Signing certificate expiration on enrolled iOS devices
The MDM signing certificate on iOS devices can display an expired date after server certificate renewal. This behavior does not affect device functions or communication with IBM® MaaS360®.
A digital signing certificate indicates that information that is sent from a server to a client is verified by a trusted source. The certificate authority that issues the certificate verifies the business and domain ownership to confirm that the site is legitimate.
During iOS device enrollment, Apple pushes a signing certificate to the device. This certificate is used for verification of MDM payloads.
Certificate behavior after server renewal
After the server certificate for the MDM primary is successfully renewed and its activation date passes, the signing certificate on iOS devices does not automatically update. The certificate continues to display the original expiration date on the device.
Impact
The signing certificate expiration display does not affect device functions. The following operations continue without interruption:
- Device reporting to the MaaS360 server
- MDM payload verification
- Application of MDM commands and policies
- Device communication with the server
The signing certificate is pushed by Apple during enrollment and is used only for verification of MDM payloads. There is no functions loss for the device.
Limitations
MDM cannot update the signing certificate on enrolled devices. The certificate update mechanism is controlled by Apple's enrollment process and cannot be modified through MDM commands or policies.
Resolution
No action is required. This behavior is expected for iOS devices that are enrolled in IBM MaaS360.
If you want to clear the expired certificate display on a device, reenroll the device. The certificate expiration message does not appear after reenrollment.