An iOS Device Has Not Shown Online Activity
Problem
Section titled “Problem”An iOS device has not shown online activity and is not checking in with CapaOne. This can happen for one of two reasons:
- The device is offline — it has no network connectivity and cannot reach CapaOne.
- The Push Certificate is broken or has not been renewed — CapaOne communicates with iOS devices through Apple’s Push Notification service (APNs). If the Push Certificate used to enroll the devices is no longer valid or has been replaced, the devices lose their connection to CapaOne and will not check in.
The most common cause — creating a new Push Certificate instead of renewing
Section titled “The most common cause — creating a new Push Certificate instead of renewing”A very common mistake is going to the Apple Push Certificate Portal and creating a brand new Push Certificate instead of renewing the existing one.
When a new certificate is created, it gets a different APSP number than the one that was originally used to enroll the devices. This breaks the chain of trust between CapaOne and all currently enrolled devices. Those devices will no longer communicate with CapaOne — and this cannot be fixed by simply clearing the queue or restarting the device. The only resolution is to ensure that the original certificate is renewed (not replaced) and uploaded to CapaOne.
How to identify if the wrong certificate was uploaded
Section titled “How to identify if the wrong certificate was uploaded”You can verify which Push Certificate is active on a device by comparing the APSP number:
- On the Apple Push Certificate Portal (identity.apple.com/pushcert), note the APSP number of the certificate that is uploaded in CapaOne.
- On the iOS device, go to Settings > General > VPN & Device Management.
- Tap the MDM profile (CapaOne) and look under Signed by — this shows the APSP number of the certificate the device was enrolled with.
The APSP number from the portal and the APSP number on the device must match. If they do not, the wrong certificate is active in CapaOne.
Solution — Renewing the SCEP certificate on the device
Section titled “Solution — Renewing the SCEP certificate on the device”If the device is simply offline or the Push Certificate has been correctly renewed but the device has not yet checked in, follow these steps:
Steps to get the inactive device online in CapaOne.
-
Login to Capaone.
- Go to Apple → Enrollment.
- Find the Enrollment Profile that was originally used to enroll the iPhone/iPad.
- Click on View (you should now see a QR code).
-
Open the Camera app on the iPhone/iPad.
- Now scan the QR code from the enrollment profile and click the link.
- Navigate to General > VPN & Device Management.
- Find the SCEP Certificate and press install.