I eventually solved the most scep issues by cleaning out all the credentials in the ios configuration profile externally sign ssl.
Now I'm kind of stuck at the profile install process again:
I'm getting a "profile failed to install" the profile mdm enrollment" could not be installed." popup
this popup comes right after the "generating key" , "enrolling certificate" and installing profile text appears.
I do not know if any more than these two (APNS?)certificates should be imported as payload in the credential settings for the IOS enrollment configuration.
the log of the ipad:
Apr 2 00:39:27 iPad sandboxd[1095] <Notice>: Mobile MGMT(1093) deny filewritecreate /private/var/mobile/Applications/0A3FD105F3B8466AA8FF864CB9EEF5AF/Documentsapt
Apr 2 00:39:29 iPad sandboxd[1095] <Notice>: Mobile MGMT(1093) deny filewritecreate /private/var/mobile/Applications/0A3FD105F3B8466AA8FF864CB9EEF5AF/Documentsapt
Apr 2 00:39:31 iPad profiled[1098] <Notice>: (Note ) profiled: Service starting...
Apr 2 00:39:31 iPad profiled[1098] <Notice>: (Note ) MC: Profile com.symantec.mdm.enrollment.{E6FDAE753CBC4E34B53B4950ABF4665B} queued for installation.
Apr 2 00:39:33 iPad profiled[1098] <Notice>: (Note ) MC: Checking for MDM installation...
Apr 2 00:39:33 iPad profiled[1098] <Notice>: (Note ) MC: ...finished checking for MDM installation.
Apr 2 00:39:33 iPad profiled[1098] <Notice>: (Note ) MC: Beginning profile installation...
Apr 2 00:39:38 iPad profiled[1098] <Notice>: (Note ) profiled: Device unlock notification received
Apr 2 00:39:39 iPad kernel[0] <Debug>: AppleKeyStore:Sending lock change
Apr 2 00:39:40 iPad profiled[1098] <Notice>: (Note ) MC: Attempting to retrieve issued certificate...
Apr 2 00:39:40 iPad profiled[1098] <Notice>: (Note ) MC: Issued certificate received.
Apr 2 00:39:41 iPad profiled[1098] <Notice>: (Error) MDM: Cannot Authenticate. Error: NSError:
Desc : A transaction with the server at https://<server dns>/IOSServices/mdm.sync has failed with the status 500.^JUS Desc: A transaction with the server at https://<server dns>/IOSServices/mdm.sync has failed with the status 500.^JDomain : MCHTTPTransactionErrorDomain^JCode : 23001^JType : MCFatalError^JParams : (^J "https://<server dns>/IOSServices/mdm.sync",^J 500^J)
Apr 2 00:39:41 iPad profiled[1098] <Notice>: (Error) MC: Cannot install MDM MDM. Error: NSError:^JDesc : The payload MDM could not be installed.^JSugg : A transaction with the server at https://<server dns>/IOSServices/mdm.sync has failed with the status 500.^JUS Desc: The payload MDM could not be installed.^JUS Sugg: A transaction with the server at https://<server dns>/IOSServices/mdm.sync has failed with the status 500.^JDomain : MCInstallationErrorDomain^JCode : 4001^JType : MCFatalError^JParams : (^J MDM^J)^J...Underlying error:^JNSError:^JDesc : A transaction with the server at https://<server dns>/IOSServices/mdm.sync has failed with the status 500.^JUS Desc: A transaction with the server at https://<server dns>/IOSServices/mdm.sync has failed with the status 500.^JDomain : MCHTTPTransactionErrorDomain^JCode : 23001^JType : MCFatalError^JParams : (^J "https://<server dns>/IOSServices/mdm.sync",^J 500^J)
Apr 2 00:39:41 iPad profiled[1098] <Notice>: (Error) MC: Rolling back installation of profile com.symantec.mdm.enrollment.{E6FDAE753CBC4E34B53B4950ABF4665B}...
