thoughtasylumTOOLBOX Preview

Tools › Mac

Configuration Profile Viewer

See what a .mobileconfig profile would do before you install it: every payload in plain words, who signed it and whether the signature checks out, and warnings for the risky parts, such as root certificates, device management, privacy permissions, proxies and DNS.

About this tool What it's for, how to use it and an example

What it's for

Read a configuration profile (.mobileconfig) before installing it. Profiles can add Wi-Fi networks and email accounts, but also trusted certificates, device management, VPNs, proxies and permissions for apps, and the install prompt shows little of that.

For example, when a website, a colleague or a support guide asks you to install a profile, open it here first to see exactly what it would change, and who signed it.

How to use it

Choose the file (or drop it on the page), or paste a profile’s XML. Signed profiles are unwrapped: the page shows who signed them and checks that the signature matches the contents, and Save the profile without its signature downloads the XML inside, as security cms -D would.

The list at the top picks out what matters, worst first: root certificates (which can vouch for any website), enrolment in device management (MDM) and what the server could then do, apps given privacy permissions without asking, proxies, DNS, VPNs and content filters, profiles that ask not to be removed, and passwords written in plain text. Below it are the profile’s details and each payload’s settings, with certificates decoded.

Example

Paste this:

<?xml version="1.0" encoding="UTF-8"?>
<plist version="1.0">
<dict>
  <key>PayloadDisplayName</key><string>Office proxy</string>
  <key>PayloadIdentifier</key><string>com.example.proxy</string>
  <key>PayloadType</key><string>Configuration</string>
  <key>PayloadContent</key>
  <array>
    <dict>
      <key>PayloadType</key><string>com.apple.proxy.http.global</string>
      <key>ProxyServer</key><string>proxy.example.com</string>
      <key>ProxyServerPort</key><integer>8080</integer>
    </dict>
  </array>
</dict>
</plist>

The message says Office proxy: 1 payload, unsigned. The list warns that the global web proxy sends web traffic through proxy.example.com:8080 and notes that the profile isn’t signed.

Good to know

A signature that checks out shows the profile hasn’t changed since it was signed, not that the signer is trustworthy: anyone can make a certificate. The page can’t tell whether macOS trusts the signer, so it may still show the profile as Unverified. Payload types it doesn’t know are listed with their raw settings. Profiles holding passwords or private keys should be kept as secret as the passwords themselves.

Private: this tool runs in your browser. Nothing you type, paste or choose leaves this page.

Saved you a few minutes? Say thanks with a coffee.

Something wrong with this tool, or missing from it? Report a bug or suggest a feature.

↑ ↓ move↵ openesc close