Push Certificates

Jamf School Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

A push certificate is an encrypted file generated by Apple that establishes trust between Jamf School and Apple Push Notification service (APNs). Jamf School relies on APNs to initiate communication with devices, and the push certificate authorizes Jamf School as an authorized sender by Apple. Once authorized, Jamf School can send push notifications through APNs to enrolled devices.

While enrollment establishes trust between devices and Jamf School, the push certificate establishes the trust required between Jamf School and APNs. Both are required for Jamf School to manage devices.

To obtain a push certificate, Jamf School generates a certificate signing request (CSR), which is signed by Jamf and submitted to the Apple Push Certificates Portal. Apple uses the signed CSR to generate the push certificate, which you must manually upload to Jamf School.

After trust between Jamf School and APNs is established, Jamf School may send requests to Apple cloud services for a managed device to communicate with its management server. Apple then responds to the persistent outbound connection from the device to notify it that it must communicate with the Jamf School server address provided in the MDM profile. The device then polls Jamf School for commands, processes those commands, and reports the results back to Jamf School.

Each push certificate is valid for one year and must be renewed using the same Apple Account that was used to generate it.

Important:

If the original Apple push certificate expires or is deleted, you must manually re-enroll all managed devices.