Creating an Apple APNS Certificate



Similar documents
How to Obtain an APNs Certificate for CA MDM

Generating an Apple Push Notification Service Certificate for use with GO!Enterprise MDM. This guide provides information on...

Guide for Generating. Apple Push Notification Service Certificate

APNS Certificate generating and installation

Generating an Apple Push Notification Service Certificate for use with GO!Enterprise MDM. This guide provides information on...

Mobile Secure Cloud Edition Document Version: ios Application Signing

QMX ios MDM Pre-Requisites and Installation Guide

Generating an Apple Enterprise MDM Certificate

Generating an Apple Push Notification Service Certificate

Zenprise Device Manager 6.1

CA Mobile Device Management. How to Create Custom-Signed CA MDM Client App

Mobility Manager 9.0. Installation Guide

Kaspersky Lab Mobile Device Management Deployment Guide

How to generate an APNs Certificate to use the Apple MDM protocol via the portal

Generating the APNs certificate is a three-step process: Download the AirWatch-signed CSR from the AirWatch Admin Console.

Cloud Services MDM. Control Panel Provisioning Guide

e-cert (Server) User Guide For Microsoft IIS 7.0

ECA IIS Instructions. January 2005

QuickStart Guide for Mobile Device Management

EM L12 Symantec Mobile Management and Managed PKI Hands-On Lab

AVG Business SSO Partner Getting Started Guide

QuickStart Guide for Mobile Device Management. Version 8.6

Sophos Mobile Control Installation guide. Product version: 3.5

Generating and Renewing an APNs Certificate. Technical Paper May 2012

Sophos Mobile Control Installation guide

Sophos Mobile Control Installation guide. Product version: 3

Entrust Managed Services PKI. Configuring secure LDAP with Domain Controller digital certificates

Mobile Device Management Fleet manager s guide. Philippe CAJET Admin Guide MDM R1.6_2013 August 1 st _V 1

ManageEngine Desktop Central. Mobile Device Management User Guide

Configuration Guide. BES12 Cloud

Kony MobileFabric Messaging. Demo App QuickStart Guide. (Building a Sample Application

Deploying iphone and ipad Mobile Device Management

Cloud Services MDM. ios User Guide

Remote Desktop Services

How to install and use the File Sharing Outlook Plugin

Sophos Mobile Control SaaS startup guide. Product version: 6

SHC Client Remote Access User Guide for Citrix & F5 VPN Edge Client

Browser-based Support Console

Preparing for GO!Enterprise MDM On-Demand Service

Sophos Mobile Control Installation guide. Product version: 3.6

Sophos Mobile Control Startup guide. Product version: 3.5

App Orchestration 2.5

Vodafone Secure Device Manager Administration User Guide

Sophos Mobile Control Startup guide. Product version: 3

QuickStart Guide for Managing Mobile Devices. Version 9.2

The IceWarp SSL Certificate Process

IceWarp SSL Certificate Process



Office of Information Technology Connecting to Microsoft Exchange User Guide

BlackBerry Enterprise Service 10. Secure Work Space for ios and Android Version: Security Note

Product Manual. MDM On Premise Installation Version 8.1. Last Updated: 06/07/15

1. Introduction Activation of Mobile Device Management How Endpoint Protector MDM Works... 5

Building a BYOD Program Using the Casper Suite. Technical Paper Casper Suite v9.4 or Later 17 September 2014

GO!Enterprise MDM Device Application User Guide Installation and Configuration for ios Devices

Mobile Device Management AirWatch Enrolment ios Devices (ipad, iphone, ipod) Documentation - End User

MaaS360 Mobile Device Management (MDM) Administrators Guide

QUANTIFY INSTALLATION GUIDE

McAfee Enterprise Mobility Management 12.0 Software

Windows and MAC User Handbook Remote and Secure Connection Version /19/2013. User Handbook

