APNS Certificate Renewal Fails: Mismatched Apple ID Causes Upload Error
iOS
iOS
If you're having trouble uploading a renewed Apple Push Notification Service (APNS) certificate to Esper, the issue is likely caused by using a different Apple ID than the one originally used to create the certificate. This article explains how to identify the correct Apple ID and successfully renew your certificate.
Before you begin
Apple's APNS infrastructure requires that you renew a certificate using the exact same Apple ID that created it. Using a different Apple ID—even if it belongs to the same person—will cause the renewal to fail when you try to upload it to Esper.
Step 1: Find your original Apple ID
- In the Esper Console, go to Apple MDM Setup.
- Look for the Apple ID listed in your Apple MDM configuration. This is the Apple ID you must use for renewal.
- If you're unsure which Apple ID is listed, contact Esper Support and provide your tenant ID. We can confirm the correct Apple ID for you.
Step 2: Renew your certificate with the correct Apple ID
- Go to the Apple Push Certificates Portal.
- Log in using the original Apple ID exactly as it appears in your Esper tenant configuration. Do not use any other Apple ID, even if it belongs to the same person.
- Find the existing APNS certificate associated with your Esper push topic.
- Click Renew. Do not click Create, as creating a new certificate will generate a new push topic and break MDM communication with all your enrolled devices.
- Download a fresh Certificate Signing Request (CSR) from the Esper Console: Apple MDM Setup → Download CSR.
- Upload the CSR to the Apple portal when prompted.
- Download the renewed
.pemcertificate file from the Apple portal.
Step 3: Upload the renewed certificate to Esper
- In the Esper Console, go to Apple MDM Setup.
- Upload the
.pemfile you downloaded from Apple. - Confirm that the certificate now shows a new expiration date (one year from today) and that your Apple MDM status returns to active.
- Verify that your enrolled Apple devices remain enrolled and responsive to MDM commands.
Troubleshooting
My original Apple ID is no longer accessible
If your original Apple ID has been deactivated, locked, or you no longer have access to it, you cannot renew the existing certificate. You must create a new certificate with a new Apple ID. However, this will unenroll all currently managed Apple devices. Before you proceed, contact Esper Support so we can help you plan the re-enrollment process and minimize disruption to your devices.
The upload still fails in Esper after using the correct Apple ID
Collect a screen recording of the entire renewal process (both the Apple portal steps and the upload in Esper) and include any error messages or browser console errors. Then contact Esper Support with the following information:
- Your tenant ID
- The push topic shown in the Apple portal
- Any error messages from the browser console during upload
- Your screen recording
I can't find my certificate in the Apple portal
Your certificate may have expired beyond Apple's renewal grace period. APNS certificates are valid for 365 days and can only be renewed within a limited window before expiry. If you cannot find your certificate, treat this as a new certificate creation scenario and contact Esper Support for guidance.
Important notes
-
Apple ID must match exactly: Even minor differences in the Apple ID domain (for example,
.appleid.comvs..appleaccount.com) will cause the renewal to fail. If you're unsure about the correct domain for your Apple ID, contact Apple Support for clarification. - Always use Renew, never Create: Creating a new certificate generates a new push topic, which breaks MDM communication with all enrolled devices. This action cannot be undone without manually re-enrolling each device.
- Use a fresh CSR for each renewal: Download a new CSR from the Esper Console each time you renew. Do not reuse a CSR from a previous renewal attempt.
- Set a renewal reminder: APNS certificates expire after 365 days. Set a calendar reminder to renew your certificate at least 30 days before expiry to avoid service interruption.
Still need help?
If you've followed these steps and still cannot upload your renewed certificate, contact Esper Support. include your tenant ID, the push topic from the Apple portal, and details about any error messages you've encountered.
Please sign in to leave a comment.
Comments
0 comments