Endpoint Security Complete

 View Only
  • 1.  MDM ios5 enrollment

    Posted Nov 25, 2011 08:14 AM

    Hello!


    I made a test environment with newest Symantec Mobile Manager MR1. Didnt installed SP1 for Windows 2008 R2. With SP1 I had problem with installing the profile. Now with new environment(new install of windows) i have problem with connection. When going to Agent, enrolling i got message that Profile installation failed and network connection error occurred. I have iOS 5.0.1. Server is pinging. No errors in Altiris Log Viewer found. I am using the SSL and override. When tried to force http instead of https got error that Safari couldnt install profile. With 4.3.5 everything was fine. I can`t downgrade iOS cause Apple permits it.

    Started a new topic cause it could be different issue.
     



  • 2.  RE: MDM ios5 enrollment

    Posted Nov 27, 2011 07:18 PM

    I found iOS 5 devices wouldn't enroll unless I had an SSL cert for the domain you are enrolling against within IIS that is signed by a CA that the device trusts.

    You might be able to do this with your own internal CA if you install the root CA cert on the device prior to enrollment but I haven't tried this.



  • 3.  RE: MDM ios5 enrollment

    Posted Nov 29, 2011 12:21 PM

    From the previous thread, it looks like your APNS Bundle Identifier is wrong.  You have something like com.symantec.mdm.enrollment.

    It should be com.apple.mgmt.* where * can be whatever.  For example, com.apple.mgmt.mike-mms.prod and com.apple.mgmt.mike-mms.test would be valid APNS bundle identifier.  You will need to recreate the APNS certificate at developer.apple.com to use this format, and then update all APNS settings and steps that you followed previously -- importing the certificate, copying the thumbprint, subject, and so forth.

    Does this help?



  • 4.  RE: MDM ios5 enrollment

    Broadcom Employee
    Posted Mar 18, 2012 05:05 AM

    So far as iOS devices work fine without SSL, and when you turn to SSL to allow iOS 5 devices to enroll this means your server is configured correctly for iOS 4. I have created the below article recently to provide more details on how to  use SSL to allow iOS 5 enrollment, and to automate the process.

    http://www.symantec.com/docs/HOWTO74478