User Guide

24 Chapter 1 Deploying iPhone and iPod touch
Phase 2 – Device Authentication: After the user accepts the installation of the
profile received in phase 1, the device looks up the requested attributes, adds the
challenge response (if provided), signs the response using the device’s built-in
identity (Apple-issued certificate), and sends it back to the profile distribution
service using HTTP Post.
For a sample configuration profile for this phase, see “Sample Phase 2 Device
Response on page 85.
Profile service
Attributes: UDID,
OS Version, IMEI
Challenge token:
AnneJohnson1
Phase 2 - Device Authentication
Signed response via POST
sample