Certificate Handling in CapaInstaller
Before CapaInstaller Mobile Device Management (MDM) can communicate with devices and third-party mobile providers, the data sent back and forth must be protected by signed certificates. MDM uses two kinds of certificates:
- A TLS certificate for the domain where the MDM service is published. It secures the communication between the devices and your MDM service.
- An Apple Push Certificate, which Apple requires before CapaInstaller can contact Apple devices.
Read more:
Request a TLS certificate
Section titled “Request a TLS certificate”To secure your MDM communication, you need a certificate issued to the domain where the MDM service is published. If you don’t have a certificate for that domain, request one from a trusted certificate authority. This can take some time, so request it well before you implement MDM.
CapaInstaller MDM supports wildcard certificates.
Create the Apple Push Certificate
Section titled “Create the Apple Push Certificate”You create and renew the Apple Push Certificate with the Apple Push Certificate request wizard in the CapaInstaller Console. Since CapaInstaller 6.1, the wizard uploads the certificate to CapaOne, so you don’t install it on the MDM server. See Apple Push Notification Certificate.
Import a certificate to the Windows Certificate Store
Section titled “Import a certificate to the Windows Certificate Store”The CapaInstaller services read their TLS certificate from the Personal store of the local computer on the server where the service runs. MDM requires a certificate with a private key, which is always a .pfx file.
To import the .pfx file:
- On the server where the service runs, right-click the
.pfxfile and select Install PFX. - In the Certificate Import Wizard, select Local Machine as the store location, and click Next.
- On the File to Import page, click Next.
- On the Private key protection page, type the password for the private key, and click Next.
- On the Certificate Store page, select Place all certificates in the following store, select Personal, and click Next.
- Click Finish.
The certificate appears under Certificates (Local Computer) → Personal → Certificates in certlm.msc. To assign it to a service, see Configuring or Updating a Certificate.
Read more:
- Managing certificates (learn.microsoft.com)
- Import-Certificate: import certificates into a certificate store with PowerShell (learn.microsoft.com)
- Tools to create, view, and manage certificates (learn.microsoft.com)
Remove a previously installed certificate binding
Section titled “Remove a previously installed certificate binding”If another certificate is already bound to the port the service uses, you can remove the binding. Open a command prompt as administrator and list the certificate bindings for all ports:
netsh http show sslcertTo remove the binding for a port, for example port 443, run:
netsh http delete sslcert ipport=0.0.0.0:443