Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

Renewing the Apple Push Notification service (APNs) certificate for Mobile Security (TMMS) for Enterprise

    • Updated:
    • 21 May 2021
    • Product/Version:
    • Mobile Security For Enterprise
    • Platform:
    • iOS 9.x

APNs certificate downloaded from Apple only have one year validity from the date the certificate(s) was created. To make sure the managed iOS devices do not have to be re-enrolled into TMMS for Enterprise, the APN certificate has to be renewed before it expires.

If the APNs certificate is already expired, the renewal steps will no longer work. A new APNs certificate will have to be generated and the mobile devices re-enrolled.


Follow these steps to renew the APNs certificate so users won't have to re-enroll their iOS mobile devices:

  1. Log in to the Apple Push Certificates Portal you used to generate your previous APNs certificate.
  2. On the Portal click Renew.


  3. It will redirect to the page requesting Vendor-signed CSR. Follow the KB article to create the Certificate Signing Request. 
  4. Go to Trend Micro Website  Apple Push Notification Certificate Signing Request Form for us to sign the generated CSR. Then use the Vendor-signed CSR on the Apple Website to proceed with the renewal.
  5. Download the new certificate from Apple APN Certificate Portal.
  6. Change the extension name of the renewed certificate from PEM to CER (e.g. Mobile Device Management.PEM to Mobile Device Management.CER).
  7. Go to IIS Manager ServerName Server Certificates.
  8. On the right pane, click Complete Certificate Request. The Complete Certificate Request Wizard will appear.
    If you are using IIS 7.5, clicking the complete Certificate Request may display the following error message:

    "A certificate chain could not be built to a trusted root authority."

    If this happens, refer to Page C-17 in Configuring IIS 7.5 for APNs Certificate Installation for the procedure to resolve this issue.

  9. Locate the CER file.
  10. On Friendly Name, type Trend Micro Mobile Security for Enterprise MDM APNs.
  11. Follow the prompts and complete the wizard.
  12. Verify that your Apple Production Push Services certificate appears on the Server Certificates list.
  13. Right-click the certificate in the Server Certificates list, and click Export.
  14. Select the location where you want to save the file, choose a password for exporting, and then click OK.
    If you are using a Mac Workstation to install the APNs certificate, please refer to Page C-22: Step 3. in Installing your APNs certificate.
  15. Re-upload the certificate to Mobile Security for Enterprise console. Please refer to Page C-23 in Installation and Deployment Guide, for the steps.
    TMMS for Enterprise has a notification feature that will notify an administrator one month prior to the APN expiration date. Refer to Page 4-20: Configuring Administrator Notifications in Installation and Deployment Guide for TMMS.

Please refer to the screenshot below for the expected result, which shows the APNs certificate having the same Credential name but a new Expiration Date:


Solution Id:
Did this article help you?

Thank you for your feedback!

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.