cancel
Showing results for 
Search instead for 
Did you mean: 

Enrollment failed in Afaria Client App AES in Android device

jigar_salecha
Explorer
0 Kudos

Hi all,

         I have installed Afaria ssp portal,package server,enrollment server on the same Afaria server 7.0.I have created a enrollment policy and genereted a tiny url enrollment code and linked this policy to a static group..

          Now when i go to the Afaria Client app (AES) which is preinstalled on my Android device and i enter the enrollment code generated using tinyurl(eg-tqx7vumx),it is showing a popup as "Enrollment failed"

            Do we need to configure anything in the Afaria client app before writing the enrollment code??

                 Please help me to solve this problem??

Accepted Solutions (1)

Accepted Solutions (1)

Former Member
0 Kudos

Hi,

Any reason for not installing Afaria 7 sp4.

Required more details

Enrollment failed error could be for multiple reason.

1. Connection problem on device

2. Wrong Enrollment code url

3. Device communication & enrollment setting not properly configured on afaria console

4. Network Ports opening problem

jigar_salecha
Explorer
0 Kudos

Hi Chetan,

               Thanks for your response.

               I am attaching screenshots of all the configurations that I have done on Afaria server.

               Please go through it and suggest if there is any error that I am committing.

               Also the long url when I enter in external device bowser,I am getting an error.

               I have attached the screenshots of that too.


               And is upgrading to sp4 free of cost ?????Any Hotfix is required for that???


              


    


              


                  


                   

                        

                          Error on entering long url in external device browser

                   

                        

                           Error on entering long url in afaria server browser

                        

                                

                             Latest server Logs

                            

                         If u require any more details,please tell me!!

                         Waiting for your response.

Former Member
0 Kudos

Hi,

Yeah you can upgrade to Afaria7sp4 seem you already have purchase the license for afaria 7?

Working with afaria 7 you need to install all hotfix at the same time and  if you are installing Afaria7SP4 no hotfix required.

I will suggest you the 1st step to go with Afaria7 sp4 if there is no problem from your end.

Check for screenshot 2.

Server address : 10.11.0.0 ( No need of Port to define)

unauthorized virtual directory : aips

( aips_enroll ? did you change the name at the time of installation)

authorized virtual directory : aips2_enroll

( aips2_enroll ? did you change the name at the time of installation)

Also confirm the connection diagram ? its direct or from relay server .

Mode of connection from device ? Internet or corporate wifi.

Answers (5)

Answers (5)

Former Member
0 Kudos

Hi,

Close the discussion if its resolved

jigar_salecha
Explorer
0 Kudos

okkk.I have put it for ugradation to sp4

Just one conceptual question


While creating enrollment policy, i selected portal only as NO and i got a tiny url.

So while enrolling from device ,sholud i put this tiny url as enrollment code and should i upgrade it in web.config of afaria server??

Former Member
0 Kudos

Hi,

If you are not enrolling the device with SSP its okie even if you keep portal only NO.

Yes if you are doing direct enrollment of the device you can use tiny url

jigar_salecha
Explorer
0 Kudos

Can u explain me how this Afaria 7 integrate with the LDAP and how the communication happens when a mobile devices tries to register in the Afaria 7 server.


Where do we exactly have to give the LDAP credential while log in to the SSP or while enrolling the device from afaria app.

  1. Will the users enter their emailid/password while log in to the self service portal and will that be authenticated via LDAP server?
  2. Do at any point of time, we have to give LDAP credentials for authentication when we embed the tinyurl code in afaria app and enrollments begins?

Is this possible??

Former Member
0 Kudos

Hi,

Ldap configuration can be configured at the time of installation of Afaria server component.

Or else you can configured from Afaria console >> Server>> Setting>> security.

1. Yes Ldap credential with SSP will be at the time of SSP login the page.

2. Even without using ssp you can set the ldap login at the time enrollment.

jigar_salecha
Explorer
0 Kudos

Can i connect multiple LDAP'S to a single Afaria server for authentication???

If yes how??

Because Afaria console >> Server>> Setting>> security, i cannot see option for multiple LDAPS.

Please help

Former Member
0 Kudos

Hi,

Yes i think its possible ,because it support multiple tenant  and can map to multiple AD

Former Member
0 Kudos

Did your upgrade to SP4 fix the problem?

jigar_salecha
Explorer
0 Kudos

Yes Gagan

Former Member
0 Kudos

We are trying the upgrade but are stuck at a message regarding Update 3 of Visual C++ Redistributable. We are already at Update 4 and have no way of rolling back. Any ideas?

jigar_salecha
Explorer
0 Kudos

U will have to download "Update 3 of Visual C++ Redistributable" from Visual C++ Redistributable for Visual Studio 2012 Update 3 - Software Informer. It is a package that...or from microsoft site ,then restart the system and then proceed

Former Member
0 Kudos

HI,

You can find the relevant package of visual c++ in Afaria sp4 setup file(Redistributables) folder .

Former Member
0 Kudos

Thank you both. We uninstalled Version 4 and installed 3 from the Afaria setup.

With this we were able to install Afaria SP4. Unfortunately, we are still seeing the same symptoms Jigar was seeing originally.

  Error on entering long url in external device browser


  Error on the device when enrolling - Enrollment Failed

Former Member
0 Kudos

Hi,

I had already mention enrollment failed error would be for multiple reason.

You can work .

