APNS Certificate Expiry Warning: Renew Apple Push Notification Service Certificate Before Expiration to Avoid Device Re-enrollment
iOS
AndroidiOSLinux
Your Apple Push Notification Service (APNS) certificate expires annually and must be renewed before the expiration date. If you don't renew your certificate, your enrolled iOS devices will lose management connection and require full re-enrollment. This article explains how to renew your APNS certificate before it expires.
Before you begin
Apple sends an expiry warning email to your Apple ID owner approximately 30 days before your APNS certificate expires. When you receive this email, renew your certificate immediately to avoid disrupting device management.
Important: You must renew your certificate using the same Apple ID that was used to create the original certificate. Using a different Apple ID creates a new certificate with a different push topic, which invalidates all existing iOS device enrollments and requires full re-enrollment.
How to renew your APNS certificate
- Log in to the Esper Console and navigate to your profile settings.
- Select Apple MDM Management.
- Under the Apple Push Notifications (APNS) Certificate section, click Renew Certificate.
- Download the signed Certificate Signing Request (CSR) generated by Esper.
- Visit https://identity.apple.com/pushcert and sign in with the same Apple ID used to create the original certificate.
- Locate the certificate matching your current expiration date in the Apple Push Certificates Portal.
- Click the Renew button next to that certificate.
- When prompted, upload the signed CSR that you downloaded from Esper in Step 4.
- Download the renewed
.pemcertificate file from Apple. - Return to the Esper Console, navigate to Apple MDM Management → APNS Certificate, and upload the newly downloaded
.pemfile. - Verify the new expiration date appears in the Esper Console under Apple MDM Management. Check Devices & Groups to confirm your enrolled devices remain under management.
Troubleshooting renewal issues
Certificate upload fails on the Apple portal:
- Ensure the CSR downloaded from Esper is unmodified and in the expected format.
- Re-download the CSR from the Esper Console and retry the upload.
Certificate still shows as expiring in Esper Console after upload:
- Confirm you uploaded the correct
.pemfile from Apple (the renewed certificate, not the CSR). - Re-upload if necessary.
Devices lose management connection after renewal:
- Verify that you used the same Apple ID throughout the renewal process.
- If you used a different Apple ID, your devices will require full re-enrollment.
Esper Console does not reflect the renewed certificate:
- Clear your browser cache and refresh the Esper Console.
- Wait a few minutes for the system to update.
- If the issue persists, contact Esper Support.
Important reminders
- Mark your calendar to renew your certificate 3–4 weeks before the expiration date each year. This is an annual recurring action.
- Always use the same Apple ID to renew your certificate. Using a different Apple ID invalidates all existing device enrollments.
- Never generate a CSR externally. The Esper Console generates the signed CSR for you.
- Certificate renewal only applies to iOS device management and does not affect Android or Linux devices.
Still need help?
If you continue to experience issues renewing your APNS certificate, submit a support ticket. When you contact us, include the Apple ID used for renewal, the old and new certificate expiration dates, and any error messages you received.
Please sign in to leave a comment.
Comments
0 comments