Community - SOTI MobiControl

Community - SOTI MobiControl

There's a new home for Articles. Find Articles on Our Product Support Page.

SOTI MobiControl Discussions


  • 0 votes 1 answer

    Uninstall Android application when removed from profile

    I've just noticed that application stays on device after being removed from profile. Is it expected behavior or I've messed up with profile configuration (didn't increment version) ?

    Android
    8 years ago
  • 1 votes 2 answers

    list of variables that we can use in a script for android+ devices Solved Locked

    Wondering please is there a list of variables that we can use in script like %IP% or %Devicename% is there a list of all other variables 

    Android
    8 years ago
  • 0 votes 1 answer

    WebConsole analog of "POST /devicegroups/{path}/members" method Solved

    SOTI mobicontrol API allows to move devices between groups using device identifiers. However, in WebConsole, the only way I've found so far is through Device Relocation Rule, which requires you to set custom attributes. Is there analog of "POST /devicegroups/{path}/members" API method in WebConsole?

    SOTI MobiControl
    8 years ago
  • 0 votes 10 answers

    Can length 1024-bit MobiControl root certificates in old v11-v13 MoibControl implementations be eventually uninstalled without requiring device re-enrollments?

    Many of my corporate and governmental customers have new internal security policies to phase out all weak length 1024-bit certificates in the IT infrastructure.   Many asked about migration of their existing v11/v12/v13 length-1024-bit  MobiControl root certificate to length-2048-bit.  As they have hundreds or thousands of devices enrolled & deployed, they cannot tolerate large-scale device recall and re-enrollment.   Someone from Soti support team informed me about the procedure to use MCadmin to install, bind and push the new 2048-bit root certificate to all enrolled devices.  However , he hadn't confirmed with me whether or not the old 1024-bit root certificate can eventually be removed from all the migrated devices and from the v11/v12/v13 MobiControl server. He then left Soti in early 2018 with the question not completely answered. Does Soti provide a complete SEAMLESS MIGRATION solution to TOTALLY phase out its old weak root-certificate for old customers to pass more modern security policies?  

    SOTI MobiControl
    8 years ago
  • 0 votes 4 answers

    How to AUTHORIZE a unique WIFI acces point ? Solved

    Hello all, we use MC browser on version 13.3.0.3454 and on mobile under android we have the client on version 13.3.2 build 1014. Our app has need to access a wifi access point ..and we 'd like if it's possible with MOBICONTROL to restrict to connect ONLY on this wifi point ? if yes, how we can do this ? thanks for all

    Android
    8 years ago
  • 0 votes 5 answers

    Can enrolled devices upgraded to the forthcoming iOS12 stay under full control in an old (v10-v13) implementation using 1024-bit MobiControl Root Certificate?

    Forthcoming iOS12 requires all MDM/EMM solutions to use an SSL certificate with minimum key-length of 2048-bit and using at least SHA2 hashing.  Is there similar new requirement(s)  for the root certificate in the MDM server?    In particular, can all iOS 10/11 enrolled devices stay under full control by a v10-13 MobiControl server using length-1024-bit self-signed root certificate, when such devices are upgraded to iOS12?

    iOS
    8 years ago
  • 0 votes 4 answers

    Trouble with honeywell d60s

    Hi,  I am trying to provision a Dolphin 60s to Soti without much success. I installed manually MCBootstrapAgent.CAB in the device then I scanned the bar code generated by Ezconfig. After a reboot wifi is working. But In Soti I get an Error message: Number of configured device has reached the licensed number (Failure to add new device, license service doesn't work well or the number of available licenses has been exceeded. Device family: All. Device type: 0.) I have plenty of available licenses thought. What to do? I am thinking that maybe the MCBootstrapagent.exe is not ok... What to do? Kind regards,

    SOTI MobiControl
    8 years ago
  • 1 votes 1 answer

    Android SSL Handshake failed

    Hi, We installed Mobicontrol V14.1.4 on our production server. All the statuses on the MCAU are green. However, the devices aren't being enrolled successfuly. We have the error "SSL handshake failed" as shown in the screenshot below. The android devices are connected to a local network without internet access. The mobicontrol server is on the same network but has internet access. We enrolled the devices with the mcsetup.ini file. The devices aren't shown in the device tree in the mobicontrol console. Can you help me? Thanks,

    Android
    8 years ago
  • 0 votes 5 answers

    Re-Enrolling Devices to Change Naming Convention

    Hello, I was wondering if anyone on the forum had success re-enrolling devices using a script in order to rename the devices.  We started enrolling some new Android barcode scanners and went about our testing and now we need to get them all to use the same naming convention:  A%AUTONUM%  We have 80 devices and I would prefer to not have to manually change the device names on each and everyone. Thanks, Patrick

