ios mdm更新应用_更新过期的iOS MDM配置文件

So I set up the SCEP server to generate an iOS identity certificate which is only valid for a short time. When it expires the profile says "This profile has expired. Update this profile for a newer version", and presents an "Update Profile" button.

However clicking this button simply tells me "Profile could not be updated. Please contact your networks Administrator". No attempt is made to contact either the MDM service or the SCEP service, and no indication of any MDM activity or errors appear in the log.

Enrolling the device again works fine, so I don't suspect calling a network administrator is actually a solution. So how do you update an expired MDM profile?

解决方案

I worked with MDM more than a year ago. So, I could be wrong with some details.

Here is what I remember:

a) Device does two SCEP calls for OTA MDM.

Look at this diagram

First SCEP call is done as part of OTA Certificate Enrollment (phase 2 on the diagram)

And second SCEP call is done when OTA delivers profile with MDM and SCEP payload (as phase 3 on the diagram).

One thing which isn't not obvious from your question which of iOS identify certificate is short living.

b) If your MDM identity has expired, you will stop receiving all MDM commands.

c) If you OTA identity has expired, you can't upgrade any of configurations wich your delivered over the air (as example MDM).

If you have access to Apple Enterprise Developer Program, you can find MDM document in there. It will say that if you did OTA MDM, you need to Update it when it's about to expire.

And as I remember, if your OTA + MDM has expired then you are screwed (you don't have any other option than reenrollment).

BTW. I believe it's common practice to make these identities quite long living (exactly because of these problems).

If you are worried that you can't prevent somebody from receiving updates, you can always:

Send wipe command

Remove all managed configuration profiles

Revoke identity certificates

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值