+ Post New Thread
Results 1 to 12 of 12
Mac Thread, Enrolling a client with Profile Manager / My Devices - not working? in Technical; So, I've now got a shiny Mac OS X 'server' here, and am trying to get a client to enroll ...
  1. #1

    localzuk's Avatar
    Join Date
    Dec 2006
    Location
    Minehead
    Posts
    18,142
    Thank Post
    522
    Thanked 2,550 Times in 1,979 Posts
    Blog Entries
    24
    Rep Power
    877

    Enrolling a client with Profile Manager / My Devices - not working?

    So, I've now got a shiny Mac OS X 'server' here, and am trying to get a client to enroll with it.

    I've set up Profile Manager with a self signed certificate, and then log in to MyDevices on the client and install the Trust Profile so the machine will trust that self-signed cert.

    I then click Enroll and it goes through the motions, asking for permission to install, continue and install. And then nothing.

    The Enroll button remains, and the device does not appear in the Devices list in Profile Manager.

    What am I doing wrong?

  2. #2

    Join Date
    Mar 2012
    Location
    Stafford
    Posts
    33
    Thank Post
    6
    Thanked 7 Times in 5 Posts
    Rep Power
    10
    iPads ? Mac's ? or iPhones?

  3. #3

    localzuk's Avatar
    Join Date
    Dec 2006
    Location
    Minehead
    Posts
    18,142
    Thank Post
    522
    Thanked 2,550 Times in 1,979 Posts
    Blog Entries
    24
    Rep Power
    877
    iMacs running 10.7.4.

  4. #4

    localzuk's Avatar
    Join Date
    Dec 2006
    Location
    Minehead
    Posts
    18,142
    Thank Post
    522
    Thanked 2,550 Times in 1,979 Posts
    Blog Entries
    24
    Rep Power
    877
    I thought I might've messed something up, so I restored back to default and tried again.

    On the client, I'm getting a pile of 'applepushserviced: Certificate not yet generated' errors, followed by 'mdmclient: *** ERROR *** [Agent:501] MDM server https://server.domain.forest.net/dev...device/connect returned error: 403 (forbidden)'

    The iMac is showing up under 'Devices' for that individual user, but not under 'Devices' in the Library section in Profile Manager. Also, the Enroll button doesn't change to the info page when its done.

  5. #5
    Rozzer's Avatar
    Join Date
    Aug 2005
    Location
    South West
    Posts
    720
    Thank Post
    21
    Thanked 81 Times in 61 Posts
    Rep Power
    33
    Have you got a proxy enabled? If so try disabling it then attempt to enrol. I have had issues where you need a proxy pac file to use exceptions for your mac server.

    Ross

  6. Thanks to Rozzer from:

    localzuk (10th July 2012)

  7. #6

    localzuk's Avatar
    Join Date
    Dec 2006
    Location
    Minehead
    Posts
    18,142
    Thank Post
    522
    Thanked 2,550 Times in 1,979 Posts
    Blog Entries
    24
    Rep Power
    877
    We do have a proxy enabled, but disabling it will mean it has no internet connection at all then.

    EDIT: Nope, no go.

    Any thoughts on what I should do to get around this issue?
    Last edited by localzuk; 9th July 2012 at 11:15 AM.

  8. #7
    Rozzer's Avatar
    Join Date
    Aug 2005
    Location
    South West
    Posts
    720
    Thank Post
    21
    Thanked 81 Times in 61 Posts
    Rep Power
    33
    Being in Bristol have you opened up the MDM ports?

    Port TCP 443 (https)
    Port TCP 1640 (SCEP)
    Port TCP 5223 (APNS)
    Port TCP 2195 (APNS)
    Port TCP 2196 (APNS)

    I opened these ports and it all started to work for my test.

    Ross

  9. Thanks to Rozzer from:

    localzuk (10th July 2012)

  10. #8

    localzuk's Avatar
    Join Date
    Dec 2006
    Location
    Minehead
    Posts
    18,142
    Thank Post
    522
    Thanked 2,550 Times in 1,979 Posts
    Blog Entries
    24
    Rep Power
    877
    You mean with BCC? We can't really open 443, as the iMacs can be on any IP range in our school!

    We don't have any internal rules on the network blocking any ports.

    Or do you mean these ports need to be accessible to the apple server? ie. TCP outbound ports for that single machine?
    Last edited by localzuk; 9th July 2012 at 11:55 AM.

  11. #9

    localzuk's Avatar
    Join Date
    Dec 2006
    Location
    Minehead
    Posts
    18,142
    Thank Post
    522
    Thanked 2,550 Times in 1,979 Posts
    Blog Entries
    24
    Rep Power
    877
    I now have the latter 4 ports open to the following IP addresses:

    network-object host 17.254.0.54
    network-object host 17.254.0.59
    network-object host 17.112.144.50
    network-object host 17.112.144.59

    Still getting the above error message... Do I also need to open 443 to albert.apple.com like it lists in another error message?
    Last edited by localzuk; 9th July 2012 at 02:33 PM.

  12. #10
    Rozzer's Avatar
    Join Date
    Aug 2005
    Location
    South West
    Posts
    720
    Thank Post
    21
    Thanked 81 Times in 61 Posts
    Rep Power
    33
    Those ports just need to be opened up for the mac server.

    Ross

  13. Thanks to Rozzer from:

    localzuk (10th July 2012)

  14. #11

    localzuk's Avatar
    Join Date
    Dec 2006
    Location
    Minehead
    Posts
    18,142
    Thank Post
    522
    Thanked 2,550 Times in 1,979 Posts
    Blog Entries
    24
    Rep Power
    877
    Woo! Well, after a night's sleep, and getting port 443 opened to albert.apple.com. Finally, it was add that site as a proxy exception on the server and give it a reboot and voila. Its working!

  15. #12
    Rozzer's Avatar
    Join Date
    Aug 2005
    Location
    South West
    Posts
    720
    Thank Post
    21
    Thanked 81 Times in 61 Posts
    Rep Power
    33
    Happy days Glad its working.

SHARE:
+ Post New Thread

Similar Threads

  1. iPad & Kindle (and probably other devices) not working on BGFL
    By CHR1S in forum Birmingham Grid for Learning (BGfL)
    Replies: 10
    Last Post: 23rd March 2012, 06:23 PM
  2. Replies: 8
    Last Post: 23rd September 2011, 12:20 PM
  3. Replies: 10
    Last Post: 19th September 2011, 06:03 PM
  4. Replies: 3
    Last Post: 2nd December 2010, 01:34 PM
  5. Redirecting "My Documents" Not Working!
    By secman in forum Windows
    Replies: 7
    Last Post: 14th February 2006, 11:56 AM

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •