Gebruiksaanwijzing /service van het product iPod and iPod Touch van de fabrikant Apple
Ga naar pagina of 58
iPhone and iP od touch En terprise Deploymen t Guide.
K Apple Inc. © 2008 Apple Inc. All rights reserved. This manual may not be copied , in whole or in part, without the written consent of Apple . The Apple logo is a trademark of Apple Inc .
3 3 C onten ts Prefac e 5 iPhone in the Enterprise 5 System Requiremen ts 6 Microsoft Exchange ActiveSync 8 VPN 8 Network Security 9 Certificates 9 Email accounts 9 Additional Resour ces Chapter 1 1 0.
4 Contents 39 Setting iT unes Restrictions Chapter 5 42 Deploying iPhone Applications 42 Register for A pplication Development 43 Signing Applications 43 Creating the Distribution P rovisioning P rofi.
5 Prefac e iPhone in the Ent erprise Learn ho w to int egrate iPhone and iP od touch with your enterprise syst ems. This guide is for system administrat ors. It provides information about deploying and supporting i Phone and iP od touch in enterprise environmen ts.
6 Preface iPhone in the Enterprise Windows c omputers  Windows XP Ser vice P ack 2 or Windo ws V ista  500 MHz P entium processor or faster  256 MB of RAM  Quick Time 7 . 1 .6 or later Some features of iT unes, such as use of the iT unes Store, have additional requir ements.
Preface iPhone in the Enterprise 7 Remote Wipe Y ou can remotely wipe the contents of an iPhone or iP od touch. Doing so quick ly remove s all data and configuration information from the devic e, then the device is securely erased and restor ed to original, factor y settings.
8 Preface iPhone in the Enterprise Exchange A c tiveSync F eatures Not Supported Not all Exchange f eatures are supported, including, for example:  F older management  Opening links in email to do.
Preface iPhone in the Enterprise 9 Certificates iPhone and iP od touch can use certificates in the following ra w formats: Â PKCS1 (.cer , .cr t, .der) Â PKSC1 2 (.
1 10 1 Deploying iPhone and iP od touch This chapter pr ovides an o ver view of how to deploy iPhone and iP od touch in your ent erprise. iPhone and iP od touch are designed t o easily integrate with y our enterprise systems including Microsoft Exchange 2003 and 2 007 , 802.
Chapter 1 Deploying iPhone and iPod touch 11 Although there is no cellular service or SIM card for iP od touch, it must also be connected to a computer with iT unes for unlocking.
12 Chapter 1 Deploying iPhone and iPod touch Network C onfiguration  Make sure por t 443 is open on the firewall. I f your company use s Outlook Web Access , port 443 is most likely already open.
Chapter 1 Deploying iPhone and iPod touch 13 WP A/WP A2 Enterprise Network C onfiguration  V erify network appliances for compatibility and select an authentication type (EAP type) suppor ted by iPhone and iP od touch.
14 Chapter 1 Deploying iPhone and iPod touch IMAP Email If you don ’t use Microsof t Exchange , y ou can still implement a secure , standards-based email solution using any email server that suppor ts IMAP and is configured to requir e user authentication and SSL.
Chapter 1 Deploying iPhone and iPod touch 15 If you don ’t use Microsof t Exchange , y ou can set similar policies on your device s by creating configuration profiles . Y ou distribute the profiles via email or a web site that is accessible using the device .
2 16 2 Creating and Deplo ying C onfiguration P rofile s Configur ation profile s define how iPhone and iP od touch work with y our enterprise syst ems. Configuration profiles ar e XML files that, when installed, provide information that iPhone and iP od touch can use to connect to and communicat e with your enterprise systems.
Chapter 2 Creating and Deploying Configuration Profiles 17 When you open iPhone Configuration Utility , a window similar t o the one shown below appears.
18 Chapter 2 Creating and Deploying Configuration Profiles iPhone Configur ation Utility for the W eb The web-based version of iPhone C onfiguration Utilit y lets you create configuration profiles for y our devices. Follow the instructions below for the platf orm you’ re using.
Chapter 2 Creating and Deploying Configuration Profiles 19 A screen similar to the one shown here will appear . F or information about using the utility , see “Creating Configuration P rofiles,” below .
20 Chapter 2 Creating and Deploying Configuration Profiles T o restar t the utility on Windo ws 1 Go to Con trol P anel > Administrative T ools > Ser vices. 2 Select Apple iPhone Configuration Web Utility . 3 Select Restar t from the Action menu.
Chapter 2 Creating and Deploying Configuration Profiles 21 General Settings This is where you pr ovide the name and identifier of this profile . A configuration name is required . The name you specify appears in the profiles list and is display ed on the device after the configuration profile is installed .
22 Chapter 2 Creating and Deploying Configuration Profiles T o sign a profile, click Apply Signature in the Signature section of the General pane. In the Configuration Signing window that appears , add the digital certificates necessary to authenticat e your signature .
Chapter 2 Creating and Deploying Configuration Profiles 23 Â Maximum passcode age (in days): Requires users to change their passcode at the interval you specify . Â Passc ode lock (in minutes): If the device isn’ t used for this period of time , it automatically locks.
24 Chapter 2 Creating and Deploying Configuration Profiles VPN Settings Use this pane to ent er the VPN settings for connecting to your network. Y ou can add multiple sets of VPN connec tions by clicking the Add (+) button. F or information about supported VPN protocols and authentication methods , see “ VPN” on page 8.
Chapter 2 Creating and Deploying Configuration Profiles 25 Credentials Settings Use this pane to add certificates to the device . Cer tificates in raw f ormats PKCS1 (.
26 Chapter 2 Creating and Deploying Configuration Profiles The Configuration Iden tifier field in the General pane is used by the device to determine whether a profile is new , or an update to an existing profile. If you want the updated profile to replac e one that users have alr eady installed , don’t change the Configuration Identifier .
Chapter 2 Creating and Deploying Configuration Profiles 27 IIS W eb S erver If your web server is IIS, add the MIME t ype in the Properties page of the ser ver using IIS Manager . The extension is mobileconfig and the file t ype is application/x-apple- aspen-config.
28 Chapter 2 Creating and Deploying Configuration Profiles If the installation isn ’t completed succ essfully , perhaps beca use the Exchange server was unreachable or the user cancelled the proce ss, none of the information ent ered by the user is retained .
3 29 3 Manually C onfiguring D evice s This chapter de scribes how t o configure iPhone and iP od touch manually . If you don ’t provide automatic configuration pr ofiles, users can configure their devices manually . Some settings, such as passcode policies, can only be set by using a configuration profile.
30 Chapter 3 Manually Configuring Devices Cisco IPSec Settings When you manually configure the device f or Cisco IPSec VPN, a screen similar to following appears: Use this chart to identify the settings and information you ent er: Field Description Description A descriptive title that identifies this group of settings .
Chapter 3 Manually Configuring Devices 31 PPTP Settings When you manually configure the device f or PPTP VPN, a screen similar to the following appears: Use this chart to identify the settings and information you ent er: Field Description Description A descriptive title that identifies this group of settings .
32 Chapter 3 Manually Configuring Devices L2TP Settings When you manually configure the device f or L2TP VPN, a screen similar to the follo wing appears: Use this chart to identify the settings and information you ent er: Field Description Description A descriptive title that identifies this group of settings .
Chapter 3 Manually Configuring Devices 33 Wi-F i S ettings T o change Wi-F i settings, go to Settings > G eneral > Network > Wi-Fi. If the network you ’re adding is within range , select it from the list of a vailable networks . O ther wise, tap Other .
34 Chapter 3 Manually Configuring Devices Exchange Settings Y ou can configure only one Exchange account per devic e. T o add an Exchange account, go to Settings > Mail, Contacts, Calendars, and then tap Add Account. On the Add Account scr een, tap M icrosoft Exchange.
