eScan BlogeScan Blog    eScan WebsiteeScan Website    eScan ForumeScan Forum    eScan FeedseScan Feeds     
    
Languages:     

From eScan Wiki

(Difference between revisions)
Jump to: navigation, search
Revision as of 08:03, 26 March 2018
WikiSysop (Talk | contribs)
('''Pre-Requisites for Managing iOS Devices''')
← Previous diff
Revision as of 09:06, 26 March 2018
WikiSysop (Talk | contribs)
('''Pre-Requisites for Managing iOS Devices''')
Next diff →
Line 26: Line 26:
'''A. To add the certificate when you log into the eScan Corporate 360 console for the first time:''' '''A. To add the certificate when you log into the eScan Corporate 360 console for the first time:'''
 +<ol>
 +<li>Click on '''[https://www.escanav.com/en/solutions/enterprise-mobility-management.asp eScan Mobility Management (EMM)]'''.
-1. Click on '''[https://www.escanav.com/en/solutions/enterprise-mobility-management.asp eScan Mobility Management (EMM)]'''.+It opens the EMM console use only for Android and iOS devices.</li>
-It opens the EMM console use only for Android and iOS devices.+<li>Under '''To manage iOS devices you need to add a Trusted CA Certificate,''' click on '''Start with iOS.'''
 +It opens a new window where you can import your certificate files.</li>
-2. Under '''To manage iOS devices you need to add a Trusted CA Certificate,''' click on '''Start with iOS.'''+<li>'''Browse''' the file from your local drive.</li>
-It opens a new window where you can import your certificate files.+
- +
-3. '''Browse''' the file from your local drive.+
- +
-4. Click on '''save'''+
 +<li>Click on '''save'''</li>
 +</ol>
'''Note:''' Make sure you add an authentic CA certificate in .crt file format and .key file format for the key. Self-signed file will not be accepted. '''Note:''' Make sure you add an authentic CA certificate in .crt file format and .key file format for the key. Self-signed file will not be accepted.
'''B. To add the CA certificate if ''' '''B. To add the CA certificate if '''
- +<ol type="square">
-i. You had selected to proceed with "'''Start with Android (without iOS)'''" earlier+<li>You had selected to proceed with "'''Start with Android (without iOS)'''" earlier</li>
'''or''' '''or'''
-ii. You have deleted the previous certificate please follow the steps below:+<li>You have deleted the previous certificate please follow the steps below:</li>
- +</ol>
-1. On the left menu click '''Settings'''.+<ol>
 +<li> On the left menu click '''Settings'''.</li>
-2. Select '''Certificate Management''' tab.+<li> Select '''Certificate Management''' tab.</li>
-3. Click the '''Add''' button.+<li> Click the '''Add''' button.
-The '''Add Certificate''' window is displayed.+
-4. '''Browse''' the file from your local drive.+The '''Add Certificate''' window is displayed.</li>
-5. Click on '''save'''+<li> '''Browse''' the file from your local drive.</li>
 +<li>Click on '''save'''</li>
 +</ol>
'''What is a CA certificate?''' '''What is a CA certificate?'''

Revision as of 09:06, 26 March 2018

Pre-Requisites for Managing iOS Devices

Overview

The eScan EMM requires a SSL certificate to manage your iOS devices from the EMM console. This document gives you information on all the pre-requisites for managing iOS devices and how you can import the SSL certificate .It also briefs on what the certificate is about and where you can purchase the same.


Steps required:

  1. Make sure you have a dedicated IP. You can have static IP or use NATing *
  2. Decide on a domain name.You need to decide a domain name for your EMM console to which the connecting devices are directed to your server, for ex: emm.abc.com.
  3. Acquiring the C.A certificate from an Apple approved CA**
  4. Add A-record
  5. Import certificate and start managing your iOS devices *If you are using NATing please refer this document for more information.
    ** List of Apple Approved CA
    https://support.apple.com/en-us/HT204132

How to import a C.A certificate on the eScan Corporate 360 EMM console?

A. To add the certificate when you log into the eScan Corporate 360 console for the first time:

  1. Click on eScan Mobility Management (EMM). It opens the EMM console use only for Android and iOS devices.
  2. Under To manage iOS devices you need to add a Trusted CA Certificate, click on Start with iOS. It opens a new window where you can import your certificate files.
  3. Browse the file from your local drive.
  4. Click on save
Note: Make sure you add an authentic CA certificate in .crt file format and .key file format for the key. Self-signed file will not be accepted.


B. To add the CA certificate if

  1. You had selected to proceed with "Start with Android (without iOS)" earlier
  2. or

  3. You have deleted the previous certificate please follow the steps below:

  1. On the left menu click Settings.
  2. Select Certificate Management tab.
  3. Click the Add button. The Add Certificate window is displayed.
  4. Browse the file from your local drive.
  5. Click on save

What is a CA certificate?

To manage iOS devices on the EMM console you are required to add a trusted CA certificate. A certificate authority (CA) is a trusted entity that issues electronic documents that verify a digital entity’s identity on the Internet. The digital certificate is an essential part of secure communication and plays an important part in the public key infrastructure (PKI). Certificates typically include the owner's public key, the expiration date of the certificate, the owner's name and other information about the public key owner.


Why is a CA Certificate required?

The certificate is from a trusted third party who is responsible for physically verifying the legitimacy of the identity of an individual or organization before issuing a digital certificate. It guarantees that the individual granted the unique certificate is, in fact, who he or she claims to be. This allows others (relying parties) to rely upon signatures or on assertions made about the private key that corresponds to the certified public key.


How to purchase a CA certificate?

Please contact an authentic SSL certificate issuing authority (like Lets Encrypt (free provider), Rapid SSL , Comodo etc.) to purchase a CA certificate. Make sure the certificate they issue is mentioned among the list in the link below.

List of Apple Approved CA https://support.apple.com/en-us/HT204132


How to create your A-record for the dedicate IP?

Creating an A- record will re-direct anyone who visits your EMM to the dedicated IP. For more information on creating your A-record please contact your ISP.


Deployment Scenarios

The eScan EMM for iOS devies can be used in the scenarios recommended as below.

Scenario 1:

eScan server is installed on a system and a Static IP (Public IP) is assigned to the system.

Scenario 2: eScan server is installed on a system locally and NAT with port redirection is done to the server system.

Scenario 3: Usage of Dynamic DNS as an alternative for Native DNS services is not recommended.


Note:

1. SSL Sniffing devices provide their own Certificate, which would be rejected by EMM and iOS during the validation process. Disable SSL Sniffing for Network Interfaces of EMM.

2. Self-Signed Certificates are not accepted.


eScan Copyright © 2015 MicroWorld Technologies Inc.- AntiVirus & Content Security.       Send your feedback to solutions@escanav.com eScan Wiki

    Privacy policy  About eScan Wiki  Disclaimers