Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.
Some article numbers may have changed. If this isn't what you're looking for, try searching all articles. Search articles

How to Generate an APNs Certificate for Workspace ONE

Summary: How to Generate an APNs Certificate for Workspace ONE.

This article may have been automatically translated. If you have any feedback regarding its quality, please let us know using the form at the bottom of this page.

Article Content


Symptoms

Affected Products:

  • Workspace One

Affected Operating Systems:

  • iOS

Administrators of iOS devices must generate and upload an Apple Push Notification service (APNs) certificate in order to manage iOS devices. This guide shows Workspace ONE administrators how to quickly and complete this process by breaking it down into a few simple steps.

Cause

Not Applicable

Resolution

The Apple Push Notification service (APNs) is used to allow Workspace ONE to securely communicate to the smart device fleet over-the-air. Workspace ONE uses the APN's certificate to send notifications to devices when the Administrator requests information or during a defined monitoring schedule. No data is sent through the APN's server, only the notification.

Diagram of Apple Push Notification service
Figure 1: (English Only) Diagram of Apple Push Notification service

  • Access to the organization group’s Workspace ONE Administration Console
  • Apple ID (or ability to create an Apple ID)
  • Safari, Firefox, Chrome, or Edge web browser (Internet Explorer is not supported): Ensure to work through all the steps in this guide using the same browser session. The APN's generation process with Apple includes time-based and browser-based credentials for security purposes, which mandate following the steps in the Generating an APNs Certificate section to avoid any security or session-related errors. If one browser does not generate the certificate, try a different browser, but ensure to redo or complete all the steps in one session.
Note: If you are looking to renew an expiring APN's certificate, follow the process that is outlined in the Renewing APN's Certificate. Generating an APN's certificate should only be used for initial setups. If a new APN's certificate is generated from scratch, all previously enrolled devices must be reenrolled to become managed. If an APN certificate is expired, a new APN has to be generated.

Generating the APN's certificate is a three-step process:

  1. Download the AirWatch-signed CSR from the Workspace ONE Admin Console.
  2. Upload the AirWatch-signed CSR to the Apple Push Certificate Portal.
  3. Download the Apple-signed certificate (.pem) from the Apple Push Certificate Portal.
Note: To perform this task, ensure that your Workspace ONE Admin Account has access to the highest Workspace ONE Organization Group. The best practice is to complete the process at the Customer Organization Group level. If your Admin Account does not have access to the highest Organization Group, you may not be able to access the necessary settings.

Download the AirWatch-Signed CSR from the AirWatch Admin Console.

  1. Go to Groups & Settings > All Settings > Devices & Users > Apple > APNs For MDM and then select Generate New Certificate.

Select Generate New Certificate
Figure 2: (English Only) Select Generate New Certificate

  1. Provide the certificate request (step 1) to Apple to process and obtain your certificate, and then upload it into the Workspace ONE console.

Click MDM_APNsRequest.plist to download the request. If you already have an Apple Id select Go to Apple, and if you do not select Click here and following directions to create one.

Go To Apple
Figure 3: (English Only) Go To Apple

  1. Sign into the Apple Push Certificates Portal website using a valid Apple ID and password. If you have two-factor authentication enable, verify your identity by entering your Verification Code:

If the Go To Apple button fails to direct you to the portal, open a new tab and go to: https://identity.apple.com/pushcert/ This hyperlink is taking you to a website outside of Dell Technologies.

Apple Push Certificates Portal
Figure 4: (English Only) Apple Push Certificates Portal

Note: An Apple Developer Account is not required for sign-in. While any valid Apple ID works, we recommend you create a separate Apple ID linked to your corporate email account for long-term management.
  1. Click Create a Certificate.

Click Create a Certificate
Figure 5: (English Only) Click Create a Certificate

  1. Select the "I have read and agree to these terms and conditions" checkbox and click Accept.

Click Accept
Figure 6: (English Only) Click Accept

  1. Click Choose File and go to the AirWatch-signed CSR downloaded in Step 2. Find and select the certificate that you downloaded from Apple’s portal named: MDM_APNsRequest.plist

Choose File
Figure 7: (English Only) Choose File

  1. Click Upload (A new certificate for Workspace ONE MDM displays.)

Click upload
Figure 8: (English Only) Click upload

  1. Click Download and save the Apple-signed certificate to an accessible location.
Note: The document must be in .pem file format.
  1. Return to the Workspace ONE Admin Console and click Next.

Click Next
Figure 9: (English Only) Click Next

  1. Upload the Apple-signed certificate to Workspace ONE that was recently downloaded (.pem file). Enter the Apple ID used to sign into the Apple Push Certificates Portal website previously.

Update the Apple-signed certificate
Figure 10: (English Only) Update the Apple-signed certificate

  1. Click Save.
  2. This is a restricted action, so you must enter you security PIN.

Enter security PIN
Figure 11: (English Only) Enter security PIN

  1. Verify details on the APNs For MDM page.
Note: When generating and renewing at a top-level Organization Group, set child groups to inherit or override settings.
  1. Click Save and then x in the upper right corner, and you have completed the task.

To contact support, reference Dell Data Security International Support Phone Numbers.
Go to TechDirect to generate a technical support request online.
For additional insights and resources, join the Dell Security Community Forum.

Article Properties


Affected Product

VMWare AirWatch, Workspace One

Last Published Date

06 Jul 2023

Version

9

Article Type

Solution