INSTALLING YOUR SSL CERTIFICATE ON THE FILEHOLD SERVER ON WINDOWS 2008 X64 ON IIS 7

DESLock+ Basic Setup Guide Version 1.20, rev: June 9th 2014

Certificates for computers, Web servers, and Web browser users

Certificate Management for your ICE Server

App Orchestration 2.0

Advanced Configuration Steps

Your First App Store Submission

Installing an SSL Certificate Provided by a Certificate Authority (CA) on the BlueSecure Controller (BSC)

Remote Access End User Reference Guide for SHC Portal Access

Getting Started Guide: Getting the most out of your Windows Intune cloud

Simplifying Device Enrollment and Content Distribution Using the Device Enrollment Program, the Volume Purchase Program, and the Casper Suite

Getting Started. with VitalSource Bookshelf. How to Access your ebooks Using VitalSource Bookshelf

Getting Started - MDM Setup

EM L05 Managing ios and Android Mobile Devices with Symantec Mobile Management Hands-On Lab

Sophos UTM. Remote Access via PPTP Configuring Remote Client

setup information for most domains hosted with InfoRailway.

Configuration (X87) SAP Mobile Secure: SAP Afaria 7 SP5 September 2014 English. Building Block Configuration Guide

Secure IIS Web Server with SSL

Mobility Manager 9.5. Users Guide

USING SSL/TLS WITH TERMINAL EMULATION

Novell Filr. Mobile Client

BuzzTouch ios Push Notifications

WHITE PAPER Citrix Secure Gateway Startup Guide

Centrify Cloud Management Suite

Telstra Mobile Device Management (T MDM) Getting Started Guide

Intel vpro Technology. How To Purchase and Install Symantec* Certificates for Intel AMT Remote Setup and Configuration

Architecture and Data Flow Overview. BlackBerry Enterprise Service Version: Quick Reference

Microsoft IIS 7 Guide to Installing Root Certificates, Generating CSR and Installing certificate

Sophos Mobile Control as a Service Startup guide. Product version: 3.5

GO!Enterprise MDM Device Application User Guide Installation and Configuration for ios with TouchDown

Installing Windows Server Update Services (WSUS) on Windows Server 2012 R2 Essentials

EM L18 Managing ios and Android Mobile Devices with Symantec Mobile Management Hands-On Lab

WatchDox Administrator's Guide. Application Version 3.7.5

SSL Management Reference

etoken Enterprise For: SSL SSL with etoken

Copyright 2013, 3CX Ltd.

Using Microsoft s CA Server with SonicWALL Devices

CONNECT-TO-CHOP USER GUIDE

Transcription:

Creating an Apple APNS Certificate 4/20/2012 Creating an Apple APNS Certificate Created by Britt Womelsdorf Edited by Mark S. Ciminello, MBA, PMP The purpose of this document is to outline the steps necessary to create and acquire an Apple Push Notifications Service ( APNS ) Certificate to enable Apple ios MDM capabilities for SAP customers in Afaria.

Creating an Apple APNS Certificate C R E A T I N G T H E A P P L E C E R T Contents OVERVIEW... 2 Mobile Device Management in ios... 2 Afaria and the Apple Push Notification Service... 2 Certificate Creation Process... 3 CREATE CERTIFICATE REQUEST... 4 Generating an APNS Certificate Request on a Windows Server... 4 SIGNING THE CERTIFICATE REQUEST... 8 OBTAINING THE APNS CERTIFICATE FROM APPLE... 10 Upload SCRS file to Apple... 10 Obtaining the additional Apple Root and Intermediate Certificates to be used with the new APNS Certificate... 13 COMPLETING THE CERTIFICATE REQUEST... 14 Completing the CSR on a Windows Server Using IIS Manager... 14 INSTALLING THE CERTIFICATES ON THE AFARIA SERVER... 19

