ios - MDM Server certificate to be used for SSL handshake with iPhone device -
i trying perform ssl handshake between iphone device , mdm server. have used iphone configuration utility (ipcu) , configured scep , mdm. scep works fine, device receives issued certificate ca.
in mdm payload, have used subject of apns certificate in topic , entered server ip port 1234. identity, have used identity of scep certificate.
the iphone generates key , enrolls successfully, when tries install profile contacting mdm server, receive error in ipcu console: the server certificate https://[ip here]:1234 invalid
in mdm server application programmed using c#.net complains authenticationexception:the sspi has failed because context has expired , can no longer used. question is, certificate should have on mdm server - mdm certificate received ios provision portal, apple push certificate of customer or certificate of scep server?
if answer question, grateful have spent hours , can't figure out.
when ios device registering mdm service, needs know talking correct server. mdm server's ssl certificate helps this. certificate other web service certificates , have cn (common name) name used in url ios device uses enroll in mdm service. example, if mdm enrollment url https://mymdmservice.mydomain.com cn mymdmservice.mydomain.com.
the mdm service's certificate signing chain needs recognized mobile device. in particular, use certificate issued 1 of usual registrars (e.g., verisign or comodo).
you can use self-signed certificate, have add device's trusted root certificate store (see http://fixmyitsystem.com/2012/01/install-corporate-pki-root-ca-on-ios.html).
Comments
Post a Comment