Chapter 3 Manually Configuring Devices 35 iPhone and iP od touch support M icrosoft’ s Autodiscov er y service, which uses your user name and password to det ermine the address of the fron t-end Exchange server . I f the ser ver’ s address can ’t be determined, you’ll be asked to enter it.
36 Chapter 3 Manually Configuring Devices Important: When you configure a device to sync with Ex change, all existing calendar and contact information on the device is o verwritten. Additionally , iT unes no longer sync contacts and calendars with your desktop c omputer .
Chapter 3 Manually Configuring Devices 37 When a certificate is downloaded to the device, the Install Profile screen appears. The description indicate s the type of cer tificate: identity or cer tificate authority (root). T o install the cer tificate, tap Install.
4 38 4 Deploying i T unes Y ou use iT unes to sync music and video , install applications, and more . This chapter describe s how to deploy iT unes and enterprise applications, and defines the settings and restrictions you can specify . Installing iT unes iT unes uses standard Macintosh and Windows installers.
Chapter 4 Deploying iTunes 39 Silently Installing on Windows T o push iTune s to client comput ers, extrac t the individual .msi files from iT unesSetup.ex e. T o Ex tract .msi files from iT unesSetup.ex e: 1 Run iT unesSetup.ex e. 2 Open %temp% and find a folder named IXP nnn .
40 Chapter 4 Deploying iTunes  Play iT unes media cont ent that is marked as explicit  Play movie s  Play T V shows  Play games Setting iT unes Restrictions for Mac OS X On Mac OS X, you control access by using keys in a plist file .
Chapter 4 Deploying iTunes 41 Updating iT unes and iPhone Software Manually If you turn off automat ed and user-initiated software update checking in iT unes, you’ll need to distribute software updates t o users for manual installation. T o update iT unes, see the installation and deployment steps described earlier in this document.
5 42 5 Deploying iPhone A pplications Y ou can distribute iPhone and iP od touch applications to your users . If you want to install iPhone OS applications that you ’ve developed , y ou distribute the application to your users , who install the applications using iT unes.
Chapter 5 Deploying iPhone Applications 43 Signing Applications Applications you distribute t o users must be signed with your distribution certificate. F or instructions about obtaining and using a cer tificate, see the i Phone Developer Cent er at http://developer .
44 Chapter 5 Deploying iPhone Applications Windows Vista  bootdrive :Users username A ppDataRoamingApple Comput erMobileDevice Pr ovisioning P rofiles  bootdrive :P rogramDataApple ComputerMobileD.
Chapter 5 Deploying iPhone Applications 45 Installing Applications using iPhone C onfiguration Utility for Mac OS X Y ou can use iPhone Configuration Utility for Mac OS X to install applications on connected devices.
46 Appendix A A Cisco VPN Ser ver C onfiguration Use these guideline s to configure your Cisco VPN ser ver for use with iPhone and iP od touch. Authen tication Methods iPhone suppor t the following a uthentication methods: Â Pre-shar ed key IPsec a uthentication with user authen tication via xauth.
Appendix A Cisco VPN Server Configuration 47 Certificates When setting up and installing certificates, make sure of the following: Â The server identity cer tificate must contain the server ’ s DNS name and/or IP address in the subject alternate name (SubjectAltName) field.
48 Appendix A Cisco VPN Server Configuration Other Suppor ted F eatures iPhone and iP od touch suppor t the following: Â Application V ersion: T he client software version is sent t o the server , allowing the ser ver to accept or r eject connections based on the device’ s software version.
49 B Appendix B C onfiguration P rofile F ormat This appendix specifie s the forma t of mobileconfig files f or those who want to cr eate their own t ools. This document assumes that y ou ’ re familiar with the Apple XML DTD and the general propert y list format.
50 Appendix B Configuration Profile Format P ayload Con tent The P ayloadConten t array is an array of dictionaries, where each dictionar y describes an individual payload of the profile . Each func tional profile has at least one or more entrie s in this array .