    Android
    8 years ago
  • 0 votes 3 answers

    Content Library

    Is it possible to add a username and password to the UNC utilized in Content Library?  I've attempted to utilize the \\server\Shared\file.docx,u=user,p=password  syntax from https://www.soti.net/mc/help/v14.1/en/console/reference/dialogs/rules/filesync/linux/filesync_filescard_linux.html along with \\server\share /user:test testpassword that was provided to me via SOTI support from https://serverfault.com/questions/580369/windows-shares-via-command-line-with-user-pass-without-mapping-the-drive however, as soon as I go to insert anything outside of the UNC it give an error “Must be a valid file path”. The only way I've successfully tested the Content Library is on a share that is wide open, but unfortunately that is not an option. Current SOTI version: 13.4.0.4591      

    Android
    8 years ago
  • 0 votes 3 answers

    Phone number of kiosk

    Is it possible to add the phone number to the Android lockdown screen? Nothing is displayed when we add %PHONENUMBER% to the HTML template.  MobiControl version is 14.1.Android 5 on Zebra TC75s.

    Android
    8 years ago
  • 0 votes 2 answers

    Android Enerprise VPN

    Hi  With Android Plus i have many Options for VPN, like F5 per App VPN, SSL VPN and IPSec. Are these VPN's on the Roadmap for Android Enterprise? With Android Enterprise i see only Pulse Secure and NetMotion Best regards Markus

