Symantec Mobile Device Management 7.1 Proof of Concept - Part III: Obtaining and Installing an Apple APNS Certificate For a Mobile Management 7.1 Proof of Concept
Warning
THIS WALKTHROUGH is PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE WALKTHROUGH IS WITH YOU. SHOULD THE WALKTHROUGH PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION.
Generating an APNS Certificate Request (Symantec Mobile Management 7.1 User Guide, 2011, p. 38)
Note: In addition to hardware requirements and software requirements, you must meet the following requirements before you can set up and install a Mobile Device Management certificate:
- Be a member of the iOS Developer Enterprise Program. You can sign up for membership of the OS Developer Enterprise Program at the following URL: http://developer.apple.com/programs/ios/enterprise/
- Have a Mobile Device Management agreement. You must contact Apple directly to acquire the agreement. The agreement allows your iOS Developer Enterprise Program membership to send MDM commands through the Apple Push notification service.
- Open IIS Manager by clicking Start > Administrative Tools > Internet Information Services (IIS) Manager
- When IIS Manger opens click on servername
- In the center pane, double click on Server Certificates
- In the right hand pane click on Create Certificate Request…
- On the Distinguished Name Properties page fill in the following information and click Next:
- Common Name: servername.domain.com
- Organization: CompanyName
- Organizational Unit: DepartmentName
- City/locality: CityName
- State/province: StateName
- Country/region: CountryName
- On the Cryptographic Service Provider Properties, in the Cryptographic service provider drop-down menu, select Microsoft RSA SChannel Cryptographic Provider, and page change the Bit Length to 2048 and click Next
- On the File Name page specify the file name for the certificate request (ie. AppleCertRequest.txt) and click Finish
Setting Up an App ID and Download an APN Certificate (Symantec Mobile Management 7.1 User Guide, 2011, pp. 38 - 39)
- Open your web browser (not Internet Explorer) and browse to https://developer.apple.com/ios/manage/bundles/howto.action
- Enter your credentials:
- Apple ID: AppleID
- Password: password
- Click on Sign In
- On the iOS Provisioning Portal page click on App IDs.
- Click on the New App ID button on the top right hand side of the page.
- Description: Type a description
- Bundle Identifier (App ID Suffix): com.apple.mgmt.XXX, where XXX is a string added by you, ie your company name. Note: com.apple.mgmt is mandatory.
- Click Submit.
- Click on the Manage Tab.
- At the bottom right hand side of the page, under Action, click on Configure.
- On the Configure App ID page place a check beside Enable for Apple Push Notification Service.
- Beside Production Push SSL Certificate click on Configure.
- On the Generate a Certificate Signing Request page click Continue.
- On the Submit Certificate Signing Request page browse to your APNS certificate request (.ie AppleCertRequest.txt) and then click Generate.
- On the Generating your Apple Push Notification service SSL Certificate page, click Continue.
- On the Download & Install Your Apple Push Notification service SSL Certificate page, click Download.
- Click Done.
Completing the Certificate Request (Symantec Mobile Management 7.1 User Guide, 2011, p. 40)
- On the Start menu, click Control Panel.
- On the All Control Panel Items page, click Administrative Tools.
- On the Administrative Tools page, click Internet Information Services(IIS) Manager.
- On the Internet Information Services (IIS) Manager page, in the left pane, click the server, and then in the center pane, double-click Server Certificates.
- In the right pane, click Complete Certificate Request.
- In the Specify Certificate Authority Response dialog box, navigate to the Apple Push Notification service SSL certificate you have created and downloaded, under Friendly name, specify a name, ie. APNS Certificate.
- Click OK.
- Open Microsoft Management Console
- Click Start > Run
- Type in mmc and click OK
- When the MMC opens click on File > Add/Remove Snap-in…
- On the left hand column choose Certificates, click on Add.
- When Certificates snap-in opens choose Computer account and then click on Next.
