Mailing Lists: Apple Mailing Lists
Image of Mac OS face in stamp
Lion Server OTA profile management: Device enrollment fails with bad cert
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Lion Server OTA profile management: Device enrollment fails with bad cert



Lion Server, all Apple updates, no funny stuff.
Brand new iPad2 with iOS 4.3.3.

I originally set up my Lion test server with one cert, then found I had to change its name, so I used the server to generate another self-signed cert.  (It's just a test server, I'll do a proper cert when it's all working.)  In Server.app I was able to do

list on the left, pick my server under HARDWARE
Settings tab
SSL Certificate
Edit... button
select my cert from the list there

When I select 'Custom' it shows this new cert being used for all the things it lists: iCal/iChat/Mail/Web even though I'm not using most of those.  The new cert functions fine for all those services.  However, there's no mention of profile management in that list.

In Server.app I have profile manager turned on.  For testing purposes I have not ticked "Sign configuration profiles".

On the iPad2 I can go to the /mydevices/ URL to register the device.  In the Devices tab I can see a big blue 'Enroll' button underneath 'This iPad'.  It takes me to the correct pane in the Settings app, but when I click 'Install' it shows this error:

The server certificate for "https://[myserver]/devicemanagement/api/device/ota_service"; is invalid.

I can't see any way to tell the profile manager which cert to use.  I have found a log file on the server called profilemanager.log which is obviously reporting things relating to the error, but I can't find any command-line tool that's related to it.

Similar error message when I try to register a Mac running Lion instead of an iPad2.  But I don't really want to register that Mac, I'm just using it for testing.

Simon.
 _______________________________________________
Do not post admin requests to the list. They will be ignored.
Macos-x-server mailing list      (email@hidden)
Help/Unsubscribe/Update your Subscription:

This email sent to email@hidden



Visit the Apple Store online or at retail locations.
1-800-MY-APPLE

Contact Apple | Terms of Use | Privacy Policy

Copyright © 2011 Apple Inc. All rights reserved.