Configuring Symantec Mobile Management to require SSL
|Article:TECH201102|||||Created: 2012-12-21|||||Updated: 2013-09-09|||||Article URL http://www.symantec.com/docs/TECH201102|
You want to use SSL to secure communication in your network. To do so, you must configure Symantec Mobile Management to require SSL for network communication.
Symantec Mobile Management 7.2
- All Mobile Management Site-servers and Notification Servers have trusted SSL certificates installed and enabled in their IIS bindings. Note: Do not require SSL at this point. See http://symantec.com/docs/HOWTO53002 for the SSL and bindings set up steps.
- For each server, the subject of each certificate matches the fully-qualified domain name (FQDN) that is used to communicate with that server.
- All devices can communicate and trust the IIS SSL certificate that is installed on the Mobile Management Site-server(s).
The Symantec Management Platform and Agents must be configured to communicate using SSL:
- The Symantec Management Platform is set up to use SSL for communication. See http://symantec.com/docs/HOWTO53002
- All Symantec Management Agents are installed using HTTPS and that they can access the Symantec Management Platform Notification Server using HTTPS. See http://symantec.com/docs/HOWTO62932
Configure SSL for targeted Symantec Management Agents
- In the Mobile Management console, go to Settings > Agents/Plug-ins > Symantec Management Agent.
- Expand Settings.
- Select Symantec Management Agent Settings – Targeted.
- Select All Site Servers.
- Click the Advanced tab and change the URL of the Notification Server to https.
- Go to REGEDIT > REGIDIT > hkey local machine > software > altiris > altiris agent > servers.
- Click server FQDN, then change the registry key Web value to enable https.
- Restart the Symantec Management Agent service.
The Mobile Management Site-Server must be configured to communicate using SSL:
- All communication between Notification Servers and Mobile Management Site-server(s) are set to use HTTPS. If necessary, force server communications to use HTTPS. See http://symantec.com/docs/TECH201766
- All device-to-Mobile Management Site-server(s) communication is set to use HTTPS. The use of HTTPS between mobile devices and the Mobile Management Site-server is typically required. See http://symantec.com/docs/TECH201766
Apply Require SSL IIS setting
Note: See http://symantec.com/docs/HOWTO53002 for more information about this procedure.
- Open IIS, select the Sites folder and right-click Default Web Site.
- In the dialog, click SSL Settings and select Require SSL.
- Click Apply in the action panel.
- Open a Command Prompt window and run iisreset to restart the IIS service.
When finished configuring SSL, restart the Symantec Mobile Management Service Agent, Symantec iOS Command Service, Symantec APNS Service, and Symantec Android Command Service on the Mobile Management Site-server.
Article URL http://www.symantec.com/docs/TECH201102