Skip to content

Apple Push Notification Certificate

To communicate with Apple devices, CapaInstaller uses the Apple Push Notification service (APNs). APNs requires a certificate issued by Apple, so only authorized services can contact your devices. Before Apple issues the certificate, the certificate request must be signed by an authorized MDM vendor, in this case CapaSystems A/S. The Apple Push Certificate request wizard in the CapaInstaller Console handles the request, the signing, and the conversion of the certificate.

Since CapaInstaller 6.1, push messages for Apple and Android devices are sent from CapaOne. The Apple Push Certificate is uploaded to CapaOne and is no longer installed on your Mobile Device Management (MDM) servers.

The CapaOne dialog where you enter the Portal Access Token

Request and create or renew the certificate

Section titled “Request and create or renew the certificate”
  1. In System Administration, select Actions → Apple Push Certificate request….

    The Actions menu in System Administration with Apple Push Certificate request selected

  2. On the welcome page, click Next.

    The welcome page of the Apple Push Certificate request wizard

  3. Wait for the prerequisite checks to finish:

    • If Verify OpenSSL doesn’t pass, see OpenSSL.
    • If Verify access to Capainstaller certificate request signing service fails, check that the computer can reach CapaOne over HTTPS (port 443) through your firewall and proxy.

    The prerequisites page with the OpenSSL and signing service checks

  4. Select an Output Folder, click Start, and click Next when the request is finished. The wizard creates the certificate request, has it signed by CapaSystems, and saves it as the file plist_encoded in the output folder.

    The certificate request page with the output folder and the Start button

  5. Click Open Apple Push Certificates Portal. The portal opens in your browser.

    The wizard page with the Open Apple Push Certificates Portal and Create Certificate File links

  6. Sign in with the Apple ID you use for push certificates.

    The Apple Push Certificates Portal sign-in page

  7. Do one of the following:

    • To renew an existing certificate, select it and click Renew.
    • To create your first certificate, click Create a Certificate.

    If Apple shows its terms of use, read and accept them.

    The certificate list in the Apple Push Certificates Portal with the Renew button

    The terms of use shown by the Apple Push Certificates Portal

  8. Click Choose File, select the plist_encoded file from the output folder, and click Upload.

    The upload page in the Apple Push Certificates Portal

  9. Download the issued certificate. The file is named MDM_<name>.pem. Note the expiration date, and add a reminder to your calendar a month before it.

    The confirmation page in the Apple Push Certificates Portal with the expiration date and the Download button

  10. In the wizard, click Create Certificate File.

    The Create Certificate File link in the wizard

  11. In Apple certificate File (*.pem), select the file you downloaded from Apple. Keep or change the name in Certificate file (pfx), click Start, and then click Next.

    The page that converts the Apple .pem file to a .pfx certificate file

  12. The wizard creates the .pfx certificate file in the output folder and uploads it to CapaOne.

    A message confirming that the new certificate was created

    The final wizard page confirming that the certificate was uploaded to CapaOne

If the upload to CapaOne fails, the final page tells you to upload the .pfx file manually on the Certificates page in the CapaOne portal.

  1. Sign in to https://mdm.capaone.com and select Certificates.

    The Certificates menu in the CapaOne MDM portal

  2. Check that the Apple Push Certificate is listed and valid.

    The Apple Push Certificate listed as valid in the CapaOne MDM portal

If you upgrade from CapaInstaller 6.0 or earlier, the Apple Push Certificate must be uploaded to CapaOne. Renew the certificate with the Apple Push Certificate request wizard after the upgrade, and the wizard uploads it for you. You can also upload your existing .pfx file on the Certificates page in the CapaOne MDM portal. Before you run it, check that the Portal Access Token is present under Software Accounts → CapaOne.