OVERVIEW The purpose of this document is to create an Apple certificate ( cert ) that can be used with Afaria to enable Apple Push Notifications ( APNS ) within the Afaria environment. The Apple APNS cert is required by Afaria to communicate with the device while it interacts with the Afaria device client. Mobile Device Management in ios Mobile Device Management ( MDM ) such as Afaria gives businesses the ability to manage large scale deployments of ios devices, including the iphone, ipad and even the ipod. This provides the ability for Afaria to securely enroll devices in an enterprise environment, wirelessly configure and update settings, monitor compliance with corporate policies, and remotely wipe or lock managed devices, and other controls. SAP Afaria Server Most management functions are completed behind the scenes with no user interaction required. For example, if you wanted to update your VPN infrastructure for example, the Afaria server can configure your ios devices with new account information over the air. The next time VPN is used, the appropriate configuration is already in place, so the employee doesn t need to call the help desk or manually modify settings. Afaria and the Apple Push Notification Service When the Afaria server wants to communicate with any ios device such as an iphone, ipad, or even a wifi-capable ipod 1, a silent notification is sent to the device via the Apple Push Notification service, prompting it to check in with the server. The process of notifying the device through this service does not actually send any proprietary information to or from the Apple Push Notification service. The only task performed by the push notification is to wake the device so it checks in with the Afaria server. All configuration information, settings, and queries are sent directly from the server to the ios device over an encrypted SSL/TLS connection between the device 1 Applies to select models of ipods.

and the Afaria server. Apple ios handles all Afaria requests and actions in the background to limit the impact on the user experience, including battery life, performance, and reliability. In order for the push notification server to recognize commands from the Afaria server, a certificate must first be installed on the server. This certificate must be requested and downloaded from the Apple Push Certificates Portal. Once the APNS certificate is uploaded into the Afaria server, devices can begin to be enrolled. For more information on requesting an Apple Push Notification certificate for MDM, visit www.apple.com/business/mdm. Certificate Creation Process To use MDM, you ll need to install an SSL certificate obtained from Apple on your MDM server. This certificate enables your server to securely communicate with the Apple Push Notification service. Requesting a certificate is simple and free. Follow these instructions to get started: 1. Create Certificate Request. SAP will generate the initial signed Certificate Signing Request (CSR). SAP will sign a customer s CSR and deliver it to the customer. 2. Obtain APNS Certificate. Once you have a signed CSR from SAP, upload the signed Certificate Request field and download a Certificate file with a valid Apple ID. 3. Complete the Certificate. Complete and export the certificate as a certificate file. 4. Load Certificate into Afaria. This certificate can now be uploaded to Afaria for use with the Apple Push Notification service. The following sections walk you through the steps required to generate the APNS certificate required by Apple.

CREATE CERTIFICATE REQUEST This section outlines the steps necessary to initiate the certificate request. Important: You will need to ensure that you are installing the certificate on the same server that you generated the CSR on for successful association of the private key that was created during the CSR process. Generating an APNS Certificate Request on a Windows Server Click on the Start Menu, go to Administrative Tools, and click on Internet Information Services (IIS) Manager. Click on the name of the server in the Connections column on the left.

Under the IIS section in the center window pane, double-click Server Certificates. In the Actions column on the right, click on Create Certificate Request...

On the Distinguished Name Properties window, enter the following information: Click on Next. Common Name. The name of the person generating the request (any name can be entered into this field). Organization. The legal name of your organization. Organizational Unit. The division of your organization handling the certificate (Most CAs don t validate this field). City/Locality. The city where your organization is located. State/province. The state/region where your organization is located. Country/Region. The two-letter ISO code for the country where your organization is located.

The Request Certificate dialog box is displayed. Leave the default Cryptographic Service Provider (Microsoft RSA...). Increase the Bit Length to 2048 or higher. Click Next. Click the button with the three dots and enter a location and filename where you want to save the CSR file. Click Finish. The file is typically in the format *.txt.

