Mobile Device Enrollment Error: "Invalid Profile" or "Invalid Certificate"

Technical Articles

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Symptoms

When installing an MDM profile on a mobile device, one of the following error messages is displayed:
  • "Invalid Profile"

  • A long message containing "Invalid Certificate"

Explanation

When enrolling a mobile device with Jamf Pro, trust is established to allow encrypted communication. If Jamf Pro fails to establish trust, enrollment fails and an error message with "Invalid Profile" or "Invalid Certificate" is displayed on the device.

There are two scenarios that can cause this issue:
  • The SSL certificate in Jamf Pro is self-signed

  • The CA certificate is not being installed on the device during enrollment

Resolution

If your If your web server certificate is self-signed, there are two ways to resolve the issue:
  • Replace the web server certificate in Jamf Pro with the certificate from Jamf Pro's built-in CA.

  • Install a public certificate from a third-party CA.

If the root CA certificate is not being installed on the device during enrollment, ensure that this option is selected in Jamf Pro.