    Android
    8 years ago
  • 0 votes 3 answers

    Server domain migration

    So I got this case in my lap this week and wile waiting on support to get back to me I would check if anyone has some tips around this: So customer are updating their domain from "OldCompany.org" to NewCompany.org"Evry request to https://OldCompany.org is now routed to "https://NewComapny.org" in their firewalls and load balancer, I got message that the connections is traced and firewalls changed for this and no drops are recorded at the moment. From this step the Admin Utility was updated and changed on following:- Primary Agent Adress: NewCompany.org : 5494- Secondary Agent Adress: OldComapny.org : 5494- Device Management Adress: NewComapny.org : 443- Management Service Address: NewComapny.org : 443 - Fully Qualified Domain Name/IP Address: NewCompany.org : 5494- Alternate Fully Qualified Domain Name/IP Address: "Server IP" As I can se this gave a bunch of error messages for the Deployment Server but after changes in their Firewall all test and System Healt says OK. It was also tested by generate a new Certificate and change Deployment Server Extension & Web Console from OldCompany.org to NewComapny.org All test and System Healt is OK, Root Certificate is listed whit 2x Certificates.Management Servers in MobiControl is listed whit OldCompany.org whit old IP as inactive and NewCompany.org as active whit correct IPSo it is listed twice? OldCompany.org/MobiControl is no longer working but NewCompany.org is OK, NewComapny.local is OK, no issues around SSL certificate and it is certified by server and not using wildcard by LB/Firewalls as it did before. So issue one is, if we try enroll a new unit whit a new add device rule on their very strict network we are not able to enroll by ID or URL, URL is not being validated.Trying same enrollement from Internet it is all ok, unit are enrolled.Tracing this now there is no drops in the network due to firewall rules or routes. Issue 2, when trying Remote Control the connection is dropped.Tracing outgoing from server we cannot find any drops. Checking the log on the unit we find that log says unit tries the enrollment for NewCompany.org but switches over to OldCompany.org before getting connection for enrollment. From server ports and internet access is checked, reaching Soti services and such.Added some error messages from server logs: 2018-08-15 13:48:42,296 (0x00000e90) [INFO] CWinLogFile::WriteAllLog() SSL: Connection info: Protocol=00000040, Exch=0000AA02 (1024), Hash=00008004, Cipher=00006610 (256) 2018-08-15 13:48:43,296 (0x00001ae0) [ERROR] CCommDeploymentSrvWorker::VerifyClient() VerifyClient: Unverified client certificate ffffffff (Remote certificate not provided), device 359998043396839 on connection 20 2018-08-15 13:48:43,421 (0x00001ae0) [INFO] CertificateInstaller::InstallDeviceCert() Generate certificate for device 359998043396839 2018-08-15 13:48:43,921 (0x00001ae0) [INFO] CertificateInstaller::InstallDeviceCert() [CertificateInstaller::InstallDeviceCert] Certificate (id=10002788) pushed to device (id=359998043396839) 2018-08-15 13:48:44,296 (0x00001ae0) [INFO] CSOTIDatabase::ErrorCodes __cdecl CSOTIDatabase::SetDeviceInstalledCertList() SetDeviceInstalledCertList: Certificate: 10002788 for device '359998043396839' is not reported in snapshot 2018-08-15 13:48:44,609 (0x000012ec) [INFO] CWinLogFile::WriteAllLog() New connection entry, index=21, name=*, host=10.46.15.254, sock=5276, port=61054 2018-08-15 13:48:44,609 (0x0000108c) [ERROR] CWinLogFile::WriteAllLog() ConnThread: index=21 (): 0 byte received, socket closed ### 2018-08-15 21:20:36.077 ERROR [167]: ************************************************************************************************************ * Exception: No connection could be made because the target machine actively refused it 138.xxx.xxx.xxx:5495 * ************************************************************************************************************ [EndpointNotFoundException: Could not connect to net.tcp://NewComapny.org:5495/mc/cache. The connection attempt lasted for a time span of 00:00:01.0000174. TCP error code 10061: No connection could be made because the target machine actively refused it 138.xxx.xxx.xxx:5495. ] Server stack trace: at System.ServiceModel.Channels.SocketConnectionInitiator.Connect(Uri uri, TimeSpan timeout) at System.ServiceModel.Channels.BufferedConnectionInitiator.Connect(Uri uri, TimeSpan timeout) at System.ServiceModel.Channels.ConnectionPoolHelper.EstablishConnection(TimeSpan timeout) at System.ServiceModel.Channels.ClientFramingDuplexSessionChannel.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.Channels.ServiceChannel.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) Exception rethrown at [0]: at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage reqMsg, IMessage retMsg) at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData& msgData, Int32 type) at System.ServiceModel.ICommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.Channels.SecurityChannelFactory`1.ClientSecurityChannel`1.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.Security.SecuritySessionSecurityTokenProvider.DoOperation(SecuritySessionOperation operation, EndpointAddress target, Uri via, SecurityToken currentToken, TimeSpan timeout) at System.ServiceModel.Security.SecuritySessionSecurityTokenProvider.GetTokenCore(TimeSpan timeout) at System.IdentityModel.Selectors.SecurityTokenProvider.GetToken(TimeSpan timeout) at System.ServiceModel.Security.SecuritySessionClientSettings`1.ClientSecuritySessionChannel.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.Channels.ServiceChannel.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) Exception rethrown at [1]: at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage reqMsg, IMessage retMsg) at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData& msgData, Int32 type) at System.ServiceModel.ICommunicationObject.Open() at Soti.MobiControl.Caching.Implementation.CacheFactory.GetProxyServiceCacheClient(Server server) at Soti.MobiControl.Caching.Implementation.CacheFactory.Create(CacheConfiguration cacheConfiguration) at Soti.MobiControl.Caching.Implementation.CachingServiceEngine.UpdateCaches(IEnumerable`1 cacheConfigurations) at Soti.MobiControl.Caching.Implementation.CachingServiceEngine.UpdateConfiguration() at Soti.MobiControl.Caching.Implementation.CachingServiceEngine.ConfigureService() { [SocketException: No connection could be made because the target machine actively refused it 138.xxx.xxx.xxx:5495] at System.Net.Sockets.Socket.DoConnect(EndPoint endPointSnapshot, SocketAddress socketAddress) at System.Net.Sockets.Socket.Connect(EndPoint remoteEP) at System.ServiceModel.Channels.SocketConnectionInitiator.Connect(Uri uri, TimeSpan timeout) } ************************************************************************************************************ ### 2018-08-15 21:20:36.077 ERROR [167]: CachingServiceEngine: Will attempt to configure caching service again in 1 minute. ### 2018-08-15 13:39:45.013 ERROR [37]: ******************************************************** * Exception: Device '358625050992967' does not exists. * ******************************************************** [AccessControlException: Device '358625050992967' does not exists.] at Soti.MobiControl.Controllers.DeviceIdentityMapper.GetId(DeviceIdentity deviceIdentity) at Soti.MobiControl.Controllers.DeviceIdentityMapper.GetId(String deviceId) at Soti.MobiControl.Api.Implementation.RequestExtensions.CreateContext(Request request) at Soti.MobiControl.Api.Implementation.Com.DeviceConfigurationFacade.CreateDeviceContext(String deviceId) at Soti.MobiControl.Api.Implementation.Com.DeviceConfigurationFacade.GetConfiguration(String deviceId) ******************************************************** ### 2018-08-15 13:47:47.617 INFO [3]: [ProgramTrace.RefreshSwitchSection] The configuration section 'system.diagnostics' has been reloaded successfully. ### 2018-08-15 13:47:47.617 DEBUG [3]: [ProgramTrace.PopulateSwitches] Current diagnostics switches: General = Error, DeploymentServer = Error, APNS = Error, Database = Error, Enrollment = Error, Schedule = Error, Management = Error, PrinterAdministration = Error, AccessControl = Error, DeviceEnrollmentProgram = Error, DeviceEnrollmentProgram.Integration = Error, VolumePurchaseProgram = Error, VolumePurchaseProgram.Integration = Error, Caching = Error ### 2018-08-15 13:48:43.421 ERROR [34]: GetCertificateByTemplateId called with template id : 0 and device id : 359998043396839 ### 2018-08-15 13:48:43.452 ERROR [34]: GetCertificateByTemplateId : key provider creates only public key : False ### 2018-08-15 13:48:43.484 ERROR [34]: GetCertificateByTemplateId : generated certificate has private key : True ### 2018-08-15 14:00:25.147 INFO [3]: [ProgramTrace.RefreshSwitchSection] The configuration section 'system.diagnostics' has been reloaded successfully. ### 2018-08-15 14:00:25.162 DEBUG [3]: [ProgramTrace.PopulateSwitches] Current diagnostics switches: General = Error, DeploymentServer = Error, APNS = Error, Database = Error, Enrollment = Error, Schedule = Error, Management = Error, PrinterAdministration = Error, AccessControl = Error, DeviceEnrollmentProgram = Error, DeviceEnrollmentProgram.Integration = Error, VolumePurchaseProgram = Error, VolumePurchaseProgram.Integration = Error, Caching = Error ### 2018-08-15 14:18:00.280 ERROR [34]: GetCertificateByTemplateId called with template id : 0 and device id : 359998043396839 ### 2018-08-15 14:18:00.311 ERROR [34]: GetCertificateByTemplateId : key provider creates only public key : False ### 2018-08-15 14:18:00.343 ERROR [34]: GetCertificateByTemplateId : generated certificate has private key : True ### 2018-08-15 14:25:38.704 INFO [3]: [ProgramTrace.RefreshSwitchSection] The configuration section 'system.diagnostics' has been reloaded successfully. ### 2018-08-15 14:25:38.720 DEBUG [3]: [ProgramTrace.PopulateSwitches] Current diagnostics switches: General = Error, DeploymentServer = Error, APNS = Error, Database = Error, Enrollment = Error, Schedule = Error, Management = Error, PrinterAdministration = Error, AccessControl = Error, DeviceEnrollmentProgram = Error, DeviceEnrollmentProgram.Integration = Error, VolumePurchaseProgram = Error, VolumePurchaseProgram.Integration = Error, Caching = Error