SIGNING THE CERTIFICATE REQUEST An Apple APNS Certificate must be signed by a Mobile Device Management vendor. This process may only be addressed by an SAP Solution Engineer having a valid Sybase Frontline Support ID. Go to the Sybase web site for Frontline Support (http://frontline.sybase.com). Sign in using your Technical Support ID. Click on Apple CSR Signing and then Browse. Find your CSR request file, select it, and then click on Upload and Sign.

Your file will be signed immediately, and you can now download the signed certificate request file. Click on Download Signed Certificate Signing Request (SCSR) and download the file to your desktop. The file downloaded will be in the file format *.scsr.

OBTAINING THE APNS CERTIFICATE FROM APPLE In this section, you will take the signed CSR file, upload it to the Apple web site for Push Notifications, and download the resulting APNS certificate. Upload SCRS file to Apple In a web browser, go to the Apple Push Certificates Portal website at https://identity.apple.com/pushcert. Note: 1. This can be any valid Apple ID. This doesn t have to be an Apple ID associated with an Apple Developer Account. 2. This process does not work in Internet Explorer, it is recommended you use Chrome or Safari Sign in using your Apple ID and password.

After you are logged in, select the Create a Certificate button. Be sure to read the Terms of Use and accept the End User License Agreement. Select the Choose File button to browse to the.scsr file provided by Sybase. Select the Upload button.

If successfully uploaded, the MDM certificate will be displayed on the Certificates for Third-Party Servers screen. This screen is where all certificates issued under the logged in Apple ID will be displayed. Select the Download button to receive the Apple certificate. The obtained certificate will be in *.pem format. You can now log out of the Apple Push Certificates Portal.

Obtaining the additional Apple Root and Intermediate Certificates to be used with the new APNS Certificate The new APNS certificate obtained from the Apple Push Certificates Portal requires a different Root and Intermediate certificate than the APNS certificate you obtain from the Apple Developer Portal. To obtain these new certificates, in a web browser, go to http://www.apple.com/certificateauthority In the Apple Root Certificates section, download the Apple Inc. Root Certificate. In the Apple Intermediate Certificates section, download the Application Integration (AAICA) certificate.

COMPLETING THE CERTIFICATE REQUEST You can complete the Certificate Request either through Windows Server or through a Mac. Completing the CSR on a Windows Server Using IIS Manager Copy the.pem certificate file to the Windows Server. Click on the Start Menu, go to Administrative Tools, and click on Internet Information Services (IIS) Manager.

The IIS Manager is displayed. Click on the name of the server in the Connections column on the left. Double-click on Server Certificates. In the Actions column on the right, click on Complete Certificate Request...

The Complete Certificate Request dialog box is displayed. Click the button with the three dots and select the.pem certificate that you received from the Apple Push Certificates Portal. If the certificate doesn t have a.cer file extension, select to view all types. Enter a friendly name you want so you can keep track of the certificate on this server. Click OK.

If successful, you will see the certificate in the list. If you receive an error stating that the request or private key can t be found, make sure you are using the correct certificate and that you are installing it to the same server that you generated the CSR on. Now, you need to export the APNS certificate to the correct format. Right-click the certificate you just imported and select Export.

Click the button with the three dots to specify a path to save the certificate file in.pfx format. When exporting the certificate, you are required to enter a password used for exporting the certificate. (Don t forget the password) Now, you should have the certificate in.pfx format. Proceed to the section titled Instructions for Installing Certificates on the Afaria Server to complete the process.

www.sap.com INSTALLING THE CERTIFICATES ON THE AFARIA SERVER Launch the Afaria Console and navigate to the Server Component ios Notification Tab: Click on Browse, and then navigate to the.pfx certificate created in the previous step, enter the.pfx password and then click on Install:

Once the certificate has successfully uploaded, restart the Afaria Service: Once the Afaria Service, it is recommended that you validate the certificate by enrolling a single ios device and sending a remote lock command. (Remote Wipe if it is your co-workers phone)