Creating a Configuration Profile with a SCEP Payload

Technical Articles

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Requirements

You may need to consult with your network administrator to obtain the information required to complete the following steps, such as the subject format and subject alternative name.

  1. In Jamf Pro, navigate to Computers > Configuration Profiles > New.
  2. Select the SCEP payload and click Configure.
  3. Select Use the External Certificate Authority settings to enable Jamf Pro as SCEP proxy for this configuration profile.
  4. (Optional) Enter a new name for the instance or leave it blank if you don't want to override the original name.
  5. (Optional) Select an option from the Redistribute Profile pop-up menu.
  6. Enter the subject in X.500 format, e.g. CN=$COMPUTERNAME.
  7. No other settings need changing in the SCEP payload; the challenges and URLs will be read from the CA settings.
  8. Click Save.
  9. Click the Scope tab and add computers to the configuration profile's scope.
  10. Click Save.
  11. On the scoped computer, you can confirm the certificate was issued in the following locations:
    • Keychain Access

    • System Preferences > Profiles (macOS 12 or earlier) or System Settings > Privacy & Security > Profiles (macOS 13 or later).