    SOTI MobiControl
    8 years ago
  • 0 votes 1 answer

    Configure SOTI as the Data Source in i-Net Clear Reports

    I'm very new to SOTI, and I'm looking to produce some custom reports. I downloaded the i-net Clear Reports Designer that was linked to in SOTI's Reports tab, but I wasn't sure how to set SOTI as the data source within the Reports Designer. Which driver should I use, and how do I find the User, Password, Host, and Database? Any help is appreciated. Thanks in advance!

    SOTI MobiControl
    8 years ago
  • 0 votes 1 answer

    Two telecom expense management rules

    I have two telecom expense management rules setup. To control data usage the first one will activate at 75% of their monthly data usage and relocate the user to a special group that has more limitations on what they can use. I also have a second rule setup that is pointed to the group that the first rule moves the device into and this rule is setup so that it will move the user into yet another group that further limits what they can use, this occurs at 100% of their monthly data usage. The issue I have is that the second rule does not appear to work. I was wondering if anyone else has setup something similar to this and had it working or if it is even supposed to work like this? The reason for having two rules instead of one rule with a soft and hard limit, is that in order to have each rule relocate the device to a different group it needs to be setup in the hard limit section of the rule. This is required as the groups that the phones are moved into with each limit being reached is a tiered setup in which at 75% only some features/apps are blocked but when they reach 100% they should go into another group where the majority of data consuming apps are blocked.

    Android
    8 years ago

Earn Contributor Badge

More info
  • Diamond
    Diamond New

    Top-tier experts who are delivering outstanding content. Should have more than 7000 points.

  • Platinum
    Platinum

    Experts who are consistent with great content. Should have more than 1000 points.

  • Gold
    Gold

    Highly experienced members with valuable inputs. Should have more than 700 points.

  • Silver
    Silver

    Beginners taking the initiative. Should have more than 500 points.

  • Bronze
    Bronze New

    New contributors starting their journey. Should have more than 250 points.