OS X Server 3 - Profile manager - I can't enroll any iOS devices

OS X Server 3 - Profile manager - I can't enroll any iOS devices
I have OS X Server setup on a Mac Mini and an Airport Extreme.
Airport is 10.0.1.1 and server is 10.0.1.3.
Server is setup to use DNS itself by server.mydomain.com
Airport is setup to use the server as DNS and the server then routes DNS queries onward to the internet.
Essentially anyone on my internal network thinks server.mydomain.com is the server itself. This is what I want.
From the outside, anyone searching for server.mydomain.com get's some page on a free hosting site with "Server is not accessible from the internet"
I also use a self-signed certificate to secure communications. It's valid.
Now this configuration has worked for the past two years. Out of curiosity in Server 3.1.1 I decided to give Profile manager a shot. Set it up, no worries.
Installed the Trust Profile first and then the Enroll profile. Done.
I can enroll and wipe, lock any mac in my firm remotely. Everything works, except iOS devices.
Any iOS device I try it fails at "Installing profile", I tried friend's phones, my own iPad... every iPad in my firm. It fails consistently at the same step, with no error code what so ever.
Is there  a checklist I need to go through? Do I need some kind of weird certificate setup?
PS. Is it a problem if my devices are enrolled as development devices, thei UUID is in Apple's device list for beta software and iOS development?

The Problem is your DNS is being pushed locally to the iOS Device from your Airport Extreme and the DNS on your Airport extreme is undoubtedly a public form of DNS that does not recognize your private server's ip address or HQDN, in Airport Utility point the DNS at your server and let your Server provide the public DNS mapping and allow your Router to provide your Server's DNS.  This should resolve your issue and allow you to enroll your iOS Devices by logging into the Profile Manager Web Portal from the iOS Device. 

Similar Messages

  • VPP Distribution issues with OSX Server Profile Manager

    Hi, I have a new issue with my OSX 10.9.5 Server. I use VPP to distribute apps to users devices, when I would add a new user I would send them an invitation message through /profilemanager . All was working well until recenetly , the message still arrives in the users mailbox however when you click the "sign in" link on the "receive apps and books from xxxxx" email instead of opening through the Mac App store app it now opens Safari and connects to the profile manager server , any ideas ? it never has done this before and although I thought it was a new feature or method I can not seem to resolve the issue.

    Hi if when you are redirected back to your Mac Server you enter the user name and password of the user you are trying to receive VPP apps for i.e the Open Directory credentials it will then open the App Store providing the credentials are correctly entered so it looks like an additional layer of security. The process is click on the link in the VPP invite email, this takes you to your Mac Server profile manager, log on with your OD account, App store then opens on your Mac like it used to.

