Updating Certificates for Workspace ONE UEM Services

I subscribed to the knowledge base articles within the VMware Workspace ONE customer portal, and the one below flew into my inbox a few weeks ago.

Hopefully, you or someone at your team take a proactive approach and renew various certificates used in your Workspace ONE UEM environment well before they expire. Failure to do so can have serious consequences (i.e. unexpected phone call from your boss or worse your CEO.)

There are several places where the certificates are used and expire. I will cover some of them here as I don’t use all the ones listed per the link above. Generally, there are three major types of certificates:

Public SSL Certificates

Update for the console server, device services server, application programming interface server

CertRenewal1.jpg

CertRenewal2.jpg

CertRenewal3.jpg

CertRenewal4.jpg

CertRenewal5.jpg

CertRenewal6.jpg

Perform an IIS reset . Afterward, navigate to your console URL and verify the certificate matches with the new one.

CertRenewal7.jpg

Signing Certificate

Within the web console, browse to GROUPS & SETTINGS -> All settings -> Devices & Users -> Apple -> Profiles. Click REPLACE and follow the steps accordingly.

CertRenewal8.jpg

As noted in the VMware Workspace ONE documentation, devices that were already enrolled with the expired certificate will simply show Not Verified. However, there’s no impact on functionality. Additional info can be found via this link: Signing Certificates

FW_ Profile signing certificate is showing as expi

APNS Certificate

Be sure not to confuse APNs for applications with APNs for MDM . The later is required to manage iOS with any MDM solution.

I also came across the VMware KB below which explains the importance of renewing this certificate well before it expires.

For steps to renew APNs for applications, check out my other post here.

There are some Dos and Don’ts you must keep in mind: