TLS Trust Configuration

The TLS Trust configuration bundles the server-side settings for establishing trusted TLS connections. It is found under Settings → TLS Trust configuration and is divided into two areas: the trusted certificates for outbound connections and certificate pinning for Apple enrollment.


Trusted certificates

Relution accepts these CA certificates in addition to the system’s default trust store when establishing outbound TLS connections. Use Add to include further certificates; the overview lists Name, Type and the expiry date (Expires) for each entry.


Certificate pinning (Apple enrollment)

When the Enable certificate pinning toggle in the General area is switched on, the MDM server’s TLS connection is validated against selected anchor certificates instead of the system trust store. This makes man-in-the-middle attacks and the use of unauthorized certification authorities more difficult. The feature takes effect during the enrollment of Apple devices. If pinning is disabled, enrollment is validated against the system trust store.

The certificates to be checked are selected in the Anchor certificates area using Add; the overview lists Name, Type and the expiry date (Expires) for each entry. At least one anchor certificate is required to enable pinning. The Require certificate revocation check toggle additionally enforces a check of the certificate revocation status.

Behavior during enrollment

When pinning is enabled, the device’s connection to the MDM server is checked against the selected anchor certificates during enrollment. If the server certificate found matches the stored anchor certificates, enrollment succeeds. If it differs, the connection is rejected and enrollment fails.

Devices with an operating system version below the minimum required for pinning continue to be enrolled without pinning; enrollment remains functional there.


Anchor certificate notifications

Relution monitors the pinned anchor certificates and reports problems in the notification center so that devices being locked out can be prevented early. Reported issues include:

  • an anchor certificate that is about to expire or has already expired,
  • an anchor certificate that cannot be loaded or is not a CA certificate,
  • ineffective pinning, for example when no anchor certificate is configured or none matches the server’s TLS certificate chain.
Top