  • Access Mac Mini Server (profile management) through reverse proxy

    Hi,
    Newbie in Mac's world and yet trying to make it more complicated as it is.
    As we recently (last month) decided to equip our sales force with iPads, they were configured through Apple Configurator tool running on a dedicated Mac Mini Mountain Lion.
    Now, I'd be keen in moving this configuration to the Profile Manager, part of the OSx Server plugin. So far so good.
    Problem is the following : another web server is already on the LAN using both 80 and 443 ports. So all incoming traffic on those ports was routed to this other server. As Mac Mini Server default http/s ports may not be altered, I installed a reverse proxy server (Oracle VM - Ubuntu 12.04LTS - pound), configured to deal differently traffic on those ports according to the domain name (host) of the web request (header). Each 'local' server has been allocated a domain name. Just to be clear, traffic is now routed by the WAN/LAN router, for those ports, towards the reverse proxy, configured to reroute the traffic to the correct destination.
    So far so good, it works like a charm, except... as soon as we enter https protocol on Mac Mini Server Profile Manager.
    Access from an iDevice to the Mac Mini Server Profile Manager login page is fine, but as soon as password is confirmed, safari is pending and finally a message 'An internal serer error occured. Please try later again' appears.
    Looking to both reverse proxy system log and Mac Mini profilemanager.log files to trace the problem, the following lines are produced at this particular moment :
    reverse proxy system.log
    Jan 15 14:44:03 reverseproxy pound: 91.... GET /devicemanagement/console/apple_theme_v2/en/da56af0a69e733b259dac3991419fa928b4 94a56/resources/images/sprites/me_controls.png HTTP/1.1 - HTTP/1.1 200 OK
    Jan 15 14:44:03 reverseproxy pound: 91.... GET /auth?redirect=http://osxsrv.fiks.net/devicemanagement/api/authentication/callback HTTP/1.1 - HTTP/1.1 302 Moved Temporarily
    Jan 15 14:44:04 reverseproxy pound: 91.... GET /devicemanagement/api/authentication/callback?auth_token=336952DE-BDDE-4390-82F 7-8475B79FB2D3 HTTP/1.1 - HTTP/1.1 302 Moved Temporarily
    Jan 15 14:44:04 reverseproxy pound: (b7680b40) e500 can't read header
    Jan 15 14:44:04 reverseproxy pound: (b7680b40) e500 response error read from 192.168....:443/GET /profilemanager/ HTTP/1.1: Success (0.007 secs)
    Jan 15 14:44:08 reverseproxy pound: 91.... POST /devicemanagement/api/magic/get_updated HTTP/1.1 - HTTP/1.1 200 OK
    OSx Server profilemanager.log
    Jan 15 14:44:05 osxsrv ProfileManager[1748] <Info>: Processing MagicController#do_magic (for 91.... at 2013-01-15 14:44:05) [POST]Jan 15 14:44:05 osxsrv ProfileManager[1749] <Info>: Processing MagicController#do_magic (for 91.... at 2013-01-15 14:44:05) [POST]
    Jan 15 14:44:06 osxsrv ProfileManager[1748] <Info>: Completed in 492ms (View: 0, DB: 6) | 200 OK [http://osxsrv.../magic/do_magic]
    Jan 15 14:44:06 osxsrv ProfileManager[1749] <Info>: Completed in 687ms (View: 0, DB: 5) | 200 OK [http://osxsrv..../magic/do_magic]
    Jan 15 14:44:07 osxsrv ProfileManager[1750] <Info>: auth_token doesn't exist
    Jan 15 14:44:07 osxsrv ProfileManager[1750] <Info>: Filter chain halted as [:verify_auth_token] rendered_or_redirected.
    Jan 15 14:44:07 osxsrv ProfileManager[1751] <Info>: Processing MagicController#do_magic (for 91.... at 2013-01-15 14:44:07) [POST]
    Jan 15 14:44:07 osxsrv ProfileManager[1751] <Info>: auth_token doesn't exist
    Jan 15 14:44:07 osxsrv ProfileManager[1751] <Info>: Filter chain halted as [:verify_auth_token] rendered_or_redirected.
    Jan 15 14:44:07 osxsrv ProfileManager[1751] <Info>: Completed in 4ms (View: 1, DB: 14) | 403 Forbidden [http://osxsrv..../magic/do_magic]
    Jan 15 14:44:07 osxsrv ProfileManager[1748] <Info>: Processing MagicController#do_magic (for 91.... at 2013-01-15 14:44:07) [POST]
    Jan 15 14:44:07 osxsrv ProfileManager[1748] <Info>: auth_token doesn't exist
    Jan 15 14:44:07 osxsrv ProfileManager[1748] <Info>: Filter chain halted as [:verify_auth_token] rendered_or_redirected.
    Jan 15 14:44:07 osxsrv ProfileManager[1748] <Info>: Completed in 45ms (View: 1, DB: 43) | 403 Forbidden [http://osxsrv..../magic/do_magic]
    Jan 15 14:44:07 osxsrv ProfileManager[1750] <Info>: Processing MagicController#do_magic (for 91.... at 2013-01-15 14:44:07) [POST]
    Jan 15 14:44:07 osxsrv ProfileManager[1750] <Info>: auth_token doesn't exist
    Jan 15 14:44:07 osxsrv ProfileManager[1750] <Info>: Filter chain halted as [:verify_auth_token] rendered_or_redirected.
    Jan 15 14:44:07 osxsrv ProfileManager[1750] <Info>: Completed in 55ms (View: 0, DB: 1) | 403 Forbidden [http://osxsrv..../magic/do_magic]
    Jan 15 14:44:08 osxsrv ProfileManager[1749] <Info>: Processing AuthenticationController#callback (for 91.... at 2013-01-15 14:44:08) [GET]
    Jan 15 14:44:08 osxsrv ProfileManager[1749] <Info>: Redirected to https://osxsrv..../profilemanager/
    Jan 15 14:44:08 osxsrv ProfileManager[1749] <Info>: Completed in 149ms (DB: 5) | 302 Found [http://osxsrv..../authentication/callback?auth_token=[FILTERED]]
    I guess the '302 Found' is causing or explaining the problem.
    I agree this might not be a Mac issue, so I still knock your doors hoping some of you could at least give a hint for what to search for !
    If the pound configuration file is of interest, just ask, but this is pretty trivial, saying basically listen these protocols (http/https) on these ports (80/443) and according to Header content (check destination host) and reroute packet to LAN device (with given LAN IP address).
    As the default port(s) of the Mac Mini Web Services may not be altered (so far I know), I guess I am stuck using 80 and 443 anyway.
    Maybe should I invest time in changing my other apache server ports to some more exotic 8080 or 88 or whatever so Mac Mini Server Profile Manager default ports 80 and 443 are maintained and can be easily and directly rerouted to my Mac server without any reverse proxy along the way.
    Thanks in advance for your help
    Alx