Appendix B Configuration Profile Format 51 P asscode P olic y Pa yload The P asscode P olicy payload is designated by the com.apple.mobiledevice .passwordpolic y P ayloadT ype value.
52 Appendix B Configuration Profile Format Email P ayload The email payload is designat ed by the com.apple .mail.managed P ayloadT ype value . This payload creat es an email account on the devic e. In addition to the settings common to all payloads , this pa yload defines the follo wing: Key V alue EmailAccountDescription String, optional.
Appendix B Configuration Profile Format 53 APN P ayload The APN (Acce ss P oint Name) payload is designated by the c om.apple.apn.managed P ayloadT ype value . In addition to the settings common to all payloads , this payload defines the following: Exchange P ayload The Exchange pa yload is designated by the c om.
54 Appendix B Configuration Profile Format VPN P ayload The VPN payload is designated by the com.apple .vpn.managed PayloadT ype value. In addition to the settings common to all pa yload types, the VPN pa yload defines the following keys. There are tw o possible dictionaries present at the top lev el, under the keys “PPP ” and “IPSec” .
Appendix B Configuration Profile Format 55 IPSec Dic tionary Keys The follo wing elements are f or VPN payloads of t ype IPSec Wi-F i Pa yload The Wi-Fi payload is de signated by the com.apple .wifi.managed P ayloadT ype value. This describes v ersion 0 of the P ayloadV ersion value .
56 Appendix B Configuration Profile Format F or 802. 1X enterprise netw orks, the EAP Client Configuration Dictionary must be provided . EAPClientC onfiguration Dic tionary In addition to the standard encryption t ypes, it is also possible to specify an en terprise profile for a giv en network via the “EAPClientConfiguration ” k ey .
Appendix B Configuration Profile Format 57 EAP-F ast Suppor t The EAP-F AST module uses the following pr operties in the EAPClientConfiguration dictionar y . Thes keys are hierarchical in nature: if EAPF ASTUseP AC is false , the other two pr operties aren ’t consulted.
58 Appendix B Configuration Profile Format If EAPF ASTUseP AC is true , then an existing P AC is used , if it is present. The only way to get a P AC on the device currently is to allo w P AC provisioning . So, you need to enable EAPF ASTPro visionP AC, and if desired, also EAPF ASTProvisionP ACAnonymously .
Een belangrijk punt na aankoop van elk apparaat Apple iPod and iPod Touch (of zelfs voordat je het koopt) is om de handleiding te lezen. Dit moeten wij doen vanwege een paar simpele redenen:
Als u nog geen Apple iPod and iPod Touch heb gekocht dan nu is een goed moment om kennis te maken met de basisgegevens van het product. Eerst kijk dan naar de eerste pagina\'s van de handleiding, die je hierboven vindt. Je moet daar de belangrijkste technische gegevens Apple iPod and iPod Touch vinden. Op dit manier kan je controleren of het apparaat aan jouw behoeften voldoet. Op de volgende pagina's van de handleiding Apple iPod and iPod Touch leer je over alle kenmerken van het product en krijg je informatie over de werking. De informatie die je over Apple iPod and iPod Touch krijgt, zal je zeker helpen om een besluit over de aankoop te nemen.
In een situatie waarin je al een beziter van Apple iPod and iPod Touch bent, maar toch heb je de instructies niet gelezen, moet je het doen voor de hierboven beschreven redenen. Je zult dan weten of je goed de alle beschikbare functies heb gebruikt, en of je fouten heb gemaakt die het leven van de Apple iPod and iPod Touch kunnen verkorten.
Maar de belangrijkste taak van de handleiding is om de gebruiker bij het oplossen van problemen te helpen met Apple iPod and iPod Touch . Bijna altijd, zal je daar het vinden Troubleshooting met de meest voorkomende storingen en defecten #MANUAl# samen met de instructies over hun opplosinge. Zelfs als je zelf niet kan om het probleem op te lossen, zal de instructie je de weg wijzen naar verdere andere procedure, bijv. door contact met de klantenservice of het dichtstbijzijnde servicecentrum.