Skip to main content
Answer

push notification certificate expires in * days

  • September 22, 2015
  • 16 replies
  • 76 views

Forum|alt.badge.img+20

What happens if the push notification certificate expires ?

Best answer by mpermann

@tcandela yes, I believe you need to have Push Notifications enabled in order for computers to be MDM capable.

16 replies

Forum|alt.badge.img+31
  • Hall of Fame
  • September 22, 2015

Apple push notification (APN) certificates have expiration dates. To maintain MDM management with the Macs and iOS devices in your organization, you must renew your APN certificates periodically.

If your APN certificate expires, your iOS devices are no longer managed by Casper. They must be re-enrolled to restore MDM management to that iOS device.

Your Macs will also lose MDM management, but it should be possible to use the Casper agent to restore MDM management after a new APN certificate is uploaded to the Casper server.


Forum|alt.badge.img+12
  • Contributor
  • September 22, 2015

Hi @rtrouton,

Whens Macs lose MDM management, is uploading the new certificate sufficient for the JSS to restore management (and re-deploy the config profiles) or is other action required?

Thank you!


acodega
Forum|alt.badge.img+15
  • Valued Contributor
  • September 22, 2015

They will not fix themselves but you can use the jamf enroll command to reenroll them. Maybe you can run this on multiple computers at once using Apple Remote Desktop.

Usage:   jamf enroll [-prompt | -invitation] [-noRecon] [-noManage]


     -prompt         Prompts for JSS and SSH credentials.

     -invitation         Uses an invitation ID for credentials instead of a user name and password.

     -noRecon        Stops enroll from acquiring inventory.

     -noManage       Stops enroll from enforcing the management framework.

     -noPolicy       Stops enroll from checking for enrollment policies.

Forum|alt.badge.img+12
  • Contributor
  • September 22, 2015

@adamcodega Thanks Adam. I'm in a bit of a pickle since we are changing Apple IDs (and thus, certificates) for our entire fleet of about 900 Macs. I love ARD but it falls flat with the way our subnets are organized. Any ideas?


Forum|alt.badge.img+12
  • Contributor
  • September 24, 2015

Hey friends, if you find yourself in my situation, all that's needed on the OS X side is to run

jamf manage

and the new MDM profiles will come down. Whoo!


Forum|alt.badge.img+20
  • Author
  • Contributor
  • September 26, 2015

@dferrara so your push notification expired and from each computer you simply ran jamf manage ?

I manage a site, the push notification expires soon, not sure what the main administrators are waiting to renew it, just anticipating what to do just in case.


Forum|alt.badge.img+12
  • Contributor
  • September 29, 2015

@tcandela

Yeah, it's going to expire in a few months, so we are preparing for it now. I ran it by our account rep and it sounds pretty simple, at least for OS X devices.


Forum|alt.badge.img+20
  • Author
  • Contributor
  • October 1, 2015

the push notifications expired here but since have been renewed. Now my enrolled computers say

MDM capability: NO

and running jamf manage, jam enroll etc.. does not change it to 'YES'


Forum|alt.badge.img+20
  • Author
  • Contributor
  • October 1, 2015

what exactly is lost if MDM Capability = NO ?

I see that policies still execute.
I see that in an enrolled computers 'Management' tab the payload to 'wipe' 'blank push' etc.. is missing


Forum|alt.badge.img+12
  • Contributor
  • October 1, 2015

@tcandela Are your profiles getting installed?

Rich T. has some great resources on this topic. I haven't read them fully yet but it looked interesting.

http://derflounder.wordpress.com/2013/08/31/automatically-fixing-casper-mac-mdm-enrollment/

https://derflounder.wordpress.com/2014/06/15/automatically-fixing-mdm-certificate-enrollment-with-casper-9-x/


Forum|alt.badge.img+20
  • Author
  • Contributor
  • October 1, 2015

for newly enrolled computers I do not see 'profiles' in the payload.

all computers that have checked in since the certificate expired have MDM Capability: NO


bentoms
Forum|alt.badge.img+35
  • Hall of Fame
  • October 4, 2015

@tcandela Sounds right.

Your full JSS Admin needs to renew the old APNS... Although as it's now expired they might have to generate a new one & then all clients will need to be re-enrolled.


Forum|alt.badge.img+20
  • Author
  • Contributor
  • October 6, 2015

the certificate has been renewed. subsequent enrollments are still MDM=NO
just to verify does 'Enable Push Notifications' need to be Checked ???

under the following section --- Computer Management --> Security


mpermann
Forum|alt.badge.img+22
  • Valued Contributor
  • Answer
  • October 6, 2015

@tcandela yes, I believe you need to have Push Notifications enabled in order for computers to be MDM capable.


Forum|alt.badge.img+20
  • Author
  • Contributor
  • October 7, 2015

I mentioned to the admins here managing the Full JSS that they probably need to also 'Enable Push Notifications' under the following section --- Computer Management --> Security

this must of 'unchecked' itself after the certificate expired.

they 'checked' the box yesterday, and after computers started checking in, the MDM started changing to YES.

no need to re-enroll


Forum|alt.badge.img+6
  • New Contributor
  • September 10, 2017

My push notification expired on my JSS - and I have 4500 ipads on this. Is there a way to mass enroll them once I renew my certificate?