Apr 2 00:39:41 iPad profiled[1098] <Notice>: (Error) MC: Installation of profile com.symantec.mdm.enrollment.{E6FDAE753CBC4E34B53B4950ABF4665B} failed with error: NSError:^JDesc : The profile MDM Enrollment could not be installed.^JSugg : The payload MDM could not be installed.^JUS Desc: The profile MDM Enrollment could not be installed.^JUS Sugg: The payload MDM could not be installed.^JDomain : MCProfileErrorDomain^JCode : 1009^JType : MCFatalError^JParams : (^J "MDM Enrollment"^J)^J...Underlying error:^JNSError:^JDesc : The payload MDM could not be installed.^JSugg : A transaction with the server at https://<server dns>/IOSServices/mdm.sync has failed with the status 500.^JUS Desc: The payload MDM could not be installed.^JUS Sugg: A transaction with the server at https://<server dns>/IOSServices/mdm.sync has failed with the status 500.^JDomain : MCInstallationErrorDomain^JCode : 4001^JType : MCFatalError^JParams : (^J MDM^J)^J...Underlying error:^JNSError:^JDesc : A transaction with the server at https://<server dns>/IOSServices/mdm.sync has failed with the status 500.^JUS Desc: A transaction with the server at https://<server dns>/IOSServices/mdm.sync has failed with the status 500.^JDomain : MCHTTPTransactionErrorDomain^JCode : 23001^JType : MCFatalError^JParams : (^J "https://<server dns>/IOSServices/mdm.sync",^J 500^J)
Apr 2 00:39:41 iPad profiled[1098] <Notice>: (Error) MC: Profile com.symantec.mdm.enrollment.{E6FDAE753CBC4E34B53B4950ABF4665B} failed to install with error: NSError:^JDesc : Profile Failed to Install^JSugg : The profile MDM Enrollment could not be installed.^JUS Desc: Profile Failed to Install^JUS Sugg: The profile MDM Enrollment could not be installed.^JDomain : MCInstallationErrorDomain^JCode : 4001^JType : MCFatalError^J...Underlying error:^JNSError:^JDesc : The profile MDM Enrollment could not be installed.^JSugg : The payload MDM could not be installed.^JUS Desc: The profile MDM Enrollment could not be installed.^JUS Sugg: The payload MDM could not be installed.^JDomain : MCProfileErrorDomain^JCode : 1009^JType : MCFatalError^JParams : (^J "MDM Enrollment"^J)^J...Underlying error:^JNSError:^JDesc : The payload MDM could not be installed.^JSugg : A transaction with the server at https://<server dns>/IOSServices/mdm.sync has failed with the status 500.^JUS Desc: The payload MDM could not be installed.^JUS Sugg: A transaction with the server at https://<server dns>/IOSServices/mdm.sync has failed with the status 500.^JDomain : MCInstallationErrorDomain^JCode : 4001^JType : MCFatalError^JParams : (^J MDM^J)^J...Underlying error:^JNSError:^JDesc : A transaction with the server at https://<server dns>/IOSServices/mdm.sync has failed with the status 500.^JUS Desc: A transaction with the server at https://<server dns>/IOSServices/mdm.sync has failed with the status 500.^JDomain : MCHTTPTransactionErrorDomain^JCode : 23001^JType : MCFatalError^JParams : (^J "https://<server dns>/IOSServices/mdm.sync",^J 500^J)
Apr 2 00:39:41 iPad profiled[1098] <Notice>: (Note ) MC: Removing certificate with persistent ID 69646e74000000000000004c
Apr 2 00:40:41 iPad profiled[1098] <Notice>: (Note ) profiled: Idled.
Apr 2 00:40:41 iPad profiled[1098] <Notice>: (Note ) profiled: Service stopping.
