Certificates with Jamf Connect

Jamf Connect Documentation

Solution
Application
Jamf Connect
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Self Service+ can also get certificates from an Active Directory Web Certificate Authority (CA) using Kerberos authentication. If configured, Self Service+ creates a certificate signing request (CSR) and submits it to the URL specified in your Self Service+ configuration profile using the certificate template supplied there. If successful, Self Service+ places the signed certificate into the user’s keychain.

Note:

To get certificates, users must trust the CA’s SSL certificate.

By default, Self Service+ creates a key-value pair for the CSR and marks it as non-exportable from the user’s keychain. This can be turned off in the preference file. Self Service+ automatically renews the certificate, if the most recent certificate for that user has less than 30 days of validity left.

Note: Because the user is usually not connected to the Active Directory domain when signing in with an IdP, Self Service+ waits for the domain to be reachable before attempting to sign in as the user. Self Service+ does not cache the user password but rather relies on the user’s keychain for storage.