# iPhone Enrollment Guide Two steps: first install the CA as a trusted root, then install your personal client cert. Both must be done before Safari can reach the EMS. --- ## Step 1 — Install the CA cert (trust anchor) Do this once. It makes your iPhone trust the EMS server cert and accept the client cert. ### On your Mac / Linux machine (in the `infra/ca/` directory): ```bash # Serve ca.crt temporarily on the LAN python3 -m http.server 8080 ``` ### On the iPhone (Safari — not Chrome): 1. Open **Safari** and navigate to `http://192.168.x.x:8080/ca.crt` (replace with your Mac's LAN IP — check with `ifconfig | grep 192.168`) 2. Safari shows: *"This website is trying to download a configuration profile. Do you want to allow this?"* → **Allow** 3. Open **Settings** → you will see a banner: **Profile Downloaded** → tap it → **Install** 4. Enter your iPhone passcode if prompted → **Install** (top right) → **Install** again to confirm 5. Go to **Settings → General → About → Certificate Trust Settings** 6. Under *"Enable Full Trust For Root Certificates"*, toggle **EMS Private CA** → **Continue** The CA is now trusted. You can stop the Python server. --- ## Step 2 — Install the client cert Do this once per device. Generate the cert first if you haven't: ```bash cd infra/ca ./issue-client-cert.sh lutz-iphone ``` Then transfer `lutz-iphone.p12` to the iPhone. The easiest ways: **AirDrop (recommended):** 1. On Mac: right-click `lutz-iphone.p12` → Share → AirDrop → select your iPhone 2. On iPhone: tap Accept 3. Tap the received file → **Settings** opens automatically 4. **Settings → Profile Downloaded** → **Install** → enter PKCS12 password → **Install** **Alternatively via Files / Mail / Notes:** - Share the `.p12` file to yourself via any app, then tap it to trigger profile installation. --- ## Step 3 — Test 1. Open **Safari** on the iPhone 2. Navigate to `https://ems.famfi.dyndns.org:9443` 3. Safari will prompt: *"ems.famfi.dyndns.org" wants to use "lutz-iphone EMS"* → **Continue** 4. The EMS login page should appear — no certificate warning --- ## Revoking a device There is no CRL/OCSP for this private CA (not needed for a home setup). To revoke a device: 1. On the iPhone: **Settings → General → VPN & Device Management** → select the EMS profile → **Remove** 2. Generate a new CA (`gen-ca.sh`) and re-enroll all remaining devices, OR regenerate only the server cert and client certs — a revoked client cert is still technically valid until the Traefik config is updated to exclude it by CN. For a home setup with 1-2 devices, deleting the profile from the device is sufficient protection. --- ## Cert renewal (annually) Server and client certs are valid for 825 days (~2.25 years). When they approach expiry: ```bash cd infra/ca ./gen-server-cert.sh # new server cert scp server.crt server.key user@synology:/etc/ems/certs/ ssh user@synology "cd /opt/ems && docker compose restart traefik" ./issue-client-cert.sh lutz-iphone # new client cert — repeat enrollment Step 2 ``` The CA itself is valid for 10 years. Its expiry date: ```bash openssl x509 -noout -dates -in infra/ca/ca.crt ```