UPDATE: Check out our CAB Signing Tool if you need to sign CAB files with your own certificate.
A recurring question I get is how to test and demo the software distribution capabilities of MDM.
People generally run into errors with importing test CAB files because the DM does not trust the signature the CAB was signed with – or the CAB is simply unsigned. First thing to note is the software distribution server can only import signed CAB files. You cannot disable this feature (as of this writing anyway.) The root certs of the certificate that signed the cab file must be in the Trusted Publisher store on the DM server. In most cases you will have to manually put it there.
If you have several unsigned apps, create a cert from your MDM CA and use that for signing all the CABs. The steps for how to do that are in a CAB Signing document on the Connect site or came with your MDM product documentation.
If you would like to do a quick test without going through the self signing cert process, you can deploy a Microsoft signed CAB like Live Search. You can download the Live Search cab here.
You will need to prep your DM server to trust the certs and CA used to sign the live search cab. Here’s the steps to do that on your DM server.
Once the CAB is imported you can simply follow the steps in the operations guide for how to deploy the application to your devices using the MDM software deployment MMC.
6 Responses
Software distribution with MDM - Marco Nielsen at myITforum.com
25|Apr|2008 1[...] http://blog.enterprisemobile.com/2008/04/software-distribution-with-mdm/ [...]
mnielsen
25|Apr|2008 2Pingback from http://myitforum.com/cs2/blogs/mnielsen/archive/2008/04/25/software-distribution-with-mdm.aspx
Robert O'Hara
22|May|2008 3Thanks for the post, most helpful. But I am a noobie with this stuff, and can’t do step 17 — I don’t know where to find the “SW package import wizard”.
Can you point me to it?
Thanks!
csaintamant
23|May|2008 4The SW package import wizard is accessible from the MDM Software Distribution Console. On any machine that has the MDM Admin Tools installed, you should be able to find that console under Start -> Programs. From within the console, there is an option to create a new package.
T
21|Jan|2009 5Is it true that all I need to do to get a Trusted Root CA cert on my WM devices is to import the cert to the Trusted Root CA on my DM, and the DM will then send down the WM “version” to my devices on next connect by the device?
csaintamant
22|Jan|2009 6T: No, there is a separate process for getting a CA cert down onto your WM devices. You must use the Group Policy Management Console (GPMC) to create a policy that adds your desired CA cert to the SPC and Privileged Execution certificate stores on the device.
Leave a reply
Search
Archives
Categories
Device Info
Mobile Blogs
Copyright © 2008 - Enterprise Mobile
Proudly powered by WordPress - InSense 1.0 Theme by Design Disease.