Tammie Posted January 29, 2015 Posted January 29, 2015 I'm just starting looking at this having put it off for a while! Anyone know what you do about getting them onto iPads that are supervised with AC and managed with Meraki? Is this something you have to do @Joanne?
Joanne Posted January 29, 2015 Posted January 29, 2015 I've not had to do that yet. What are you installing them for? I can have a lookie see tomorrow if I get to work 😊 1
Tammie Posted January 29, 2015 Author Posted January 29, 2015 Lucky you! We very rarely see snow down here! It's something I've been told to do by RM - see Changes to Google SSL and RM Safetynet Plus | RM Education - What we do
Norphy Posted January 29, 2015 Posted January 29, 2015 With Profile manager, you'd put the certificate into a profile and push the profile out to the iPads. I can't imagine it'd be much different with Meraki. 1
steewy Posted January 29, 2015 Posted January 29, 2015 You can install the certificates via apple configurator. Add them to your mac, make sure you change the security to trust on all of them and import them into your profile. 1
Jehanzeb Posted January 29, 2015 Posted January 29, 2015 (edited) You can't do it with Meraki but you can do it with AC. Either create a new profile with RM Cert name or just add the Certificate into the current profile under the certificate section [download the cert file and then upload to AC]. Here's the direct link that can install the certificate directly onto an ipad without the need of AC. http://www.rm.com/_rmvirtual/media/downloads/rmeducationca.crt P.S. you do need to enter the passcode while installing the new certificate. Also under proxy settings instead of proxy.swgfl.org.uk you would need to enter sslfilter.proxy.swgfl.org.uk In order to download and install on the machines, I had to go to their normal address download the Mac and Windows versions respectively and install them. Here's the default address link Changes to Google SSL and RM Safetynet Plus | RM Education - What we do with regards to Macbooks, I found that after installing the Apple version of certificate, some browsers still didn't work until I went onto the web browser safari/firefox/chrome and run the .crt link [first link I gave above] and click Trust on all options. With regards to windows unzip the file and run the .reg file, it'll add the info into the registry for you. To test if it has been installed properly, go to RM SafetyNet - SSL Filtering Certificate Test onto your browser and if there is a green tick mark, it means it has been installed successfully, if you see yellow ! mark that means something went wrong. hope this helps Edited January 29, 2015 by Jehanzeb 1
biz Posted January 29, 2015 Posted January 29, 2015 (edited) I've just finished pushing RM's SSL certificate to all 1031 of our iPads using Meraki, it can push out a .mobileconfig configuration profile to any enrolled iOS or OS X devices. RM provide the certificate in .crt format on the page linked to several times above. I used the old iPhone Configuration Utility to add the certificate to a configuration profile and then exported the .mobileconfig file. Import the .mobileconfig into Meraki and voila, certificate pushed to all devices over-the-air. Edited January 29, 2015 by biz 1
Jehanzeb Posted January 29, 2015 Posted January 29, 2015 Biz would you kindly share the iPhone configuration utility download with us please? I tried meraki but had no luck, I asked RM but they never understood what I was on about. In the end I did what I explained in the above post. Regards J.
Arthur Posted January 29, 2015 Posted January 29, 2015 Biz would you kindly share the iPhone Configuration Utility download with us please? Here's a link to the latest Windows version of the iPhone Configuration Utility (v3.6.1.296) if you still need it? http://download.cnet.com/iPhone-Configuration-Utility-for-Windows/3001-20432_4-10969175.html N.B. The download above doesn't include any additional bundled software. 2
kathabell Posted January 30, 2015 Posted January 30, 2015 We install them on the Mac mini running Configurator and then import them as part of the profile applied to the iPads when they are prepared/supervised. 1
Tammie Posted February 3, 2015 Author Posted February 3, 2015 I've just finished pushing RM's SSL certificate to all 1031 of our iPads using Meraki, it can push out a .mobileconfig configuration profile to any enrolled iOS or OS X devices. RM provide the certificate in .crt format on the page linked to several times above. I used the old iPhone Configuration Utility to add the certificate to a configuration profile and then exported the .mobileconfig file. Import the .mobileconfig into Meraki and voila, certificate pushed to all devices over-the-air. Thanks biz for this. I appreciate all the solutions - AC would be a pain as I'd have to physically get them all in (although we only have 131 not 1031!) so I'd prefer Meraki if possible! I'm not sure how to do this, I've got iPhone CU (thanks @Arthur) but I don't know what to do next. Is it a General Configuration Profile or do you upload it in Credentials?
biz Posted February 3, 2015 Posted February 3, 2015 When you create a new Configuration Profile there are some mandatory fields to fill out in General. In this case I went with: Name - RM SSL Certificate Identifier - RM.SSL.CERT Organization - RM Education Certification Authority Description - Allows RM to intercept and filter Google search results. Authorization - With Authorization It doesn't really matter what you choose, it's just for your reference as these are the certificate details that show up on the device. The actual certificate goes in under Credentials, just press Configure and upload the .crt file. You should end up with "1 payload configured". Hit Export at the top and you're done. 1
Jehanzeb Posted February 3, 2015 Posted February 3, 2015 This is exciting, I've been reading this post as well, trying to understand. I created a new profile under MDM-->Profiles--> Add New Profile---> mobile profile. Then I went to MDM--->Settings ---> Credentials -->Add a new credential --> filled Name,Password, (and selected) certificate. [TABLE=class: cfg skip_magic_search, width: 1414] [TR] [TD=class: cfgq]Name [/TD] [TD=class: cfgo]Name or description of the credential [/TD] [/TR] [/TABLE] [TABLE=class: cfg skip_magic_search, width: 1414] [TR] [TD=class: cfgq]Password[/TD] [TD=class: cfgo]Password protecting the certificate file [/TD] [/TR] [/TABLE] [TABLE=class: cfg skip_magic_search, width: 1414] [TR] [TD=class: cfgq]Certificate[/TD] [TD=class: cfgo]Filename: RMEducationCA.crt Issuer: RM Education Certification Authority Subject/CN: RM Education Certification Authority Expiration: Feb 20, 2034 Replace this certificate [/TD] [/TR] [/TABLE] Now what next....... 3
biz Posted February 3, 2015 Posted February 3, 2015 (edited) This is exciting, I've been reading this post as well, trying to understand. I created a new profile under MDM-->Profiles--> Add New Profile---> mobile profile. Then I went to MDM--->Settings ---> Credentials -->Add a new credential --> filled Name,Password, (and selected) certificate. Now what next....... Hah that's excellent! All the messing around with .mobileconfig files I did and turns out Meraki can push certificates out itself Sorry everyone for over-complicating things. @Jehanzeb assign the profile with the credentials in to all devices and you are done! Edited February 3, 2015 by biz 1
Tammie Posted February 4, 2015 Author Posted February 4, 2015 Many thanks for this info @biz and @Jehanzeb, much appreciated. I will try that and let you know!
busby Posted July 19, 2016 Posted July 19, 2016 This has helped me so thank you for that. in the password what password did you use (apple ID one or just a random one? could i leave it blank ?
biz Posted July 19, 2016 Posted July 19, 2016 The password field is for protected SSL certs, so you can leave it blank if the cert you want to push isn't password protected. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now