1. Connection problem on device

2. Wrong Enrollment code url

3. Device communication & enrollment setting not properly configured on afaria console

4. Network Ports opening problem

Former Member
0 Kudos

1. Connection problem on device - The device has internet connectivity and is able to open the self service page with no issues.

2. Wrong Enrollment code url - Not sure what you mean here, we are using http://<domain>/ssp/Enrollment

have also tried using http://<domain>/ssp/xxx6g4zyh from the tinyurl

Neither have worked.


3. Device communication & enrollment setting not properly configured on afaria console:

4. Network Ports opening problem - How do I know what ports need to be opened? I ran portqury on 3007 and it looks to be filtered:

Former Member
0 Kudos

Hi Enrollment failed because of following reasons i know up to now.

1) Restart your iPhoneServer using Service(Task manager).

2) Change your dot net version from 2.x to 4.x

Just check your virtual directory up to http://server/aips/aipService.svc/help

check are you able to download seed data. Inspect tinurl generated by Afaria admin.

3) if still your problem persist apply hot fix

make sure that all port numbers should be open for Afaria specification document.

Former Member
0 Kudos

HI,

If you are not using relay server and connecting the device directly to Afaria server for enrollment.

Port  : 3007 should be open because you had mention device communication address : xnet://ip:3007.

Other than 3007 port , you need to open 5228 port for GCM

Note : The above port details is only for Android device comminication.

2. Wrong url code :

Just click on Enrollment code you had generated and than click on INSPECT .

You can view the long url there please check the url .

3. Also you can verify on device afaria client .

Open the afaria client on device and click setting and check the communication address on client is it the same you had mention xnet://ip:3007.

Former Member
0 Kudos

Thanks Rajaramesh,

1) I am using android not iPhones is this still relevant?

2) The Dot Net version is already 4 in the IIS App Pool

the /aips/aipService.svc/help page comes up and we are able to see the XML Feed.

3) What hot fix?

Which port numbers are required, 3007 and 5228?

Former Member
0 Kudos

Hi,

For Afaria 7 sp4 no hotfix required.

You need to open both port from afaria server 3007 and 5228

Former Member
0 Kudos

1. I will work on opening the relevant ports.

2. Wrong url code :

Just click on Enrollment code you had generated and than click on INSPECT .

You can view the long url there please check the url .

This is the URL that I tested above in the screenshot. It returns an error:

Request ErrorError Status Code: 'InternalServerError'Details: The server encountered an error processing the request. Please see the server logs for more details.

3. When I try on the client using xnet://<IP Address>:3007 from my server machine I very briefly get the following error:

You are not assigned to run this channel

and then it comes back to the main screen of the client.

Former Member
0 Kudos

Thank you, will work on the ports and let you know.

Former Member
0 Kudos

Hi Enrollment Server means iPhone Server. Apply recent chetan answer.

Former Member
0 Kudos

Hi,

You are not assigned to run this channel : Error occurred because you had not link the group and policy .. you need to link the policy to the group

Former Member
0 Kudos

Hi Chentan,

I opened both ports and am able to see that they are no longer FILTERED in portqry.

But I'm still seeing the same error in Android. Any further ideas?

Former Member
0 Kudos

Hi,

Please check the device communication setting

Former Member
0 Kudos

I already pasted a screenshot of the Device Communications settings above, do you see anything wrong?

Former Member
0 Kudos

Hi,

Please provide the screenshot for Enrollment server setting and enrollment code inspect url

Former Member
0 Kudos

We uninstalled all the Afaria components and started over. This is the error we are getting now on the enrollment screen:

This is a screenshot of the enrollment server settings:

To enroll we are using the following url:

http://<host ip>/ssp/<code from tiny URL>

Former Member
0 Kudos

Thank you so much Chetan for your help.

Finally figured out we were missing config under SERVER-> COMPONENT -> Self Service Portal.

Now we are able to log in from the device!

Former Member
0 Kudos

Hi,

Thats what i inform you to check initial the wrong url code.

Good the error resolved

jigar_salecha
Explorer
0 Kudos

But in my Afaria server,i am hiving C2DM and not GCM

How to proceed??

Former Member
0 Kudos

That because you are on Afaria 7 you need to install hotfix for the same to get GCM on Afaria console.

That the reason i had suggested to install Afaria 7 SP4

jigar_salecha
Explorer
0 Kudos

HI chetan,

          Thanks for your help...

           I am upgrading it to sp4.

           Once done will revert back to you.

          I am not able to telnet port 5228 from the same Afaria server.So is this port close .Is this port is the reason because of which,I am not able to enroll.How to open it???

         

          I am able to telnet port 3007.

          And sorry,GCM is actually not used by me??Is it compulsory???

               Waiting for Your response

Former Member
0 Kudos

Yes GCM is mandatory

jigar_salecha
Explorer
0 Kudos

Hi Chetan,

               Okay, I am upgrading it too SP4.

      

             1)  Ya I changed both directory names at the time of installation

                  2) I removed port number .....But even now enrollment failed

                  3)There is no relay server

                  4)Mode of connection from device -corporate wifi.-------Is this creating problem???


Also what do u mean by Network Ports opening problem.How to check that???



is GCM compulsory????I am using it..



Waiting for Your response



Former Member
0 Kudos

HI,

I will suggest you once you complete the Afaria7 sp4 installation.

Afaria 7 sp4 will resolve most of the problem

1.  its ok to test with WIFI no problem with it.

2. Yes GCM is required for sending notification on device

3. Port 5228 should be open from afaria server for the same.

I will suggest you to 1st install afaria 7 sp4 and check