Symptoms
When installing an MDM profile on a mobile device, one of the following error messages is displayed:
"Invalid Profile"
A long message containing "Invalid Certificate"
Explanation
When enrolling a mobile device with Jamf Pro, trust is established to allow encrypted communication. If Jamf Pro fails to establish trust, enrollment fails and an error message with "Invalid Profile" or "Invalid Certificate" is displayed on the device.
There are two scenarios that can cause this issue:
The SSL certificate in Jamf Pro is self-signed
The CA certificate is not being installed on the device during enrollment
Resolution
If your If your web server certificate is self-signed, there are two ways to resolve the issue:
Replace the web server certificate in Jamf Pro with the certificate from Jamf Pro's built-in CA.
Install a public certificate from a third-party CA.
If the root CA certificate is not being installed on the device during enrollment, ensure that this option is selected in Jamf Pro.