Jump to content

Recommended Posts

Posted
I'm just starting looking at this having put it off for a while! Anyone know what you do about getting them onto iPads that are supervised with AC and managed with Meraki? Is this something you have to do @Joanne?
Posted
With Profile manager, you'd put the certificate into a profile and push the profile out to the iPads. I can't imagine it'd be much different with Meraki.
  • Thanks 1
Posted
You can install the certificates via apple configurator. Add them to your mac, make sure you change the security to trust on all of them and import them into your profile.
  • Thanks 1
Posted (edited)

You can't do it with Meraki but you can do it with AC. Either create a new profile with RM Cert name or just add the Certificate into the current profile under the certificate section [download the cert file and then upload to AC]. Here's the direct link that can install the certificate directly onto an ipad without the need of AC.

 

http://www.rm.com/_rmvirtual/media/downloads/rmeducationca.crt

 

P.S. you do need to enter the passcode while installing the new certificate. Also under proxy settings instead of proxy.swgfl.org.uk you would need to enter sslfilter.proxy.swgfl.org.uk

 

In order to download and install on the machines, I had to go to their normal address download the Mac and Windows versions respectively and install them. Here's the default address link

 

Changes to Google SSL and RM Safetynet Plus | RM Education - What we do

 

with regards to Macbooks, I found that after installing the Apple version of certificate, some browsers still didn't work until I went onto the web browser safari/firefox/chrome and run the .crt link [first link I gave above] and click Trust on all options.

 

With regards to windows unzip the file and run the .reg file, it'll add the info into the registry for you.

 

To test if it has been installed properly, go to RM SafetyNet - SSL Filtering Certificate Test onto your browser and if there is a green tick mark, it means it has been installed successfully, if you see yellow ! mark that means something went wrong.

 

hope this helps

Edited by Jehanzeb
  • Thanks 1
Posted (edited)

I've just finished pushing RM's SSL certificate to all 1031 of our iPads using Meraki, it can push out a .mobileconfig configuration profile to any enrolled iOS or OS X devices.

 

RM provide the certificate in .crt format on the page linked to several times above. I used the old iPhone Configuration Utility to add the certificate to a configuration profile and then exported the .mobileconfig file. Import the .mobileconfig into Meraki and voila, certificate pushed to all devices over-the-air.

Edited by biz
  • Thanks 1
Posted

Biz would you kindly share the iPhone configuration utility download with us please? I tried meraki but had no luck, I asked RM but they never understood what I was on about. In the end I did what I explained in the above post.

 

Regards

 

J.

Posted
We install them on the Mac mini running Configurator and then import them as part of the profile applied to the iPads when they are prepared/supervised.
  • Thanks 1
Posted
I've just finished pushing RM's SSL certificate to all 1031 of our iPads using Meraki, it can push out a .mobileconfig configuration profile to any enrolled iOS or OS X devices.

 

RM provide the certificate in .crt format on the page linked to several times above. I used the old iPhone Configuration Utility to add the certificate to a configuration profile and then exported the .mobileconfig file. Import the .mobileconfig into Meraki and voila, certificate pushed to all devices over-the-air.

 

Thanks biz for this. I appreciate all the solutions - AC would be a pain as I'd have to physically get them all in (although we only have 131 not 1031!) so I'd prefer Meraki if possible!

 

I'm not sure how to do this, I've got iPhone CU (thanks @Arthur) but I don't know what to do next. Is it a General Configuration Profile or do you upload it in Credentials?

Posted

When you create a new Configuration Profile there are some mandatory fields to fill out in General. In this case I went with:

 

Name - RM SSL Certificate

Identifier - RM.SSL.CERT

Organization - RM Education Certification Authority

Description - Allows RM to intercept and filter Google search results.

Authorization - With Authorization

 

It doesn't really matter what you choose, it's just for your reference as these are the certificate details that show up on the device.

 

The actual certificate goes in under Credentials, just press Configure and upload the .crt file. You should end up with "1 payload configured". Hit Export at the top and you're done.

  • Thanks 1
Posted

This is exciting, I've been reading this post as well, trying to understand. I created a new profile under MDM-->Profiles--> Add New Profile---> mobile profile. Then I went to MDM--->Settings ---> Credentials -->Add a new credential --> filled Name,Password, (and selected) certificate.

[TABLE=class: cfg skip_magic_search, width: 1414]

[TR]

[TD=class: cfgq]Name 1x1.gif[/TD]

[TD=class: cfgo]Name or description of the credential

[/TD]

[/TR]

[/TABLE]

[TABLE=class: cfg skip_magic_search, width: 1414]

[TR]

[TD=class: cfgq]Password[/TD]

[TD=class: cfgo]Password protecting the certificate file

[/TD]

[/TR]

[/TABLE]

 

[TABLE=class: cfg skip_magic_search, width: 1414]

[TR]

[TD=class: cfgq]Certificate[/TD]

[TD=class: cfgo]Filename: RMEducationCA.crt

Issuer: RM Education Certification Authority

Subject/CN: RM Education Certification Authority

Expiration: Feb 20, 2034

Replace this certificate

[/TD]

[/TR]

[/TABLE]

 

 

Now what next.......

  • Thanks 3
Posted (edited)
This is exciting, I've been reading this post as well, trying to understand. I created a new profile under MDM-->Profiles--> Add New Profile---> mobile profile. Then I went to MDM--->Settings ---> Credentials -->Add a new credential --> filled Name,Password, (and selected) certificate.

 

 

Now what next.......

 

Hah that's excellent! All the messing around with .mobileconfig files I did and turns out Meraki can push certificates out itself :doh:

 

Sorry everyone for over-complicating things. @Jehanzeb assign the profile with the credentials in to all devices and you are done!

Edited by biz
  • Thanks 1
  • 1 year later...
Posted
This has helped me so thank you for that. in the password what password did you use (apple ID one or just a random one? could i leave it blank ?
Posted
The password field is for protected SSL certs, so you can leave it blank if the cert you want to push isn't password protected.
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...