Does anyone know how to sign a custom profile for the iphone? I can modify the apple.xml file by using the apple Iphone Configuration Utility. I export the settings out of this utility and change the name of the file that I exported to apple.xml and install it on the server. I then restart the http service and go to install the profile and it warns me that the profile is unsigned. It is no big deal as the profile works but I was just wondering how to sign it.
When I export the settings out of the Iphone Configuration Utility I have to keep the security of the export to None as the server needs plane xml as the signed xml has junk that the server can’t read.
Subject: Changing the Signed by Lotus Traveler profile
Is there a solution for this yet? We are currently using Mobile Iron and the profile from them is signed by “*.mobileiron.net” and it verified. We are looking at getting rid of Mobile Iron and just using Traveler. I would like to be able to get the profile signed by my SSL certificate on the server or at least have it signed by the server name.
Subject: RE: Changing the Signed by Lotus Traveler profile
The “solution” is that you would have to create the profiles for each user and sign them yourself. That profile would be placed on some location that the devices can access it. There is no automated process to do this. The fact that the profile is signed or not doesn’t have any impact on the account setup - the same data gets there either way. Once the account data is there (no matter how it gets there), the connections, syncs, push, etc. are all the same from that point. Therefore, it is probably more work than it is worth.
It does not appear to me that at this time Lotus is supporting the creation of signed profiles (*.mobileconfig files) on Domino. The apple.xml file is pure xml where they “Generate” a user-specific ILNT.mobileconfig file which is not signed. Refer to Apple’s Enterprise Deployment guide for the iPhone and see that there seems to be a lot more work required to get an Over-The-Air Enrollment working with signed configuration files. Maybe they will try to incorporate signed profiles in the next release and additional Active Sync features - like policy support.