    HI All,
    i'm also using reverse proxy technique to publish my server to the internet. The ip is used by twice domains. The problem is by using the profile manager
    after login it redirects the url to the Local Area network addresse instead to the domain.
    How to configure this on OS X Server and the Profile Manager Service?
    Kind Regards
    Oemer

  • I can't install any audio device on MacBook Pro 2012

    I got a new MacBook Pro 2012 but I can't install any audio device, specially Native Instruments (Traktor)
    is there an issue with Mount Lion?
    Thank you

    Troubleshoot with install logs
    Mylenium

  • My iPhone 4s Bluetooth is not working, I have ios 5.1 but just can't get my Sony erricson hbh-pv715 headset to connect to the phone,  the phone can't find any Bluetooth device, can you help please

    My iPhone 4s Bluetooth is not working, I have ios 5.1 but just can't get my Sony erricson hbh-pv715 headset to connect to the phone,  the phone can't find any Bluetooth device, can you help please

    Yes it's in pairing mode, it worked fine with the 3GS but doesn't seem to work with the 4s,  my 4s can't find any other bluetooth device, I think the problem ls with apple?

  • I can not update or restore any ios device with my iTunes in my macbook but I can with my pc, why?

    I can not update or restore any ios device with my iTunes in my macbook but I can with my pc, why?

  • Hp soluation center can't detect any hp devices

    have installed the software and drivers on a acer laptop with windows vista home basic,all software and drivers installed. when i clicked on the shortcut for hp solution center it said it can't detect any hp device. but when you print the printer prints the other software works. the printer driver is installed. also when i plug the printer in the safely remove hardware said safely remove usb mass storage device - drive (f. please help thank you hp photosmart 7260

    i downloaded the software from hp,it was for windows vista 32 bit . it loads but the hp solution center said it can't detect any hp devices. the rest of the software and drivers work. thank you

  • HT1386 Can i sync multipler iOS devices like iPad, iPhones on the same iTunes? Can each iOS device have different contents which are subsets of the iTunes complete library

    Can i sync multipler iOS devices like iPad, iPhones on the same iTunes? Can each iOS device have different contents which are subsets of the iTunes complete library

    You can share a library with as many devices as you want but they cannot have seperate subsets like you wish. They would all have access to all information in the library. You could "Manually" sync content to each device by doing the following:
    On Mac: iTunes > Preferences > Devices Tab > Put a check in the box next to sentence that says "Prevent iPods, iPhones, and iPads from syncing automatically > Then click ok.
    On Pc: Edit > Preferences > Devices Tab > Put a check in the box next to sentence that says "Prevent iPods, iPhones, and iPads from syncing automatically > Then click ok.
    To manually sync data from iTunes to devices see article below:
     http://support.apple.com/kb/HT1351
    If you do not want all devices to have access to all the media from the main library, you would need to create a library for each device. See the article below for more info:
     http://support.apple.com/kb/HT1495
    Hope this helps.