- When Select Computer opens accept the defaults and click on Finish.
- Click OK.
- Right click on the newly imported APNS Certificate and choose All Tasks > Manage Private Keys.
- When the Security page opens click on the Add… button.
- Type Network Service and click Check Names.
- When the Security page is shown again click on Network Service, uncheck Full Control and click OK.
Exporting the MDM Certificate and Installing it on Multiple MDM Servers (Symantec Mobile Management 7.1 User Guide, 2011, p. 41)
Note: This step is only necessary if you have more than one MDM server. If so, you need to perform this step and then install the certificate on each MDM server.
- Select the Server Certificate with the friendly name that you specified in step 6 of the previous section.
- In the right pane, click Export.
- In the Export Certificate dialog box, specify a filename and location for where to export the MDM Certificate, ie MDM Certificate.pfx. Then specify a password to secure the MDM Certificate.
- Click OK.
- Open Microsoft Management Console
- Click Start > Run
- Type in mmc and click OK
- When the MMC opens click on File > Add/Remove Snap-in…
- On the left hand column choose Certificates, click on Add.
- When Certificates snap-in opens choose Computer account and then click on Next.
- When Select Computer opens accept the defaults and click on Finish.
- Click OK.
- Browse to Console Root > Certificates > Personal > Certificates.
- In the middle pane, right click on the white space and choose All Tasks > Import…
- On the Welcome to the Certificate Import Wizard page click on Next.
- On the File to Import page click Browse and browse to the location of the MDM Certificate.
Note: When you get to the folder that contains the MDM Certificate you will have to choose Personal Information Exchange (*.pfx, *.p12) for the file type to see the certificate.
- Click on the APNS file and click Open.
- On the File to Import page click on Next.
- On the Password page type the password used to export the certificate and then click Next.
- On the Certificate Store page accept the defaults and click Next.
- On the Completing the Certificate Import Wizard page click Finish.
- When the Certificate Import Wizard success notification pops up click on OK.
- Right click on the newly imported MDM Certificate and choose All Tasks > Manage Private Keys.
- When the Security page opens click on the Add… button.
- Type Network Service and click Check Names.
- When the Security page is shown again click on Network Service, uncheck Full Control and click OK.
Part II: Installing Mobile Management 7.1 For a Mobile Management 7.1 Proof of Concept
Part IV: Installing and Configuring SCEP For a Mobile Management 7.1 Proof of Concept
Part V: Configuring Mobile Management 7.1 For a Mobile Management 7.1 Proof of Concept
Comments 1 Comment • Jump to latest comment
There is a new APNS process for obtaining an APNS certificate.
To request Symantec certificate signing:
Generate a certificate signing request (CSR) on your MMS server or a Windows 2003/2008 server.
1. To generate a certificate request
1 Select Start > Control Panel > Administrative Tools.
2 Select Internet Information Services (IIS) Manager.
3 Select the server, and then double-click Server Certificates.
4 On the Actions menu, click Create Certificate Request.
Enter the following information:
■ Common Name – Use the FQDN of your MMS server
■ Organization - The name of your organization.
■ Organizational unit - The name of the group or department within your organization
■ City/locality - The city or locality where your organization is located.
■ State/province - The state or province where your organization is located.
■ Country/region - The country or region where your organization is located.
5 Click Next.
6 In the CryptographicServiceProviderProperties window, select Microsoft
RSA SChannel Cryptographic Provider for the Cryptographic service
provider. Select 2048 for the Bit length.
7 Click Next. In the File Name window, type a file path and name or click the
ellipsis button to browse.
8 Click Finish to generate and save the certificate request. It will be saved as a.txt file.
Send the certificate request to your partner and they will obtain an APNS certificate for you.
Once you have the signed CSR from Symantec, use Safari or Chrome, (Firefox may also work) as your web-browser, do not use Internet Explorer.
Cameron Mottus
Would you like to reply?
Login or Register to post your comment.