APNs Certificates Test

Workspace ONE UEM communicates with Apple devices securely and reports information back to the UEM console using APNs certificates. If the APNs certificate had expired, communication may be hit between the Workspace ONE UEM and Apple devices. To avoid such communication failures, eG Enterprise offers the APNs Certificates test.

This test auto-discovers the APNs certificates on the Workspace ONE UEM and reports the number of days that are left for each APNs certificate to expire. This way, administrators can identify the certificates that had expired or are nearing expiry and initiate steps to renew those certificates at the earliest.

Note:

For this test to report metrics, a few pre-requisites need to be fulfilled. Please refer to Pre-Requisites to Monitor APNs Certificates for more details.

Target of the test : A VMware Workspace ONE UEM

Agent deploying the test : A remote agent

Outputs of the test : One set of results for each APNs certificate installed on the VMware Workspace ONE UEM

Configurable parameters for the test
Parameter Description

Test Period

How often should the test be executed. By default, this is 4 hours.

Host

The host for which the test is to be configured.

User Name, Password and Confirm Password

For execution, this test requires the privileges of a user who is vested with the Console Administrator role. Configure the credentials of such a user against the User Name and Password text boxes. Confirm the password by retyping it in the Confirm Password text box.

Domain Name, Domain User Name, Domain Password and Confirm Password

These parameters are applicable only if the eG agent needs to communicate with the VMware Horizon Workspace ONE UEM console via a Proxy server.

In this case, in the Domain text box, specify the name of the Windows domain to which the eG agent host belongs. In the Domain User Name text box, mention the name of a valid domain user with login rights to the eG agent host. Provide the password of that user in the Domain Password text box and confirm that password by retyping it in the Confirm Password text box.

On the other hand, if the eG agent is not behind a Proxy server, then you need not disturb the default setting of these parameters. By default, these parameters are set to none.

Proxy Host, Proxy Port, Proxy User Name, Proxy Password and Confirm Password

These parameters are applicable only if the eG agent needs to communicate with the Office 365 portal via a Proxy server.

In this case, provide the IP/host name and port number of the Proxy server that the eG agent should use in the Proxy Host and Proxy Port parameters, respectively.

If the Proxy server requires authentication, then specify the credentials of a valid Proxy user against the Proxy User Name and Proxy Password text boxes. Confirm that password by retyping it in the Confirm Password text box. If the Proxy server does not require authentication, then specify none against the Proxy User Name, Proxy Password, and Confirm Password text boxes.

On the other hand, if the eG agent is not behind a Proxy server, then you need not disturb the default setting of any of the Proxy-related parameters. By default, these parameters are set to none.

Tenant API Key

By default, this test collects relevant metrics from the VMware Horizon WorkSpace ONE console by executing the REST API commands. In order to execute the REST API commands, you will need the API key associated with the VMware Horizon WorkSpace ONE account that is being monitored. To know how to figure out the API key, refer to Identifying Tenant API Key.

DD Frequency

Refers to the frequency with which detailed diagnosis measures are to be generated for this test. The default is 1:1. This indicates that, by default, detailed measures will be generated every time this test runs, and also every time the test detects a problem. You can modify this frequency, if you so desire. Also, if you intend to disable the detailed diagnosis capability for this test, you can do so by specifying none against DD frequency.

Detailed Diagnosis

To make diagnosis more efficient and accurate, the eG Enterprise embeds an optional detailed diagnostic capability. With this capability, the eG agents can be configured to run detailed, more elaborate tests as and when specific problems are detected. To enable the detailed diagnosis capability of this test for a particular server, choose the On option. To disable the capability, click on the Off option.

The option to selectively enable/disable the detailed diagnosis capability will be available only if the following conditions are fulfilled:

  • The eG manager license should allow the detailed diagnosis capability
  • Both the normal and abnormal frequencies configured for the detailed diagnosis measures should not be 0.
Measures made by the test
Measurement Description Measurement Unit Interpretation

Days to expire

Indicates the number of days for which this certificate is valid.

Number

The detailed diagnosis of this measure lists the Apple ID, Certificate Type, ThumbPrint, Certificate Issued By, Certificate Issued To, Valid From, Valid To, Current Setting and Child Permission.