Problem
You set up advanced management with Apple iOS devices, and created an Apple push certificate that you must renew yearly.
Environment
- Mobile Device Management
- iOS
Solution
Before you begin
- If the certificate expires before you renew it, Google Workspace data will no longer sync with iOS devices, and users will see an error in the Google Device Policy app.
- You have 30 days to renew the certificate after the expiration date. Apple offers this period now, but it may change in the future.
- You cannot renew the certificate either 30 days after it expires or if you don't have the password for the Apple ID associated with the certificate.
- If you cannot renew your certificate, you can create a new one. When you do, your iOS users must unregister and reregister in the Google Device Policy app to sync Google Workspace data. For details, go to Set up an Apple push certificate.
- Do not reload your browser window or close any pages while you renew the certificate.
Step 1: Generate a renewal request
- Log in to the Admin console.
- Navigate to Menu > Devices > Mobile & endpoints > Settings > iOS settings.
- Requires having the Services and devices administrator privilege.
- Click Apple certificates.
- The current certificate details are displayed: the unique identifier (UID), the Apple ID, and expiration date.
- Click Renew Certificate.
- Click Get CSR and save the certificate signing request (.csr file). Download this file only once.
Step 2: Get a renewed certificate
- Click Apple Push Certificates portal.
- In the new tab, sign in to the Apple portal with the Apple ID and password you used when you created the certificate.
- Next to the certificate you want to renew, click Renew and accept the terms of use.
- Tip: If more than one certificate is listed, you need to identify the correct certificate. Locate certificates with the same expiration date as in the Google Admin console. Click the i button (certificate info) next to each one to find the UID and make sure it matches the certificate you want to renew.
- Click Choose File and open the certificate signing request (.csr) file you saved in step 1.
- To submit the request file, click Upload.
- Apple accepts the request and displays a confirmation page with your service type, vendor domain, and the expiration date for this certificate.
- Click Download and save the signed certificate (.pem) file. Download this file only once.
- Go back to your Admin console tab or window.
Step 3: Upload your renewed certificate
- Click Upload Certificate and select the certificate (.pem) file you saved from the Apple Confirmation page in the previous step.
- Click Save & Continue.
- The system verifies and uploads the renewed certificate. If you have problems, make sure the signed certificate you submitted matches the UID of the existing certificate.