Symptoms or Error
Unable to enroll devices under Apple Device Enrollment Program (DEP). The following error appears:
"The configuration for your iPhone could not be downloaded from <organisation>. This operation couldn't be completed. (NSURLErrorDomain error -1012)"
Solution
Validate that all SSL certificates have the full chain for the MDM server linked properly.
When validating the SSL certificates for full chain, compare them to List of available trusted root certificates in iOS 8. If you have SSL certificates that are not trusted by Apple, then you will not be able to enroll DEP devices. Normal MDM devices will however work.
To test this you can temporarily disable SSL Enforcement at MDM, Full Wipe and reboot the device. Device should be able to enroll, this validates that issue is with the SSL certificate chain.
If the issue persists:
-
Set ios.mdm.enrollment.installRootCalfRequired to false within ew-config.properties file and test again.
-
This modification forces the MDM server to not send the pki-ca-root.p12 file to Apple.
-
If set to true, DEP device are forced to use this to complete SSL handshakes for MDM servers which will fail if the SSL certificate has been modified.
-
- Verify that the IP found in the Apple DEP portal matches with the IP address of the external FQDN hostname.
- i) Unassign device from DEP portal at deploy.apple.com using device serial number (located on back of device)
ii) Perform Recovery mode restore via iTunes but do not setup device.?? Recovery mode restore is different from regular restore as it has a critical step where it reaches out to Apple for activation
iii) Assign device back to MDM server to give device new activation policy before it goes through re-activation
Problem Cause
SSL trust cannot be completed between the server and DEP devices or DEP device is unable to reach MDM server specified in activation policy possibly due to MDM server change
Supporto Citrix
Traduzione automatica
Questo articolo ??¨ stato tradotto da un sistema di traduzione automatica e non ??¨ stata valutata da persone. Citrix fornisce traduzione automatica per aumentare l'accesso per supportare contenuti; tuttavia, articoli automaticamente tradotte possono possono contenere degli errori. Citrix non ??¨ responsabile di incongruenze, errori o danni derivanti dell'uso di articoli automaticamente tradotte.
Citrix技術支持
自動翻譯
這篇文章被翻譯由一個自動翻譯系統,並沒有受到人們的審查。 Citrix提供自動翻譯,增加獲得支持的內容;但是,自動翻譯的文章可能可以包含錯誤。思傑不負責不一致,錯誤或損壞因使用自動翻譯的文章的結果。
Поддержка Citrix
Tradução automática
Эта статья была переведена автоматической системой перевода и не был рассмотрен людьми. Citrix обеспечивает автоматический перевод с целью расширения доступа для поддержки контента; Однако, автоматически переведенные статьи могут может содержать ошибки. Citrix не несет ответственности за несоответствия, ошибки, или повреждения, возникшие в результате использования автоматически переведенных статей.
시트릭스 지원
자동 번역
이 문서 자동 번역 시스템에 의해 번역 된 사람들에 의해 검토되지 않았다. 시트릭스는 컨텐츠를 지원하기 위해 접근을 높이기 위해 자동 번역을 제공합니다; 그러나, 자동으로 번역 기사 오류를 포함 할 수있다. 시트릭스는 자동으로 번역 된 기사의 사용의 결과로 발생하는 불일치, 오류 또는 손해에 대해 책임을지지 않습니다.