APNS Certificate generating and installation Quick Guide for generating and installing an Apple APNS Certificate Version: x.x
MobiDM Quick Guide for APNS Certificate Page 1 Index 1. APPLE APNS CERTIFICATE... 2 2. REQUEST A CERTIFICATE... 3 2.1 ROOT CERTIFICATE REQUIRED... 3 2.2 WINDOWS SERVER 2003... 5 2.3 WINDOWS SERVER 2008... 6 2.4 MAC OS X... 7 3.0 SIGNING THE CERTIFICATE... 8 3.1 UPLOAD THE CERTIFICATE TO APPLE... 8 4.0 INSTALLING THE CERTIFICATE... 10 4.1 WINDOWS SERVER 2003... 10 4.2 WINDOWS SERVER 2008... 11 4.3 MAC OS X... 12 5.0 ADDING THE CERTIFICATE TO MOBIDM... 13 5.1 PARTNER... 13 5.2 CUSTOMER... 14 6.0 RENEWING AN APNS CERTIFICATE... 15
MobiDM Quick Guide for APNS Certificate Page 2 1. Apple APNS Certificate ios devices can be securely enrolled and managed for the entire enterprise with the use of MobiDM. Apple uses a technology within the ios operating system to connect to a deployment server and push settings and Apps to the devices. To do this the deployment server requires a so-called Apple Push Notification Service certificate (APNS for short). This APNS certificate needs to be installed on the deployment server of the organization. Each organization needs to obtain its own APNS certificates. This document contains the information to generate an APNS certificate and import it in the MobiDM portal. Before you continue make sure you have: - Full Administrator permissions - A free Apple ID account
MobiDM Quick Guide for APNS Certificate Page 3 2. Request a Certificate 2.1 Root Certificate Required Important! Apple root certificate is required before installing the APNs certificate. The new APNS certificate obtained from the Apple Push Certificates Portal requires a different Root and Intermediate certificate than the APNS certificate you obtain from the Apple Developer Portal. To obtain these new certificates, in a web browser, go to http://www.apple.com/certificateauthority. In the Apple Root Certificates section, download the Apple Inc. Root Certificate. In the Apple Intermediate Certificates section, download the Application Integration (AAICA) Certificate. Note: When you download the certificates on the Mac, you will be given an option to install them right away. Tick all three of the checkboxes and click on add. The certificate is now installed.
MobiDM Quick Guide for APNS Certificate Page 4 For Windows: Launch MMC console (Start > Run > MMC) Add snap-in for certificates (select Computer account for type of certificate) Select Certificates > Trusted Root Certification Authorities > Certificates Import the Apple, Inc. Root Certificate and import the Application Integration (AAICA) certificate Now you are ready to request an APNS Certificate.
MobiDM Quick Guide for APNS Certificate Page 5 2.2 Windows Server 2003 Open the Internet Information services (IIS) manager. Inside the manager right click on the Default Website in the left pane. Select the option Properties from the dropdown menu. Warning: It isn t possible to create a certificate, if the Default Website already contains a certificate. Create a new website if you want to create an APNS certificate. Next select the tab Directory Security and click the button Server certificate. Click Next and select the option Create a new certificate Click Next to continue. The only option available in the next screen is to: Prepare the request now, but send it later. Go to Next to continue. Provide a name for the certificate request and choose a bit length of 2048.
MobiDM Quick Guide for APNS Certificate Page 6 In the next step provide information about your organization and organizational unit. If other certificates already exist, this information may already be available in the dropdown lists of this screen. The next few screens require various details about the organization the certificate is to be generated for. They are self-explanatory. The Geographical Information screen in this process requires the name and location of the certificate request file. This is the text file that will be generated and used by de APNS certificate generation process. Select a location to store this CSR file on the computer. The last screen shows the details that have been entered. Check if they are correct. If not use the Back Button to go back and change the details. Warning: When you have completed the steps above a "pending request" will be created in IIS. This "pending request" must not be deleted. Later, when your certificate is signed, you must install the certificate to this exact pending request or the certificate will not be functional. 2.3 Windows Server 2008 Enter the configuration screen of the Internet Information Services (IIS). In the management screen scroll down to the topic IIS and select Server Certificates. Double click this icon and a new window will open. Existing certificates are listed in the overview. On the top right, select the menu option Create Certificate request. Fill in the various fields in the DNP screen. These details are needed to identify the certificate later in the process. Press Next.
