If you are encountering issues with the expired APNs certificate on the TMMS server, please follow the steps below to recreate and update the certificate:
- Generate Certificate Signing Request (.txt)
Open the following link to generate a Certificate Signing Request (.txt):
https://success.trendmicro.com/solution/KA-0002760 - Trend Micro APNs Certificate Signing Portal
Access the following link to access the Trend Micro APNs Certificate Signing Portal:
https://www.trendmicro.com/product_trials/apn/index/us/129?_ga=2.113699143.1584961293.1636077737-1303291367.1630466304
Copy and paste the information from the CSR cert request (.txt). - Apple Push Certificates Portal
Access the following link to access the Apple Push Certificates Portal:
https://identity.apple.com/pushcert/
a. Click create certificate
b. Upload the CSR_signed_by_TrendMicro (.certSigningRequest)
c. Click Upload
d. Download the Certificate uploaded on the apple pust certificate portal - Complete the Certificate
a. Go to IIS Server Certificates
b. Click Complete Certification Request. Upload the file MDM_ Trend Micro Incorporated (Ent)_Certificate.pem (.pem)
Note: Rename (.pem) to (.cer)
c. Friendly Name: Trend Micro Mobile Security for Enterprise MDM APNs - Export the .pfx file in the Server Certificate
a. Click Export Certificate
b. Export and Save file as TMMS_MDM.pfx
c. Type the password and confirm password. Click ok - Upload TMMS_MDM.pfx
a. Log in to the TMMS console
b. Go to administration certificate management
c. Click add then upload the TMMS_MDM.pfx (.pfx)
d. Type the password.
e. Click ok - Configure Apple Push Notification service (APNs) Settings
a. Go to administration Communication Server Settings
b. Click IOS Settings. Choose the apple certificate.
c. Go to Client Profile Signing Credential. Choose the apple certificate.
d. Click save
If the TMMS APNs have been recreated properly before it has expired, there should be no need to perform re-enrollment to the iOS devices. However, since the TMMS APNs have already expired last August 5, 2023, you will need to re-enroll each iOS device in order to get the new certificate. Before re-enrollment, please make sure to delete the MDM profile from the iOS device. Please let us know if the issue gets resolved after re-enrolling the iOS devices.