Skip to content

Certificate Handling in CapaInstaller

Before CapaInstaller Mobile Device Management (MDM) can communicate with devices and third-party mobile providers, the data sent back and forth must be protected by signed certificates. MDM uses two kinds of certificates:

  • A TLS certificate for the domain where the MDM service is published. It secures the communication between the devices and your MDM service.
  • An Apple Push Certificate, which Apple requires before CapaInstaller can contact Apple devices.

Read more:

To secure your MDM communication, you need a certificate issued to the domain where the MDM service is published. If you don’t have a certificate for that domain, request one from a trusted certificate authority. This can take some time, so request it well before you implement MDM.

CapaInstaller MDM supports wildcard certificates.

You create and renew the Apple Push Certificate with the Apple Push Certificate request wizard in the CapaInstaller Console. Since CapaInstaller 6.1, the wizard uploads the certificate to CapaOne, so you don’t install it on the MDM server. See Apple Push Notification Certificate.

Import a certificate to the Windows Certificate Store

Section titled “Import a certificate to the Windows Certificate Store”

The CapaInstaller services read their TLS certificate from the Personal store of the local computer on the server where the service runs. MDM requires a certificate with a private key, which is always a .pfx file.

To import the .pfx file:

  1. On the server where the service runs, right-click the .pfx file and select Install PFX.
  2. In the Certificate Import Wizard, select Local Machine as the store location, and click Next.
  3. On the File to Import page, click Next.
  4. On the Private key protection page, type the password for the private key, and click Next.
  5. On the Certificate Store page, select Place all certificates in the following store, select Personal, and click Next.
  6. Click Finish.

The certificate appears under Certificates (Local Computer) → Personal → Certificates in certlm.msc. To assign it to a service, see Configuring or Updating a Certificate.

Read more:

Remove a previously installed certificate binding

Section titled “Remove a previously installed certificate binding”

If another certificate is already bound to the port the service uses, you can remove the binding. Open a command prompt as administrator and list the certificate bindings for all ports:

Terminal window
netsh http show sslcert

To remove the binding for a port, for example port 443, run:

Terminal window
netsh http delete sslcert ipport=0.0.0.0:443