The iis log of the mms server states the last http query of the ipad:
2012-04-01 22:38:58 W3SVC1 SRVMMS01AMNL 192.168.203.73 POST /iosservices/SYMC-iOSWebService.aspx - 443 - 77.248.82.190 HTTP/1.1 Mobile%20MGMT/1.4+CFNetwork/548.1.4+Darwin/11.0.0 - - <server dns> 200 0 0 213 1230 1123
2012-04-01 22:39:00 W3SVC1 SRVMMS01AMNL 192.168.203.73 GET /iosservices/MobileLibraryFeedProxy.aspx feedLanguage=en&platformId=04&platformVersion=5.1 443 - 77.248.82.190 HTTP/1.1 Mobile%20MGMT/1.4+CFNetwork/548.1.4+Darwin/11.0.0 - - <server dns> 200 0 0 2165 288 2948
2012-04-01 22:39:27 W3SVC1 SRVMMS01AMNL 192.168.203.73 GET /MobileEnrollment/Symc-IOSEnroll.ASPX - 443 - 77.248.82.190 HTTP/1.1 Mobile%20MGMT/1.4+CFNetwork/548.1.4+Darwin/11.0.0 - - <server dns> 200 0 0 261 235 468
2012-04-01 22:39:27 W3SVC1 SRVMMS01AMNL 192.168.203.73 POST /MobileEnrollment/Symc-IOSEnroll.ASPX - 443 - 77.248.82.190 HTTP/1.1 Mobile%20MGMT/1.4+CFNetwork/548.1.4+Darwin/11.0.0 - - <server dns> 200 0 0 725 1232 124
2012-04-01 22:39:27 W3SVC1 SRVMMS01AMNL 192.168.203.73 GET /mobileenrollment/eula-en.html - 443 - 77.248.82.190 HTTP/1.1 Mobile%20MGMT/1.4+CFNetwork/548.1.4+Darwin/11.0.0 - - <server dns> 200 0 0 565 228 15
2012-04-01 22:39:29 W3SVC1 SRVMMS01AMNL 192.168.203.73 POST /iosservices/SYMC-iOSWebService.aspx - 443 - 77.248.82.190 HTTP/1.1 Mobile%20MGMT/1.4+CFNetwork/548.1.4+Darwin/11.0.0 - - <server dns> 200 0 0 837 1212 78
2012-04-01 22:39:29 W3SVC1 SRVMMS01AMNL 192.168.203.73 GET /iosservices/MobileLibraryFeedProxy.aspx feedLanguage=en&platformId=04&platformVersion=5.1 443 - 77.248.82.190 HTTP/1.1 Mobile%20MGMT/1.4+CFNetwork/548.1.4+Darwin/11.0.0 - - <server dns> 200 0 0 2165 288 171
2012-04-01 22:39:31 W3SVC1 SRVMMS01AMNL 192.168.203.73 GET /MobileEnrollment/MobileConfig.aspx - 443 - 77.248.82.190 HTTP/1.1 Mozilla/5.0+(iPad;+CPU+OS+5_1+like+Mac+OS+X)+AppleWebKit/534.46+(KHTML,+like+Gecko)+Version/5.1+Mobile/9B176+Safari/7534.48.3 - - <server dns> 200 0 0 4165 369 1170
2012-04-01 22:42:42 W3SVC1 SRVMMS01AMNL 192.168.203.73 POST /iosservices/SYMC-iOSWebService.aspx - 443 - 86.80.112.221 HTTP/1.1 Mobile%20MGMT/1.4+CFNetwork/548.1.4+Darwin/11.0.0 - - <server dns> 200 0 0 837 1272 577
2012-04-01 22:42:42 W3SVC1 SRVMMS01AMNL 192.168.203.73 GET /iosservices/MobileLibraryFeedProxy.aspx feedLanguage=nl&platformId=04&platformVersion=5.1 443 - 86.80.112.221 HTTP/1.1 Mobile%20MGMT/1.4+CFNetwork/548.1.4+Darwin/11.0.0 - - <server dns> 200 0 0 6453 288 249
2012-04-01 22:42:43 W3SVC1 SRVMMS01AMNL 192.168.203.73 GET /iosservices/MobileLibraryFeedProxy.aspx feedLanguage=nl&platformId=04&platformVersion=5.1 443 - 86.80.112.221 HTTP/1.1 Mobile%20MGMT/1.4+CFNetwork/548.1.4+Darwin/11.0.0 - - <mms FQDN> 200 0 0 6453 288 312
Where and how should/could I check for the problem now?