Certificate error when importing CSR certificate for MDM
book
Article ID: 237962
calendar_today
Updated On:
Products
IT Management SuiteClient Management Suite
Issue/Introduction
When importing the signed CSR certificate for MDM (Modern Device Management) the following error is returned:
Failed to import signing certificate Cannot find the requested object.
Environment
ITMS 8.x
Resolution
The "Signing certificate" is a certificate used for signing profiles. It should be obtained by the ITMS Administrator and it should not be signed by Broadcom per KB article CSR signing for MDM. Also there is no need to import the CSR into the MDM certificate page - as only certificates are expected to be imported there.
Broadcom signs only APNS Certificate requests because it is mandatory to obtain an APNS certificate from the Apple portal. For APNS you'll need to create an APNS certificate request, export it and send it to Broadcom. Then Broadcom signs it and returns it to you. Then you use the signed APNS CSR at identity.apple.com to obtain an APNS certificate, that needs to be imported to the MDM Certificates page.
Other certificates should be prepared by you - no actions from Broadcom are expected for other certificates type(Intermediate/ Signing/Server). Please find more details at the help page Setting up MDM for macOS.
Note: In the event you get the following error message while trying to install your wildcard cert used on your MDM server:
Failed to import signing certificate The certificate with thumbprint xxxxxxx already exists.
This issue may occur when the same certificate is already imported to the SMP Server by non-MDM functionality (see certificates under Settings > Notification Server > Certificate Management in Symantec Management Console) as shown here: