A push certificate is an encrypted file generated by Apple that establishes trust between Jamf Pro and Apple Push Notification service (APNs). Jamf Pro relies on APNs to initiate communication with devices, and the push certificate authorizes Jamf Pro as an authorized sender by Apple. Once authorized, Jamf Pro can send push notifications through APNs to enrolled devices.
While enrollment establishes trust between devices and Jamf Pro, the push certificate establishes the trust required between Jamf Pro and APNs. Both are required for Jamf Pro to manage devices.
To obtain a push certificate, Jamf Pro generates a certificate signing request (CSR), which is signed by Jamf and submitted to the Apple Push Certificates Portal. Apple uses the signed CSR to generate the push certificate, which you must manually upload to Jamf Pro.
After trust between Jamf Pro and APNs is established, Jamf Pro may send requests to Apple cloud services for a managed device to communicate with its management server. Apple then responds to the persistent outbound connection from the device to notify it that it must communicate with the Jamf Pro server address provided in the MDM profile. The device then polls Jamf Pro for commands, processes those commands, and reports the results back to Jamf Pro.
Each push certificate is valid for one year and must be renewed using the same Apple Account that was used to generate it.
If you have a push certificate in .p12 format, you do not need to create a new one. You can upload the .p12 file to Jamf Pro following the instructions in this section.
You can also use Jamf Pro to renew your push certificate when needed.
Uploading a push certificate to Jamf Pro automatically enables the Enable push notifications setting in Jamf Pro's Security settings.