There's a new home for Articles. Find Articles on Our Product Support Page.
Hi everyone Anyone have seen this issue before? It all started in february. More than 5k Android tablet have this error at check-in (logs mobicontrol) now. Deployment Server error (Failed to retrieve and issue Client Certificate. Device may not be able to communicate on subsequent connections.) The enrollment time (in the Information tab) for this tablet is 2015-10-20. If we go to Certificates tab in Mobicontrol, we actually see that the certificate will expire in 2 months (April). The thing is that we checked all our deployment server certificate and the expire date is in 2030 same as the Mobicontrol Root. We are on the 13.4.0.5519 version Thanks
I have trouble when enrollment laptop windows 10, I do it based on certificate, not long ago I did it successfully, and it works normally, but now it doesn't work anymore.I hope to receive your support. Many thanks! https://ibb.co/mXNNzL4 https://ibb.co/g4VnPdrhttps://ibb.co/n7Lz2mg
Hello together, i need to get the Zebra MC 93 with Oreo 8.1 connected to our WLAN.I created already two profiles for the device to push the certificates manually: The certificates are already installed on the device but i can not choose the certificate for the WLAN the CA and client certifacte are not choosable in the WLAN. Do you have any idea what the issue should be?Which format does the certificates need?
Hello everybody I have a problem to enroll devices under android 10I have a message that says "failed to connect to the server. SSL negotiation failed. And i have one message on my server who said me this: Can you help me please?
Hello All, im newbie with mobicontrol and i looking for the best way to provide an SSL certificate to our devices. We use TC51/56/MC33 with Android 8.1 with Enterprise Browser 3.0.0.1 Agent for non-gms 14.3.3.1038 for GMS 14.3.0.1000 Our mobicontrol version is 15.0.1.1181 The idea whas to use an script created with MCStudio and a profile. The script look like it: certimport -cert "filepath (path where the file comes from ;Server or Soti?)" -ctype CERT What is your proposal for import the certificate? Thank you Guenniko
Hello Is there a way to check which certificate (DS) a device using ? I enrolled multiple devices using SHA1, then SOTI installed SHA2 (to support Android 10). Now I need to attach the new SHA2 certificate to Deployment server but I need first to double check that SHA2 certificate has been learned by all devices. Is there a way to do that "easliy" ? steve
Hi everyone, We recently deployed 30 Android devices. They have been enrolled while being on Android OS 9. Some end-users updated their devices and now Mobi app doesn't connect anymore to our DS. The reason is that our mobicontrol server have a self-sign certificate with SHA1 and Android 10 doesn't support it. We have an inventory of Windows Mobile CE 6.5 (which don't support TLS 1.2) and we don't wanna update this certificate yet because it would disconnect all those PC pockets. I've pushed a script to disable the system OS update but I believe this script only last 30 days on Android Enterprise devices. Is pushing the script again after 30 days will extend the policy ? Thanks for your help,
Hello, Can I use MobiControl to assign certificate to a Zebra wireless printer? The customer only support DCOM or NDES protocol. Regards, Tal.
It was brought to our attention that certain versions of MC have already started alerting on the MC web console that the DSE cert is expiring in 90 days. We are aware of the certificate expiry notification and like every year, SOTI will renew the certs and roll it out on all servers before the expiry. There is NO immediate action required from customers or our support/PS at the moment. As we are currently managing the cloud instances, SOTI will be renewing the certificates. Regards,
Hey there, I am trying to move some devices to a new install of Mobicontrol on a different server. I have a new SSL cert in place and have had some success enrolling new Android+ devices to it. I had some keep giving me "Connection to server failed, an error occurred during the process". I was able to get some devices to work moving between servers if I choose the remove certificates when unenrolling. However, a customer site cannot re-enroll their devices without this error. I have a ticket open but wanted to see if others were able to freely move devices around servers as I think should be allowed. I wonder if it is a certificate issue? Also, it seems like if I enroll with one server I am locked in, and try to enroll elsewhere and get this error. Now I cannot enroll devices from the new server back to the old: 2019-10-29 14:06:59,714 (0x00001da8) [INFO] MessageQueue::<AddWorkerThread>b__49_0() [328] New worker started2019-10-29 14:07:10,633 (0x000012f8) [INFO] MessageProtocolHandler::<Start>b__33_0() [ 31] PulseChecker enter: Send: False, Check: True, Memory: 120382192, ThreadPool: 32767, 999, Queue: 0, Workers: 202019-10-29 14:07:10,633 (0x000012f8) [INFO] MessageProtocolHandler::<Start>b__33_0() [ 31] PulseChecker exit: Total: 28, Connected: 4, Dropped: 0, Retried: 0, finished in 0 ms2019-10-29 14:07:26,998 (0x00000e8c) [INFO] Client::Accept() < 75> Comm.Client.2042: Accepted a new connection from [::ffff:173.162.166.161]:26610.2019-10-29 14:07:27,154 (0x00002b94) [INFO] <OnReceived>d__44::MoveNext() <210> Comm.Client.2042: Client [::ffff:173.162.166.161]:26610 authenticated. Cipher: Aes256/2562019-10-29 14:07:27,295 (0x000030fc) [ERROR] CCommDeploymentSrvWorker::OnInstallStatusMsg() OnInstallStatus: Error 2 getting device info, connection 2042, device 87f4230b56ef7bdc2019-10-29 14:07:27,420 (0x00002fbc) [ERROR] <OnReceived>d__44::MoveNext() <405> Comm.Client.2042: Connection with [::ffff:173.162.166.161]:26610 has been reset.2019-10-29 14:07:27,420 (0x00002fbc) [INFO] MessageQueue::AddNewWorker() <405> MQ: Queue length 1, total threads 20, waiting threads 0, adding 1.2019-10-29 14:07:27,420 (0x00002e88) [INFO] MessageQueue::<AddWorkerThread>b__49_0() [403] New worker started Support is talking about doing a factory reset, which is a big issue for my distributed machines.