  • My Windows XP AirPort util and Bonjour can't find any wireless device

    I have both macbook and a PC laptop.
    I just started using my TimeCapsula and all features (Internet gateway, access to the USB printer and the external harddisk) are visible and working fine when using my macbook.
    My PC wireless card seems to be working fine too and I can access the Internet using the Airport gateway.
    My problem is that Airport Util and Bonjour on my PC "can't find any wireless devices" (even though It is clearly working fine) and therefore don't detect/mount the external drive or the Printer.
    Thanks!

    How do your Extreme and Express connect to one another? Wired Ethernet between the two, or wirelessly?
    Try unplugging the Express. Does that change anything?
    Wireless interference could cause the symptoms you're describing. Even though you did nothing to your wireless network, the presence of other wireless networks or introduction of nearby devices will bring interference where there was none before.
    AirPort and Bluetooth: Potential sources of interference for wireless devices and networks
    Try changing wireless channels; use "automatic" unless you have reason to use a specified channel. Try checking "interference robustness". Altering these settings may help, but they could make things worse.
    If you are unable to configure a device over Airport, or changing a setting leaves you unable to configure it wirelessly, connect its Ethernet port to your computer's Ethernet port and Airport Utility should find it.
    As a last resort, try a "hard reset" followed by re-configuring the Extreme, Express, or both. Start by removing your Express from the network. Re-configure the Extreme and see if that fixes things. If it does, add the Express to your network and re-configure it as well.
    AirPort troubleshooting guide
    I open airport utility ... can not locate any of my wireless devises, airport extreme base,, airport express, apple tv, wifi printer.
    AirPort Utility will only detect Apple AirPort base stations (Extreme, Express, Time Capsule) for purposes of configuring them. It is not designed to detect or configure other wireless devices like your printer.

  • Iphone4s can's search any BT device after upgrading to 7.0.3

    2 iphone4s can's search any BT device after upgrading to 7.0.3
      it can work well with IOS 6.0.3, but fail to search any BT device with 7.0.3
       Tesing BT device
      1: Plantronics Voyager Legend earphone
      2: other Mobile phone BT ( available), and other MobileDevice can search this iphone and successfully paried, iphone can‘t search any device,
      Keep the “searching device”  status

    Hi toneyfeng,
    If you are having Bluetooth issues after updating to iOS7, you may find the following article helpful:
    iOS: How to troubleshoot Bluetooth connections
    http://support.apple.com/kb/TS4562
    Regards,
    - Brenden

  • Can os x server Profile Manager updates iOS os and appl installation?

    I've currently use Apple configurator to push profiles, update OS and app deployment to our College ipads. Have been told to use os x server to deploy instead. After upgraded the macbook air to mountain lion and install os x server, i'm kinda wondering does the profile manager in os x server is only for pushing out profiles and assigning users to the ipads etc? Do i still need to use apple configurator to do all the updates and appl installed first then use profile manager to push profile?
    We've got quite alot of ipads need setting up and we normal use a ipad case where one usb cable connect to the laptop and charging case to deploy our apps.

    How to configure ibm traveler as a profile for iOS devices:
    http://www.manageengine.com/products/desktop-central/configuring-ibm-traveler-fo r-ios-devices.html

  • Lion Server Profile Manager Configuration

    Hi Guys,
    Currently have been testing Lion Server and Profile Manager Configuration.
    So Far Have setup
    Lion with Server App and Server Admin Tools
    Configured Open Directory Master and enabled SSL on LDAP
    Once Configured OD has created a CA Certificate can use for Profile Manager
    Have Enabled in Server.app Web and Profile manager
    In SSL Certificate Configuration have set CA Certificate for Web and Enabled Apple push notifications with my apple ID
    In Profile Manager Enabled Device Management and Enabled Sign configuration profiles and selected CA Open Directory Certificate Created when setting up OD Master.
    On Server Originally could install Trust Profile OK and Enroll Server OK with no issues, but on any other 10.7 Devices could install Trust Profile OK but would always say unsigned and Enroll would never work or just hang.
    Now Since Played around with settings on 10.7 Server can no longer enroll but trust OK.
    Questions have is
    For SSL and Profile Manager to work properly as well as Certificates do you require to purchase a proper SSL Certificate or can we use the OD Master Certificate that gets created. All we are testing is on the Local LAN so don't want to get a SSL certificate from the internet.
    Also why cannot 10.7 clients trust profile and enroll Devices Properly? How do I get this working properly?
    Any ideas?
    Regards,
    Shane

    taubmas wrote:
    Not sure if its that as finally got Lion Server working on a VM setup so network shouldn't be an issue...
    Had 1 OSX Lion Server VM and 1 OSX Lion Client VM and OSX Lion Server VM gets profile and enrolls device fine but again OSX client doesn't get enroll just sits again at installing..... even if set keychain to trust and make trust profile verified..
    any other ideas? I think need to somehow get the server to trust trust profile by default instead of going to keychain all the time.
    Shane
    Did you get this to work in an ESXI envrionment? If so, which version are you running?

  • Lion Server Profile Management error reading settings

    After starting up Lion Server the profile management pane showed an error. It is also not possible to login via de browser to the profile manager. How can I fix this? Using the default httpd.conf file did not help.
    This is one of the many problems I have with Lion server that does not work as expected. So if someone has a solution to remove all profile settings from my client MBP than I can try to revert back to Lion on my server also.
    I hope this question is also read by someone of apple as this is not the quality I expected from apple. It lacks decent documentation and the setup of Portable Home Users is not possible. I thought apple product were self explaining and intuitive. This reminds me of the old Windows days: sitting days to figure it out and use a lot of terminal commands.

    Did you ever find a resolution? If not then this might help Server: An error with code -1 occurred while setting up Device Management

  • How to write .CSV file to import device placeholder into Lion Server Profile Manager?

    I'm now using Mac Mini with Lion Server (10.7.4). I've already setup a server with Profile Manager to manage some iOS devices.
    Now I need to add many devices into Profile Manager. From some articles, (for example http://my.safaribooksonline.com/book/-/9780132778879/chapter-4dot-managing-accou nts/ch04lev1sec3), I found that I can use .CSV file to import many device placeholders at a time. So I create a .CSV file "devices.csv" with the content as the following:
    iPhone001,12345ABCD12,,,
    Then I import this file to "Devices" in Profile Manager, but in vain. It says that the placeholder is invalid.
    If there's any one could provide some exemples? Thanks a lot.

    Hi Nien-Yi Ho,
    A little late, but perhaps someone else can benefit ...
    The way I did this, is:
    - create an empty Excel spreadsheet
    - add 5 headers in the first row: DeviceName, SerialNumber, IMEI, MEID, UDID
    - in the next rows add your devices and specs (for the iPhones and iPads I only added DeviceName, SerialNumber and IMEI specs)
    - IMPORTANT: save the file as a Windows CSV file.
    If you import the CSV file now, all should go well.

  • HT200088 Error Reading Settings in Lion Server Profile Manager

    Whenever I try to use Profile Manager in Lion Server, it says "Error Reading Settings". Can anybody help?

    I did a clean install of Lion/Lion Server, but I ran ino the same problem too with "Error Reading Settings" for both the profile manager and the wiki.
    INVESTIGATION: I checked to see if the postgres database (which I presumed was were the settings were being read from).
    # sudo serveradmin fullstatus postgres
    postgres:dataDirHasBeenInitialized = yes
    postgres:PG_VERSION = "9.0.4"
    postgres:dataDir = "/var/pgsql"
    postgres:postgresIsResponding = no     # !!! why isn't it responding???
    postgres:dataDirIsDirectory = yes
    postgres:PGserverVersion = 0
    postgres:dataDirExists = yes
    postgres:setStateVersion = 1
    postgres:state = "RUNNING"
    PROBLEM: The postgres service hadn't been started properly; I found this by doing the following:
    # sudo serveradmin stop postgres
    postgres:state = "STOPPED"
    # sudo serveradmin start postgres
    postgres:error = "CANNOT_START_SERVICE_TIMEOUT_ERR"
    FIX: The postgres service couldn't create the log file because it didn't have permission. I did this to fix it, then simply restarted it and all was well:
    # sudo chmod 777 /Library/Logs/
    # sudo serveradmin start postgres
    postgres:state = "RUNNING"
    I hope this helps someone.

Maybe you are looking for