Note: If you are looking to
renew an expiring APNs certificate, follow the process that is outlined in the
Renewing APN's Certificate. Generating an APN's certificate should only be used for initial setups. If a new APN's certificate is generated from scratch, all previously enrolled devices must be reenrolled to become managed. If an APN certificate is expired, a new APN has to be generated.
Generating the APN's certificate is a three-step process:
- Download the AirWatch-signed CSR from the Workspace ONE Admin Console.
- Upload the AirWatch-signed CSR to the Apple Push Certificate Portal.
- Download the Apple-signed certificate (.pem) from the Apple Push Certificate Portal.
Note: To perform this task, ensure that your Workspace ONE Admin Account has access to the highest Workspace ONE Organization Group. The best practice is to complete the process at the Customer Organization Group level. If your Admin Account does not have access to the highest Organization Group, you may not be able to access the necessary settings.
Download the AirWatch-Signed CSR from the AirWatch Admin Console.
- Go to Groups & Settings > All Settings > Devices & Users > Apple > APNs For MDM and then select Generate New Certificate.
- Provide the certificate request (step 1) to Apple to process and obtain your certificate, and then upload it into the Workspace ONE console.
Click MDM_APNsRequest.plist to download the request. If you already have an Apple Id select Go to Apple, and if you do not select Click here and following directions to create one.
- Sign into the Apple Push Certificates Portal website using a valid Apple ID and password. If you have two-factor authentication enable, verify your identity by entering your Verification Code:
If the Go To Apple button fails to direct you to the portal, open a new tab and go to: https://identity.apple.com/pushcert/
Note: An Apple Developer Account is not required for sign-in. While any valid Apple ID works, we recommend you create a separate Apple ID linked to your corporate email account for long-term management.
- Click Create a Certificate.
- Select the "I have read and agree to these terms and conditions" checkbox and click Accept.
- Click Choose File and go to the AirWatch-signed CSR downloaded in Step 2. Find and select the certificate that you downloaded from Apple’s portal named: MDM_APNsRequest.plist
- Click Upload (A new certificate for Workspace ONE MDM displays.)
- Click Download and save the Apple-signed certificate to an accessible location.
Note: The document must be in .pem file format.