Login and Category Keys in the Keychain Access utility.
4. Verify that the certificate, that the common name identifies, appears with a key value in the Kind column. 5. Right-click the private key and select Export. 6. Save the file in.p12 or.pfx or p12 format. 7. To export the certificate, enter and note the password. You now have an MDM APNs certificate from Apple that can be added to the CA MDM Server. Upload MDM APNs Certificate to CA MDM Server Once the CSR is completed, export the APNs Certificate to.pfx or p12 format. Later, upload the MDM APNs certificate to CA MDM Server. 1. Log in to the CA MDM Administrator Console, navigate to Server Configuration Component ios Notification. 2. Fill in the details for APNs Push Certificate (for Mobile Device Management). Push Service displays the push service name. For example, com.apple.mgmt.external.22721840-3c25-46bb-b611-c12d51f439ad. File allows you to browse for the certificate file in.pfx or p12 format. Password defines the password that you used during exporting the APNs Certificate. 3. Click Install. The certificate is installed to the personal certificate on the CA MDM Server. The MDM certificate name populates the page. (System tenant) If your Apple root and intermediate certificates are not installed, the interface prompts you to install them. (The nonsystem tenant) If Apple root and intermediate certificates are not installed, the interface opens an error. Notify your system tenant administrator. The MDM APNs certificate is successfully uploaded to the CA MDM Server. You have successfully obtained an APNs certificate to support Apple ios devices.