Hi all I see the following error when accessing the web console lately... mobile.abc.co.uk normally uses encryption to protect your information. When Google Chrome tried to connect to 350mobile.bvt.org.uk this time, the website sent back unusual and incorrect credentials. This may happen when an attacker is trying to pretend to be mobile.abc.org.uk, or a Wi-Fi sign-in screen has interrupted the connection. Your information is still secure because Google Chrome stopped the connection before any data was exchanged. You cannot visit mobile.abc.co.uk right now because the website uses HSTS. Network errors and attacks are usually temporary, so this page will probably work later. We do have a wildcard certificate for our domain but I'm a little nervous about applying it and what impact that would have on our mobile devices. Is there a correct procedure for this?
Hell all, we have mobicontrol in version 13.3.0.3454 We have a lot of device in zebra TC75X with android 6 and 7. the client mobicontrol is on version 13.3.2 build 1014 actually, we migrate all url we call in http to https. i can install the certificate on the device without problem all works fine. I would like to know if some people has experience with certificate. Is it better to add the certificate in a separate profile or it's better to add the certificate in the main profile (where authentifcation kiosk is added) ? Actually, for testing i have created a separate profile who contains just the certificate I have a main profile where i have (bookmark, kiosk, …) and so on. I can install all, remove all, all seems to work but i would like to have some advice or suggestion. thanks for sharing your knowledge
Hello ! I would like to deploy (manually for the moment and for testing purposes) a Certificates Profile that contains a PKCS#12 certificate (with a .p12 extension). I have the impression that this is not possible because once assigned, the profile does not deploy. It remains in a "Pending Install" status and I have an error message in the device logs : Error Device configuration failed ([Certificates] Configuration failed to apply) When I edit the profile and download the certificate provided (with .p12 extension), it downloads me a file in .cer extension. Maybe for security reasons, I don't know. How can I deploy my p12 file on a test device ? (MC server 14.3.3 - Android Enterprise DO) Thank you !
It seems that, if you want to deploy a certificate (using a Certificate configuration in a Policy), you also have to deploy an Authentication policy, according to the warning shown below: So we created an Authentication Policy too, and it surprises us to see that it's not necessary to define a User Password Policy.The 'Device Administrator Password' setting is enough. Is this logical? Because, when installing a certificate on a non-MobiControl-managed device (plain, out-of-the-box Android), one must configure a pincode on the device before a certificate can be installed... SOTI Support has been contacted & have indicated to us that 'if it's working for you right now, it will be ok', but I'm interested in the deeper philosophy behind the above... ;)
Hi, Any suggestions as to why Zebra devices wont enable network interfaces before a PIN has been entered? We are requiring a device PIN due to a certificate profile on the device. However when soft resetting the device, we are prompted for device pin (naturally). However the network interfaces are not enabled until the PIN has been entered, thus effectively cutting of a branch for the mobicontrol administrator. (The devices still have an administrative WPA2 network available). This is not the case for Samsung devices, they will activate interfaces to the network just fine before entering PIN. Any suggestions or workarounds?
Top-tier experts who are delivering outstanding content. Should have more than 7000 points.
Experts who are consistent with great content. Should have more than 1000 points.
Highly experienced members with valuable inputs. Should have more than 700 points.
Beginners taking the initiative. Should have more than 500 points.
New contributors starting their journey. Should have more than 250 points.