MobiDM Quick Guide for APNS Certificate Page 7 In this Cryptographic Service Provider Properties page, set the Cryptographic Provider Service to Microsoft RSA SChannel Cryptographic Provider and the Bit Length to 2048. Click Next to complete the last step of this procedure. This last step will create a text file containing all the information for generating the new APNS certificate. Choose a location where this text file will be stored. This file is needed when the APNS certificate is generated from the Apple developer site. Now click Finish and this text file will be created. 2.4 Mac OS X First generate a Certificate-signing request. On the Mac, go to Applications->Utilities- >Keychain Access. Select the login Keychain from the left sidebar and choose Certificates from the Category pane. From the top menu select the consecutive options; Keychain Access, Certificate Assistant and lastly Request a Certificate From a Certificate Authority. Next the Certificate Assistant screen opens. It will ask you to enter the User Email Address and the Common Name. Use the name and email address of your Apple ID. Select save to disk to save the request as a file or select Emailed to the CA to sent the CSR directly to the Certificate Authority. In this case enter the email address: support@mobidm.com and click Continue to complete the procedure. A text file is now created to request the APNS certificate.
MobiDM Quick Guide for APNS Certificate Page 8 3.0 Signing the Certificate The certificate request now needs to be signed by a certificate signing authority. If in the previous step the option Emailed to CA was chosen and an email address provided an email will already have been generated. If not, send the text file created in the previous step to support@mobidm.com with the request to sign this certificate request. After Sybase has signed it the MobiDM support desk will return the signed request as an attachment by email. Store the file returned from support in a known location. This will be uploaded to the Apple portal in the next step. MobiDM Support will return a signed certificate request by email within 24 hours on a business day. 3.1 Upload the Certificate to Apple Now you can upload the Intermediate Certificate to the Apple Push Certificate Portal. You will need an Apple ID to login. If you haven t done so already please register with Apple first. Go to https://appleid.apple.com/cgi-bin/webobjects/myappleid.woa/ and register a free Apple ID. Next open the Apple Push Certificate Portal website: https://identity.apple.com/pushcert/ and login with the AppleID. Once logged in click the button Create a certificate.
MobiDM Quick Guide for APNS Certificate Page 9 Tick the box confirming you have read the license agreement. And click Accept. Next browse to the certificate request file received from MobiDM support and click Upload. The APNS certificates will now be generated. When the new APNS certificate is created, a new screen is show with an option to download the certificate. Download the certificate and store it preferably on the location on the same computer the request was generated from.
MobiDM Quick Guide for APNS Certificate Page 10 4.0 Installing the Certificate 4.1 Windows Server 2003 As before, open the Internet Information services (IIS) manager and again, right click on the Default Website in the left pane. Select the option Properties from the drop-down menu. Select again the Directory security tab and press the button Server Certificate. The screen now shows the next step in the procedure. Select the option Process the pending request and install the certificate. And click Next twice. Select "Processing the pending request and install the certificate." to continue installing the certificate(s). The next step provides a screen to enter the name and location of the generated APNS certificate Enter in the file location and details or browse to the file and click Next. Specify the SSL port to be used and click Next again. This last screen shows an overview of the details of the certificate. Check if everything is correct, if not go back and correct it. If all is correct press Next. The certificate will now be installed on your server. When installation has completed, the last screen is shown. Press Finish to complete the procedure. Return to the Internet Information Services Manager (IIS) and right click on the Default Website. Select the Properties option from the drop-down menu. Select the tab Directory Security and click the Server Certificate button. Select Export the current certificate to a.pfx file and click Next.
MobiDM Quick Guide for APNS Certificate Page 11 Browse to the path where the.pfx file is to be stored and click Next. Enter a password for the certificate file to be exported and click Next. Check the details in the next screen and click Next or Back if details need to be changed. Finally click Finish to complete the export procedure. The certificate is now ready to be imported in the MobiDM Portal. 4.2 Windows Server 2008 Return to the IIS management screen and double click again on Server Certificates. In the actions screen click the option Complete certificate request. To complete the certificate request select the next menu item from the Actions menu Complete Certificate Request. Next browse to the downloaded certificate. Enter a recognizable name for the certificate and press Ok to complete the process. The certificates are now available to be used by the deployment server. Return to the Internet Information Services Manager (IIS). Open the Server Certificates as before. Select the APNS Certificate and choose the option Export from the Actions Panel. Enter or browse to a path where the exported certificate needs to be stored. Also provide a password and click Ok to export the certificate. The certificate is now ready to be imported in the MobiDM Portal.
MobiDM Quick Guide for APNS Certificate Page 12 4.3 Mac OS X After the certificate has been downloaded, Double-click on the file *.cer to upload it to Keychain Access. Click Ok to add it to a keychain to complete the signing request. To check if the certificate has been installed, return to the Keychain Access. Select Login in the top left panel of the screen (Keychains). Select certificates in the left bottom panel of the screen (Categories). The main panel shows a list of the installed certificates. See example below. Click the small triangle on the left of the entry to expand the certificate and see the installed private key. Next the certificate needs to be exported and uploaded in the Portal. Select from the menu File the option Export. Enter a name for the exported certificate and a location to store it. Click Save to save the exported certificate. The certificate is now ready to be imported in the MobiDM Portal.
MobiDM Quick Guide for APNS Certificate Page 13 5.0 Adding the Certificate to MobiDM 5.1 Partner Select the correct customer in the context tree. Select the second object in the Navigation panel Customers. Select the desired customer in the customer overview screen en click Edit. The Edit customer screen will open. On the bottom left of this screen is a panel Certificates. Click New to add a certificate. In the next screen enter a name for the certificate, the password of the certificate and browse to the exported certificate file you created earlier. Click Save to upload the certificate to the server and complete the procedure. Warning messages about the requirement to upload a certificate for ios devices will no longer appear. Congratulations, you have successfully uploaded the APNS Certificate in MobiDM.
MobiDM Quick Guide for APNS Certificate Page 14 5.2 Customer You can also upload the APNS certificate as a customer. Log in to the portal. On the top right you ll see the username and customer. Click Edit next to the name of your customer. The Edit customer screen will open. On the bottom left of this screen is a panel Certificates. Click New to add a certificate. In the next screen enter a name for the certificate, the password of the certificate and browse to the exported certificate file you created earlier. Click Save to upload the certificate to the server and complete the procedure. Warning messages about the requirement to upload a certificate for ios devices will no longer appear. Congratulations, you have successfully uploaded the APNS Certificate in MobiDM.
MobiDM Quick Guide for APNS Certificate Page 15 6.0 Renewing a Certificate The APNS certificate will expire after one year. Therefore it is important to renew the certificate before this happens. Make sure to keep track of the certificate s expiration date, so the certificate can be renewed before it expires. The process of renewing a certificate is almost the same as creating a new certificate. Follow the guide above until you log in to the Apple Push Certificates Portal. Note: Use the same AppleID that was used when the certificate was first created. An overview of all the certificates currently managed is shown. You can select the Renew button next to the certificate currently being used by MobiDM. When prompted, click on Browse and select the new certificate you have created. Click Upload to update the certificate. After this you can follow the guide again to install this new certificate in MobiDM.