Latest Updates done, before integrating
This commit is contained in:
94
infra/ca/enroll-iphone.md
Normal file
94
infra/ca/enroll-iphone.md
Normal file
@@ -0,0 +1,94 @@
|
||||
# iPhone Enrollment Guide
|
||||
|
||||
Two steps: first install the CA as a trusted root, then install your personal client cert.
|
||||
Both must be done before Safari can reach the EMS.
|
||||
|
||||
---
|
||||
|
||||
## Step 1 — Install the CA cert (trust anchor)
|
||||
|
||||
Do this once. It makes your iPhone trust the EMS server cert and accept the client cert.
|
||||
|
||||
### On your Mac / Linux machine (in the `infra/ca/` directory):
|
||||
|
||||
```bash
|
||||
# Serve ca.crt temporarily on the LAN
|
||||
python3 -m http.server 8080
|
||||
```
|
||||
|
||||
### On the iPhone (Safari — not Chrome):
|
||||
|
||||
1. Open **Safari** and navigate to `http://192.168.x.x:8080/ca.crt`
|
||||
(replace with your Mac's LAN IP — check with `ifconfig | grep 192.168`)
|
||||
2. Safari shows: *"This website is trying to download a configuration profile. Do you want to allow this?"* → **Allow**
|
||||
3. Open **Settings** → you will see a banner: **Profile Downloaded** → tap it → **Install**
|
||||
4. Enter your iPhone passcode if prompted → **Install** (top right) → **Install** again to confirm
|
||||
5. Go to **Settings → General → About → Certificate Trust Settings**
|
||||
6. Under *"Enable Full Trust For Root Certificates"*, toggle **EMS Private CA** → **Continue**
|
||||
|
||||
The CA is now trusted. You can stop the Python server.
|
||||
|
||||
---
|
||||
|
||||
## Step 2 — Install the client cert
|
||||
|
||||
Do this once per device. Generate the cert first if you haven't:
|
||||
|
||||
```bash
|
||||
cd infra/ca
|
||||
./issue-client-cert.sh lutz-iphone
|
||||
```
|
||||
|
||||
Then transfer `lutz-iphone.p12` to the iPhone. The easiest ways:
|
||||
|
||||
**AirDrop (recommended):**
|
||||
1. On Mac: right-click `lutz-iphone.p12` → Share → AirDrop → select your iPhone
|
||||
2. On iPhone: tap Accept
|
||||
3. Tap the received file → **Settings** opens automatically
|
||||
4. **Settings → Profile Downloaded** → **Install** → enter PKCS12 password → **Install**
|
||||
|
||||
**Alternatively via Files / Mail / Notes:**
|
||||
- Share the `.p12` file to yourself via any app, then tap it to trigger profile installation.
|
||||
|
||||
---
|
||||
|
||||
## Step 3 — Test
|
||||
|
||||
1. Open **Safari** on the iPhone
|
||||
2. Navigate to `https://ems.famfi.dyndns.org:9443`
|
||||
3. Safari will prompt: *"ems.famfi.dyndns.org" wants to use "lutz-iphone EMS"* → **Continue**
|
||||
4. The EMS login page should appear — no certificate warning
|
||||
|
||||
---
|
||||
|
||||
## Revoking a device
|
||||
|
||||
There is no CRL/OCSP for this private CA (not needed for a home setup).
|
||||
To revoke a device:
|
||||
1. On the iPhone: **Settings → General → VPN & Device Management** → select the EMS profile → **Remove**
|
||||
2. Generate a new CA (`gen-ca.sh`) and re-enroll all remaining devices, OR
|
||||
regenerate only the server cert and client certs — a revoked client cert is still technically valid
|
||||
until the Traefik config is updated to exclude it by CN.
|
||||
|
||||
For a home setup with 1-2 devices, deleting the profile from the device is sufficient protection.
|
||||
|
||||
---
|
||||
|
||||
## Cert renewal (annually)
|
||||
|
||||
Server and client certs are valid for 825 days (~2.25 years). When they approach expiry:
|
||||
|
||||
```bash
|
||||
cd infra/ca
|
||||
./gen-server-cert.sh # new server cert
|
||||
scp server.crt server.key user@synology:/etc/ems/certs/
|
||||
ssh user@synology "cd /opt/ems && docker compose restart traefik"
|
||||
|
||||
./issue-client-cert.sh lutz-iphone # new client cert — repeat enrollment Step 2
|
||||
```
|
||||
|
||||
The CA itself is valid for 10 years. Its expiry date:
|
||||
|
||||
```bash
|
||||
openssl x509 -noout -dates -in infra/ca/ca.crt
|
||||
```
|
||||
Reference in New Issue
Block a user