TLS Trust Configuration
The TLS Trust configuration bundles the server-side settings for establishing trusted TLS connections. It is found under Settings → TLS Trust configuration and is divided into two areas: the trusted certificates for outbound connections and certificate pinning for Apple enrollment.
Trusted certificates
Relution accepts these CA certificates in addition to the system’s default trust store when establishing outbound TLS connections. Use Add to include further certificates; the overview lists Name, Type and the expiry date (Expires) for each entry.
Certificate pinning (Apple enrollment)
When the Enable certificate pinning toggle in the General area is switched on, the MDM server’s TLS connection is validated against selected anchor certificates instead of the system trust store. This makes man-in-the-middle attacks and the use of unauthorized certification authorities more difficult. The feature takes effect during the enrollment of Apple devices. If pinning is disabled, enrollment is validated against the system trust store.
The certificates to be checked are selected in the Anchor certificates area using Add; the overview lists Name, Type and the expiry date (Expires) for each entry. At least one anchor certificate is required to enable pinning. The Require certificate revocation check toggle additionally enforces a check of the certificate revocation status.
Pinning is fixed in the enrollment profile
Pinning is embedded into the enrollment profile at enrollment time and cannot be changed afterwards. Changes made here only affect future enrollments. A misconfiguration can lock devices out of MDM communication until they are re-enrolled. Only long-lived CA certificates should be pinned; when rotating a CA, keep both the old and the new anchor selected.
Only enable the revocation check with revocation information
The Require certificate revocation check may only be enabled if the server’s TLS certificate provides revocation information (OCSP responder URL). If this information is missing, devices may refuse to connect.
Behavior during enrollment
When pinning is enabled, the device’s connection to the MDM server is checked against the selected anchor certificates during enrollment. If the server certificate found matches the stored anchor certificates, enrollment succeeds. If it differs, the connection is rejected and enrollment fails.
Devices with an operating system version below the minimum required for pinning continue to be enrolled without pinning; enrollment remains functional there.
Anchor certificate notifications
Relution monitors the pinned anchor certificates and reports problems in the notification center so that devices being locked out can be prevented early. Reported issues include:
- an anchor certificate that is about to expire or has already expired,
- an anchor certificate that cannot be loaded or is not a CA certificate,
- ineffective pinning, for example when no anchor certificate is configured or none matches the server’s TLS certificate chain.