User Guide

24 Chapter 1 Deploying iPhone and iPod touch
Phase 2 – Device Authentication: After the user accepts the installation of the profile
received in phase 1, the device looks up the requested attributes, adds the challenge
response (if provided), signs the response using the device’s built-in identity (Apple-
issued certificate), and sends it back to the profile distribution service using HTTP Post.
For a sample configuration profile for this phase, see “Sample Phase 2 Device
Response on page 85.
Profile service
Attributes: UDID,
OS Version, IMEI
Challenge token:
AnneJohnson1
Phase 2 - Device Authentication
Signed response via POST
sample