Jump to content

Recommended Posts

Posted

Having a weird issue here, onsite smoothwall, dynamic certificates were expiring so renewed them as per instructions, root cert still in date.

 

No issues on any Chromebooks or windows computers, but since then I've had 5 iPads showing a certificate error when browsing the internet, not all on day 1 but over the course of a few days. Viewing the certificate shows the one issued by smoothwall as expected, and checking the management profile on the iPad I can see the root cert we have pushed out via mdm, so it should be trusting the cert from the smoothwall.

 

I have tried removing the iPad from the group which has the cert pushed out and then manually installing it with no improvement.

 

Yesterday I generated a new root cert and pushed that out to all our devices and this morning changed our smoothwall over to use this. The same devices still have the same error.

 

A wipe and re-enroll of the iPad does sort the issue, but I'd like to work out why they are doing it - a wipe and re-install is pushing the same cert back to them!

 

All are running ios 18.1.1

Posted
Does the communication back to your MDM also go through the smoothwall proxy, thus not working? could be possible to configure the MDM URLs to notbe inspected so they go straight through?
Posted
Does the communication back to your MDM also go through the smoothwall proxy, thus not working? could be possible to configure the MDM URLs to notbe inspected so they go straight through?

 

MDM communication is working - when I removed it from the group for the ssl cert it did remove from the device, the same device also got the new root cert which I pushed out via intune - I had hoped that this would sort it, but annoyingly didn't.

Posted
If it’s getting the root cert and still showing cert errors then maybe intermediate certs are required, or possibly the routes to CRL checks (over port 80 if memory serves) are not working.
Posted
If it’s getting the root cert and still showing cert errors then maybe intermediate certs are required, or possibly the routes to CRL checks (over port 80 if memory serves) are not working.

 

Thanks for the suggestions, CRL checks are set to be unfiltered on the smoothwall and it's working in bridged mode so no firewall restrictions. It's strange (and frustrating!) that it's only about 5 iPads out of 300 and a factory reset does fix the issue.

Posted
Suspect you will find those ipads are haunted.

 

I don't mind 1 or 2 haunted iPads, getting 1 or 2 new ones a day is what I'm not so keen on!

Posted

iPad and cert are often not so fun...

Please take a look at Smoothwall Cloud Filter, maybe not the prettiest solution with its own browser, but it works very well.https://kb.smoothwall.com/hc/en-us/sections/14416737869084-Apple-iOS

Posted
iPad and cert are often not so fun...

Please take a look at Smoothwall Cloud Filter, maybe not the prettiest solution with its own browser, but it works very well.https://kb.smoothwall.com/hc/en-us/sections/14416737869084-Apple-iOS

 

We want to use the classroom.cloud browser so can't use the cloud filter one, we do use cloud filter on our Chromebooks as this can work alongside classroom cloud. This used to be so much easier 10 years ago!

  • 5 weeks later...
Posted

Sort of half a solution to this, not an ideal one but a work around to get it working again without having to reset an iPad.

 

On the affected iPads, if I go to settings, general, about, certificate trust settings I can see that the smoothwall cert is missing. This is despite it showing in General, VPN & Device Management, management profile, more details - it is listed under the certificates that have been deployed.

 

The workaround is going to the getcert page on the smoothwall, installing it on the ipad, and then going back to settings, general, about, certificate trust settings and toggling the trust on for this new cert.

 

Just need to work out now why random iPads don't have the one we deploy showing.

  • 2 weeks later...
Posted
Sort of half a solution to this, not an ideal one but a work around to get it working again without having to reset an iPad.

 

On the affected iPads, if I go to settings, general, about, certificate trust settings I can see that the smoothwall cert is missing. This is despite it showing in General, VPN & Device Management, management profile, more details - it is listed under the certificates that have been deployed.

 

The workaround is going to the getcert page on the smoothwall, installing it on the ipad, and then going back to settings, general, about, certificate trust settings and toggling the trust on for this new cert.

 

Just need to work out now why random iPads don't have the one we deploy showing.

 

Where did you find the certs? Searched the help page on our Smoothwall but doesn't come up and can't see it in any of the sub menus.

Posted
Where did you find the certs? Searched the help page on our Smoothwall but doesn't come up and can't see it in any of the sub menus.

 

Enter your Smoothwall name or IP into your browser, followed by/getcert

 

e.g. 104.104.104.1/getcert

Posted
Enter your Smoothwall name or IP into your browser, followed by/getcert

 

e.g. 104.104.104.1/getcert

 

Thanks, that worked!! You are a star. Been chasing them for a couple of days with no response, not happy with them at all.

 

They made us wait 5 days for a response for something simple recently and can't believe how poor the support is.

Posted
Can you send me the ticket where you waited 5 days please? I would want to see where we are going wrong, most tickets are getting a good turnaround

 

PM sent.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...