HowTo entitle pass-thru authentication for enrollment process
Last Updated September 09, 2013
Entitle pass-thru authentication is requested for the enrollment process to avoid issues like:
The profile "MDM Enrollment" could not be installed.
The certificate which had defined for the IIS HTTPS binding was generated for the Mobile Management Server (MMS) and used the fully qualified domain name (FQDN) of the server (e.g. Testlab.Symantec.com). But the IP override on the MMS configuration policy was set to the public IP address of the MMS which is reachable from the internet.
In this situation the enrollment works when using HTTP. For iOS5 devices however, there is need for HTTPS. So in this example the trust could not be made because the certificate is generated for the FQDN (Testlab.Symantec.com) and this DNS record is not reachable from the internet (only the IP address is reachable).
1. Create a (temporary) trusted root certificate (Testlab.Symantec.com) for testing and importing on the MMS
2. Change the HTTPS (443) port binding in IIS on the MMS to this trusted root certificate (Testlab.Symantec.com)
3. Create a public DNS record to forwarded (Testlab.Symantec.com) the public IP address of the MMS.
4. Change the IP override for the MMS to the public DNS name (Testlab.Symantec.com)
Now all iOS devices should enroll without any problem. The configuration profiles that are configured during the enrollment (additional profiles) should apply successfully as well.
iPad or iPhone iOS 5
Imported Document ID: TECH175678
Subscribing will provide email updates when this Article is updated. Login is required to Subscribe