Addigy lets you remove an Apple Push Notification service (APNs) certificate that your account no longer uses, so your MDM Settings page reflects only the certificates you actively rely on. Because a push certificate is what keeps your devices connected to MDM, Addigy shows you exactly where a certificate is in use before you remove it. Read this article before deleting anything.
Overview
Your Apple Push Certificates (APNs) can be found under Account > MDM Settings. This list shows you all of your APNs certificates no matter where they are located in your policy hierarchy.
From this page you can:
- Review every push certificate on your account in one place.
- See which policies and devices depend on a given certificate before you act on it.
- Renew a certificate that is approaching or past its expiration date.
- Delete a certificate that is no longer in use anywhere in your hierarchy.
When a Certificate Is Safe to Delete
An Apple Push Certificate (APNs) will show as safe to delete when the following three conditions are met:
- The certificate is expired.
- The certificate is not assigned to a policy in your hierarchy.
- There are no devices attached to that certificate within Addigy.
If any one of these conditions is not met, Addigy will not present the certificate as safe to delete.
Renewing vs. Deleting a Certificate
These are two different actions with very different outcomes, so confirm which one you actually need before you open the menu.
- Renew keeps the existing certificate and updates it with a new PEM file from Apple. This is the standard annual maintenance task and is the action you want in nearly every case. See Renewing Apple Push Certificates.
- Delete removes the certificate from Addigy. Deleting a certificate from Addigy is irreversible.
If your certificate has already expired, renewal is still your first course of action — an expired certificate can typically still be renewed through Apple. For the full decision tree, including what to do when renewal is not possible, see FAQ: My Push Certificate Expired.
Note: Push certificates are applied to devices at the time of enrollment. Changing which certificate a policy uses only affects future enrollments — devices that are already enrolled keep the certificate they enrolled with. See FAQ: My Push Certificate Expired.
How to Review a Certificate's Usage
Always review usage before deleting. This is the step that tells you whether anything still depends on the certificate.
- Navigate to Account > MDM Settings.
- Find the certificate you want to review and click the ... menu in the Actions column.
- Select Usage / Delete.
An informational modal opens that details all of the usages of the certificate within Addigy:
- Name, APN topic and expiration of the certificate
- The policies the certificate is assigned to.
- The devices that have the certificate assigned to them.
A certificate that is not expired, is assigned to policies and has devices attached:
A certificate that is safe to delete:
How to Delete a Certificate
Use this workflow only after the usage modal confirms the certificate is safe to delete.
- Navigate to Account > MDM Settings.
- Click the ... menu in the Actions column for the certificate.
- Select Usage / Delete.
- Confirm that the modal reports no assigned policies and no attached devices, and that the certificate is expired.
- Delete the certificate.
Please note that deleting an APNS certificate could potentially cause MDM communication issues with devices.
Note: Deleting a certificate from Addigy is irreversible.
Other Actions in the Certificate Menu
The ... menu in the Actions column also gives you:
- Renew — upload a new PEM certificate from Apple for the token. See Renewing Apple Push Certificates.
- Info — view the certificate's attributes, including its serial numbers, APN topic, and expiration date. This view also provides a Rename button next to the certificate name.